A note about extension. Even though he's technical and interested in some of nostr native apps, he didn't know about extensions!
So I did a test and found that Snort/Iris doesn't show any hints or suggestion about the benefits of using an extension, if it is not already installed. So even if he had pressed the correct "Sign Up" button, he would have continued to login sharing his nsec with the website: a faked domain and you are over.
We should promote account creation *outside* of web apps (and probably outside native app too) and the use of extensions/signing tools. I know, it is hard.
promote "metamask" login...