Sort:  

because they type their owner key as password, the hacker using xss to steal that key :)

Thanks you guys cleared that up for me, I guess we still need 2FA for SBD though. POWERED UP IS very SAFE, but SBD Insurance should be sufficient!