Yes, that's true.
The most important thing of all is that you never use your master password to sign in anywhere.
Always use your posting key (most secure) or active key.
In case you have your account compromised you can use your master password to reset the other keys (posting key/active key).
RE: Vlog 306: The coolest way to share photos on the blockchain. Demonstrating the Steepshot app!