That would be silky. No one will do that for every single interaction. It's simle. Don't enter your nsec into websites. Use a signing extension or bunker. Done.
Trivial mitigation. Keeping a post-it of your password in a drawer rather than posted on the monitor makes little difference to the cleaning maid. And Biden has a LOT of evil maids in his orbit 😉