With this solution you actually get both benefits: you own the keys but you can use a safer and revocable login token that is "semi-custodial" (all signer need to collude to steal the nsec). Of course the user need to understand a new paradigm: keep the may nsec safe and just use the derivated token(s) to login or sign.