Yes, I know. Every app can fake everything.
That's why I think a verification button that opens the same data set somewhere else (that you already know) in the onboarding process is a good solution.
It beats blindly trusting the app or centralizing "Nostr login" to a few honeypot services.
A newcomer that is only part of Nostr group chat and then opens his first new app can do a loooot more with trusting the app he already knows and the Web of Verification that that app has, than with trusting who the other chat members are following.
fair. Public square dynamics (follows) aren't that useful if you aren't in a public square (e.g. a group)