Cool hope they do a decent job moderating the servers they run and limiting malware exposure. I also hope they've taken steps to prevent themselves being used as a host for malicious entities to distribute malware to third parties
The reason that they require an account is because if they did not require user side authentication then it would be trivial to upload obfuscated malware and then use Nexus as a host to distribute it. If someone uploads malware to a random S3 bucket or random VPS or random shared server and tries to use it as a malicious host, the owner and operator will notice a massive bandwidth spike Nexus won't notice 30,000 downloads.
Well, unless someone makes an alternative, people are going to use it.
They do need to provide a lot of bandwidth, which isn't free, though I wonder how viable it'd be for someone to create a Nexus-like Website using magnet URLs and BitTorrent as a backend.
Maybe too much of a technical bar to attract users.
The issue with using torrents is longevity. You'd still want/need traditional storage backing it all. Don't want some mod to become lost media because nobody is actively seeding it.
There are JS based torrent downloaders. That would work for the normies to get files, but you'd still have to find a way to convince people to host files on the backend. It'd probably take a full-on desktop client wrapper with an embedded torrent client but that's a pretty hard sell for the average nerd if you're upfront, and probably a harder sell if you're dishonest about it.