Earlier quoted context omitted.
The problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.
I think this is a valid concern, and perhaps verifiable. How many Windows user actually create a non-admin account to use for their everyday work? I find, anecdotally, that a helluva lot of them don't; in fact, the very idea is foreign to them.
Most users will leave the default settings if they don't have an active need to change them. Easily usable (and understandable) tools and interfaces prevent most needs from arising in the first place.
Concrete example: The root account on many Linux distros is disabled by default. I've never felt the need to enable it, because sudo does everything I need. Secure default, useful tools, unlockable system.
Historically we haven't had either of those things. Poor design and implementation led to bad choices by clueless users. The resulting mess is used as an excuse to restrict freedoms. The cure is arguably worse than the poison.