User should never be forced to login with their owner key. Here's how I would prevent it
On sign-up:
Step 1
- generate a 12 word mnemoric acting as owner/master key
- tell the user to write it down
- ask the user to type the words in as a confirmation
Step 2
- the user sets a password now which acts as their posting key
That's it. would've prevented the last dilemma
By the way, is there an ETA on a Wallet GUI or Light client?
Building on this, steemit.com could reject any key to login except the posting key, and all transactions requiring an active key could be done on subdomains such as market.steemit.com and wallet.steemit.com where no user editable content would be found.
sounds even better now. I hope they build something like this
https://www.pwdhash.com/