I think it's worth digging a little.
I'm not big on TOR at all, so if that's a game-changer then fair.
Tying a public key to a long-lived hash may be doable, though you'd need a refresh mechanism for when the browser forces. Again though worth digging.
For Web PKI I read chatter before on some kind of push for secondary authentication, who knows, all very new.
Complexity, no doubt.
But I will say that if the performance you get with iroh holds up then it might be worth every trade-off. For me, p2p with this kind of performance is just nuts. Never in my internet history.