The thing with crypto, definitely Ethereum, is your security can be as strong or weak as you like, with the hazards and benefits of whichever option you go with.
I keep my private keys encrypted on Google Drive, with no record of my password, which I'm trusting I'll remember. I'll eventually go for multiple hardware wallets. One in a safety deposit box with the bulk of my funds, another for regular use. I just use myetherwallet to manage transactions, but I'll probably eventually get a machine dedicated to runnig a client for Dapps in the future... Although I suspect that may become unnecessary.
I think most users will need to rely on third parties, to manage their own incompetence. Which kind of negates the whole idea of a trustless system, but I imagine someone will come up with an elegant solution.
__________________
Stay shook. No sook.
|