Using a signer (while still having your pair backed up in a password manager) alleviates the former issue, but I do agree that the latter (especially when users from 2021-25 get compromised) is a major issue.
The moment a developer can make key management and identity retainment without having to wholly start over viable, Nostr will blow up like crazy; Divine and other services that don't heavily emphasize the Nostr aspects of it while retaining full compatibility already do a lot for the protocol.
