Here's my rebuttal: http://turtlapp.tumblr.com/post/81222024691/how-turtl-has-no...
Now, if users provide their own key and it's never transmitted, that would be secure, but obviously the data would be un-decryptable if the key is lost.
Right now if you forget your login/password your account is lost unrecoverably. We have a feature slated that would let you download a file version of your account key, meaning if you lost your username or password, you could log in with the special key file and reset your info. Obviously, you'd have to keep the file encrypted/safe, but that's the user's responsibility ultimately.