I think developers have a moral responsibility to make their products as secure as possible, within reason and while still being usable. It doesn't matter if the users care about the benefits. To your second question: no, not yet.
I fully agree with you, and my first question was asked somewhat sarcastically. For the second, my implication is that developers also have a moral responsibility to make their products as private as possible, and SMS verification aint it.