It’s a nice idea and a great flow, but it suffers from some problems: Low entropy You are still giving your nsec to a million apps (here only one party has it) No possibility of “password recovery” here recovery can be achieved