All fair points, but still, you're only looking at the cases where users type nsecs into untrusted apps, which is IMO orthogonal to whether a legacy solution can or should try to be built out on nostr.
We should teach *users* why nsec security is important, not chill *devs* trying to build out the ecosystem. I use amethyst; never gave it any of my nsecs. Why not nostr login on proton too?