The security was fine for 3 years
Nah, it really wasn't. There was a massive (relative to the size of the site at least) hack three years ago specifically because of keys being the browser. The mechanism was changed a bit and might be a little better but the fundamental vulnerability remains. It is good that Steemit is being pro-active on this instead of waiting for another incident.