Hi, Bernard.
I am Gleb, one of the founders of the lobstr.co
First of all, I'm terribly sorry to hear about your troubles while using our wallet.
Our team is looking into the issue which you've described in your review of the stellar wallets, and we will definitely take some actions to notify users more clearly about the consequences of resetting password and actions needed to ensure safety more clearly.
Let me clarify:
We don't have access to your secret key - it is securely stored inside our platform encrypted.
Your password is taking part in the process of encryption/decryption of your secret key.
(Obviously, we don't store passwords in raw format as well.)
We've implemented the logic that allow users to restore their secret keys in case of password loss, using a special passphrase, which is called "Recovery Code".
During the registration process, the system shows a message, asking to securely store the recovery code on your side, as it can be used to restore access to your secret key in case of lost password.
Here is the screenshot of this prompt:
https://www.dropbox.com/s/qbt7sy67kimj7js/Screenshot%202016-07-06%2016.26.48.png?dl=0
Lobstr allows you to easily email it to your inbox.
Our records show, that you haven't requested Lobstr to email the secret key, and you probably haven't wrote it down manually.
During "Reset Password" you can see the option to enter recovery code - it will allow you to get access to your secret key and completely restore your existing account.
Please, see the screenshot:
https://www.dropbox.com/s/n4bdl0guxjljdpm/2016-07-05%2021-40-35.png?dl=0
We see recovery code as a helper tool, for the rare cases when user forgets his password. Of course, since we are talking about money and their safety, users have to be careful with storing passwords and credentials.
It never hurts to manually securely save the secret code and account address if you plan to store funds in cryptocurrency wallet.
We will review the flow and will try to emphasize importance of security measures.
We will be happy if you'll give https://lobstr.co/ another try at some point later.
Thank you for the feedback,
Lobstr team.