There's a button "Change SecureLogin" which essentially replaces old pubkey with new one. One would have to do it with all services they every used, and do it before the attacker. It could be automated though.
> The big downside I see is the immediate compromise upon revealing your master password
On this problem I wrote another blog post https://medium.com/@homakov/why-brainwallet-are-great-for-cr...
I believe having to worry about 1 thing is better than 2. It's losing (usability) > stealing (security) in this problem.
But otherwise you summed up everything properly, just what I was trying to say.