Nostr hasn’t grown up to that yet, and pointing out that pasting private keys is a bad idea is fair game.
But implying that public private key cryptography can’t be used to log into web apps is just silly given that value worth billions is being moved around daily using such web apps.