* I have to trust thimbl.net and/or you that you aren't storing anything.
* Even if you released your codebase on github (or similar) there is no guarantee (to outside users) that it is the same one that you are running on your servers.
* Your site is not https, meaning that my ssh password is going plain-text over the internet.
* Even if your site is 100% not doing anything funny, there is the possibility for someone else to sniff the passwords flowing through your site.
1. thimbl.net provides its public key.
2. You add it to ~/.ssh/authorized_keys (or whatever your SSH server uses).
3. ...
4. That's it (remove key if you don't trust thimbl anymore or thimbl may even remove it by itself, at the end of setup process).
I could have multiple keys, all w/ different access levels, all on the same user account. There is no way to do this with a password, other than to just have separate user accounts.