Steemconnect is the central login platform for most of the 3rd party steemit apps. Since steemit itself has no app, developers have developed multiple apps for ease of use, accessibility and flexibility. There's a whole new world of possibilities opened up by these new apps.
To give these apps access to certain functions and roles on the steemit platform, one has to log in with steemit credentials, now this poses a security risk. Some websites are designed to maliciously collect data from unsuspecting victims. These collected data can then be used to access the victims account for purposes I don't need to mention.
How it works
Most of the genuine apps and websites that are related to steemit use the steemconnect platform. This ensures that no third party can gain access to ones login credentials since steemconnect simply authenticates the app or website's request for a certain amount of "access" without necessarily sending the login credentials out.
source
In some cases, steemconnect is used to authenticate transfers. A good example is when using steembottracker.com or even blocktrades.us.
Security Advice
In recent times, there has been many phishing attacks. For this reason, it is always advisable to crosscheck a website's url before you input sensitive data like usernames and passwords. The real steemconnect website is https://www.steemconnect.com. Make sure you check properly, especially the letters. If you notice any irregularity or get a prompt that the connection is not secure, do not input sensitive data.