One year passed, and I checked my backups. Yup, there it was.
If you take security seriously, you should actually read what's on the page instead of clicking "next, next, next" like some driveby malware-installing Windows-installer. And then this shouldn't be an issue.
I guess this is StartSSL's way of not having to deal with people who don't take security as seriously as they do.
Having a login cert is fine if the "user" is an organisation. It is a broken model for individuals or small businesses.
StartSSL doesn't take security serious. They'll happily accept breaches to their terms of use, as long as you pay up.