that is probably a bad place to start, but also pretty uncommon, almost everyone knows someone who says "i'm on nostr" and they first follow them even if there is no onboarding procedure
not sure. That's true for our "community" of Bitcoiners, but that might not be true in general.
the thing that helps make sure of it is well known clients that have default logged out feeds of legit people
if people are dropping links to fake clients then yeah, but this is a general web phishing problem not anything special about nostr