Recaptcha after failed logins --- yes, that makes sense.
Nameserver locations. If you are based in (e.g.) Belgium, with nameservers in Switzerland, the UK and France, then my .com is at risk from the US (can order the registry to kill my domain) and Belgian (can (potentially) order you to kill my domain) police / justice systems. In addition, the Swiss, British and French can each block a substantial proportion of my visitors. On the other hand, if you were based in the US and all your nameservers were in the US, then my .com would only be at risk from the US police/judiciary.
Similarly, my .co.uk is surely safest when hosted by a UK company on nameservers located only in the UK.
I didn't read most of the poker site takedown thread, so maybe there is a good counter-argument there. But as a random web developer, that's my concern.
(There are other reasons for spreading nameservers around though --- as a customer I wouldn't worry about the increased legal attack surface unless I had concerns about specific countries.)
Logging in via Facebook/Gmail/Twitter/etc. I wouldn't use Gmail because when Gmail goes down and prevents me from logging in, there's not much point asking for a password reset e-mail to be sent to my Gmail account.
I'm not sure how safe it is to rely on my Facebook or Twitter credentials for something like dns hosting. I login to HN and StackOverflow using OpenID, and I use OpenID for commenting on blogs sometimes as well, and although I'd be upset if my OpenID got compromised and I got locked out of these accounts, I'd be much much more upset if my domain names were suddenly being used to sell Viagra as well.
Meanwhile, if my ssh private key gets compromised, it's overwhelmingly likely that my Twitter+Facebook+Gmail passwords get compromised as well, because a machine I access the net from will have been compromised. The reverse is not true.
I think on balance for this sort of website I prefer using (and writing down somewhere) yet another password over entrusting my dns security to Facebook/Twitter. I'd prefer a properly maintained public key ssh interface to either. I do appreciate that it's another interface that needs maintaining though; I don't know what Javascript support text mode browsers have.