It need to warn that password is only used to hide privatekey from plainview and is NOT your account

Losing the keystore file will render your password useless.
It should state it's ok to backup keystore file on a usb stick as private key is encrypted from plain view but you should still guard it.

Is password used to seed the creation of privatekey?, with bruteforce if you know the password and public key,
within 6months you could recover privatekey?
I lost 0.2 as nanopool auto-paid-out to that old account.
