The potential impact of a breach doesn't just affect you, and their security decisions should be made with a wider consideration of concerns than the short lived frustrations of users.
It varies, I guess. For a normal end-user account on a system where no interaction between users is possible, it pretty much just affects you.
For some kind of admin account with privileged access to other users' data, then it definitely affects others.
One might expect increasing mandatory security measures correlating with increased potential damage of a breach. Similar to safety measures on mass transit vs. personal vehicles.
Your liberty starts where mine ends. By the same logic password complexity should be left up to the users as well, but what responsibility is this user willing to shoulder when they are the reason sensitive information leaks?
I’m sure most people on HN have great passwords stored in password managers, but 99.9% of users are not like that, so mandatory 2FA does not only make sense, it’s the only reasonable choice for sensitive information.