2FA authentication has been suggested too and will be part of the feature list of the new forum but I think thats using bitcoin addresses and signing too.
i am sure its a nice way to prove it, but no message alerts you to post an address and save the private key since will be needed in case of receovery.
so what if you dont have any bitcoin address posted? i am pretty sure there are tons of people who never posted any address because they had no need to.
also neither change the fact security measures in the forum are very low, and you must wait months before the admin answers you in case of a hack,
the security on the forum and the recovery path is just out of any sense,
asking a signed message should rather be an extra last step, not the single one.
that an objective point of view,