Agreed, this is a valid concern. This could possibly allow a 3rd party to crack the password, but then again, they would not gain access to any key material. So yes, you could expose your password, but your key would still be safe.If people feel strongly about this vulnerability, we can revisit step 4 and adjust it to make password recovery more expensive.