This is true. NIP05 is a step in the right direction but I think DIDs would be better for adoption. Tbh unless you have some form of verification badge for everyone even things like hashing profile images and text analysis of names and bios etc would do more to stop impersonation. Look at how rampant this is on Twitter and how the scammers use it