> Am I worried about getting hacked? Absolutely!
If you set a strong, long, unique password for every account, your chances of getting the account compromised are just about zero.
2FA is a good thing in most cases, but I do hate how the industry has blindly adopted it as some sort of mantra that you can't exist without. The reality is that if you chose 128+ bit passwords generated out of /dev/random, they cannot be brute-forced within the lifetime of the universe. You might get phished, which is entirely different, but if you're careful about that you'll do fine without 2FA.