Make the transition more legit can also be used by attackers to make their attack more legit. That's where all crypto-first ideas die. I think it will always be out of band communications. At least I have not seen a single idea that doesn't require active web of trust verifying things around it... Which is the same as the kind 1 post.

Replies (2)

That's why my proposal is not crypto-first, wot social proofs, ots, and so on. Not a single way an attacker can impersonate you by "knowing your password". And from my pov is not the same as a kind 1 post, kind 1s are already overloaded
Its just formalizing the wot verification that already happens on a single kind 1. I don't disagree with you that it works in the same way, but you have to see that it is way more complicated to implement for the exact same result. OTS alone is not even coded by 99% of nostr apps.