Earlier quoted context omitted.
I don't think it follows that malware is the only possible alternative to walled gardens. You could still have trust mechanisms while downloading from sites where the author , not the walled garden, has the control.
A lot of authors want to do things that violate the user’s trust, but are hard to detect. Wouldn’t it be better to have the user have the control? The walled garden does have problems, but I generally don’t see anyone adding any value to our understanding of how to replace it with something better.
It would, but the user has no control of the walled garden either. It's a situation where both the user and the author have little to no control, as well as poor feedback.
I'm not sure walled gardens, with their arbitrary rules, and opaque audit and review processes (which include not knowing how detailed their reviews are), are really a trusty safeguard against malicious authors. Whether you believe walled gardens protect you from malware depends on your definition of "malware".
It's not true that without the App Store there's a world of dangers out there. Author reputation goes a long way.