Exactly why it's not free. All systems are vulnerable to some extent and from varying perspectives. The case of "account hacking" is client-side. Something that can be prevented without an authenticator if you just follow strict measures of safe computing. Authenticator is not mandatory as it is only an extra layer of security for your account. Think extended warranty not limited warranty. Limited warranty is when they restore your account.
Restoring your account is like shouldering fraudulent costs. Does your company provide an authenticator-type or biometric devices to add protection and prevent CC fraud? For an additional cost?
I'm not trying to argue Manben statements. Really, I just don't want to have to deal with work anymore today so... Yeah. :D Really, this is kinda like the sparkly pony issue. Only not about a pony anymore..? :D