So then the well known URI faces the exact same risk since that's under a domain name anyway.
I'm just saying to signal the hexkey via DNS TXT, not via a flat file confined to the domain component of a NIP-05.
You don't gain any advantages to doing it via well-known URI in censorship terms and you lose flexibility and usability in terms of deployment.
