Plans for more security for the lite client? 2FA or something, password alone is not secure enough imo.
2FA is mainly to make sure others can't access a public service like an exchange when your credentials are stolen / hacked.
The Waves Client code is executed locally, so attackers can only login to your wallet if your own computer is hacked / compromised.
And what good is 2FA on a compromised computer?
On other computers, they will need your seed (pass phrase) to login to your account and if they have that, your coins are lost anyway.
So in my opinion, 2FA would only offer a false sense of security.
And how could someone recover the 2FA key for you, if you lost it while on a decentralized and locally executed service?
If you lost it and you would lose your seed, you could never access your wallet again, even if you remembered the password.