> Another problem with key authentication that is often forgotten is that even if you have a password on the private key and it gets stolen the thief can brute force the password at his leisure and can use any and all computer power available to him.
But that still gives you some time to cancel/revoke the stolen key (losing a password does not).