Get the Security Token and use it. There is no excuse not to do it. I don't feel bad for anyone who refuses to use it and gets hacked. None at all. You invite it upon yourself.
In fact, anyone who gets hacked and account banned should be forced to use the security token as a condition of getting their account back.