I feel like this is a huge problem with nxt that needs to be resolved... (Maybe with trustless 2 factor multisig on your phone). I am so worried that if anything or anyone was able to get their hands on my password then what the hell would I do? There is no "change password" functionality. I would need to go through my assets one by one and transfer them to a new account. Followed by sending my nxt(since I need my nxt to transfer out the assets). With bitcoin it's easy because you just send all your coins to new address, takes a second. With nxt you possibly have so many things in your account; this lack of 2 factor or multisig is a massive problem that needs to be solved asap. I feel paranoid as shit entering my password into secureae. My single account holds everything I own in nxt, including a massive investment in supernet. In bitcoin I would have had 90% of this in cold storage but that does not appear to be possible with nxt and is an extremely paranoia bringing feeling.
Doesn't seem that would take more than a minute to do that. A function could easily be created that would sweep everything to a new account.