Earlier quoted context omitted.
The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.
Personal freedoms have always had risks, but is it really warranted to take them away in this case and not offer a way to get them back in any shape or form? Looking at recent Samsung devices, is Google Services Framework really that integral to the security of my device that I must be forbidden from disabling that package? Isn't there an alternative way to achieve a comparable level of security, but without slurping…
I’m still on the fence about whether that justifies their protocols. I think I actually lean toward “no”, but I’ve also lately become keenly aware of the difficulty of even simple things like keeping everything up to date, and my lack of real insight into what those updates include. If I’m effectively trusting them anyway, might as well trust them to get it to me ASAP, right?
I’m also enough of a realist to assume there’s a Fight Club style “A times B times C > X” reputational/financial risk logic going on here. If there’s few enough of the devices out there, it’s probably cheaper to apologize (legally, as in settle).