I suggest your read the account security section on https://steemian.info
In a nutshell, don't use your password at all, use the posting key for your daily blogging, and the active key for doing transactions.
And whatever person or website asks for your password, gtfo quickly.