"It is highly recommended you enable two factor authentication on your My wallet account. Your wallet data is still only encrypted with your password however a second authentication step will need to be passed before your encrypted wallet data is output."
There's also GreenAdress.it which has interesting security system in place using "nLockTime": http://www.reddit.com/r/Bitcoin/comments/20puhg/while_blockc...
If you trust every other aspect of their service (that they aren't capturing and storing your password, which of course they handle every time you use the service), then you can feel safe in knowing that you don't have to trust them not to spend your coins because they can't.
But only if you trust that every other part is honored.
That isn't a rational set of conditions. In the usage of Blockchain.info, they absolutely gain the capacity to capture your private keys. As does anyone who hacks the service.
So today they don't have your keys. Not to say they couldn't be malicious in the future, or get hacked, but that's not the case today. Again, as far as I know.
And of course the reason for this is because Javascript cryptography is an oxymoron [0].
[0] - http://www.matasano.com/articles/javascript-cryptography/
That's possible with multisig and GreenAddress offers 4 different kind of 2FA: Google Auth, SMS, email and Phone (robot call)