I don't mean to keep beating a dead horse on this subject, but why are we acting like this is only a possibility? Apple is almost certainly going to remove the ability to run unsigned code in the future.
A day or two I wrote[0] about the timeline that took Facebook from guaranteeing that you'd never need to sign into an account on Oculus to requiring a Facebook account on Oculus. Different company, same story.
We spent a long time having concerns dismissed, and then once everyone was used to the idea and the uproar had been reduced to a manageable level, Facebook did it. People get told that they're paranoid when they express concerns about the future. Then those concerns turn out to be correct, but by then the concerns seems less dystopian, and we've moved on to dismissing other concerns even farther down the road.
I'm not going to find the other threads and articles, but:
Voice assistants: same story different companies. Concerns about recordings leaking, being distributed outside of the company to 3rd-party contractors were all paranoia until they weren't.
Facebook, again: same story different company. Facebook would need to be stupid to use 2-factor phone numbers for advertising and promotion services, the people worrying about that scenario were paranoid. Until they were proven right.
Browsers: same story different companies. You can not run unsigned extensions in Chrome. You can not run unsigned extensions in Firefox unless you are on the beta-version developer branch. In both cases, even though Firefox technically has an escape hatch, the effect is the same: normal no longer have the unrestricted ability to write software for their own devices.
I'm not going to argue that Mozilla's worries about malware aren't real, I'm not even going to argue about whether or not they made the right decision overall. BUT, anyone who thinks for one second that Apple isn't in a position to bring up the exact same security justifications for removing unsigned code from the Mac is fooling themselves.
We keep on taking these companies at face value, assuming the most permissive, conservative version of their policies, and then using that assumption to avoid talking about the real dangers of a corporate war on user-controlled general-purpose computing.
When Mac signing came out, so many people were telling me that it was stupid to object, because this was just about stopping specific malware. It would never be used to enforce a ToS or directly punish another company. So when we have conversations about Apple's dominance in the space, about what walled gardens mean for Apple, we need to have those conversations under the assumption that the most likely future is one where those same exact policies apply to both Apple phones and Apple desktop computers.