Why is it the worst? It was very smooth for me.
The problem is it's a multi step process and not very private where it could just ask my nip07 to sign a message. As it is, I can trivially get a list of all login events of all nostr users without much gain. It is better than asking for the private key though.
Yeah we tried to avoid touching the private key. This is the best we came up with... 6 months ago or so. Since then we pretty much rewrote the whole thing, including the log in. The new version just asks your extension to sign an event, but the event never gets sent to relays. Coming very soon.