Everyone using any centralized service (Google, Microsoft, Meta, etc) that is not using client-side encryption (Proton, Tuta) is already sharing their contacts with some multinationals and advertising companies that use them to mine everyone’s data and create social graphs. I don’t see how contacts are all that personal when looking at how easily people let all these companies just grab a full take.
I looked into adding another level of encryption on top to basically “unseal” contacts using a 2nd password but it wouldn’t really be nostr-native anymore and it adds significantly more complexity to the codebase.
If you don’t want to use it, all good. I just don’t see the attack surface you described when using a random nostr identity that only resides within your password manager and you only.
