it will be bad when a client’s domain gets compromised and nsecs leaked via an attack
so people will switch to web based signer apps
then they will be compromised
the only way out is a proper hardware signer, a proper remote signer or a browser extension
What's the best way of handling your nsec right now? I use alby extension for zap.stream and Nostrudel and only use Amethyst on mobile.
Public Nostr terminals (like phone booths). Bring your own hardware signer
USB hardware device + mobile app/browser plug-in? User inserts the device when using Nostr apps/sites and removes it when not.