Earlier quoted context omitted.
How do you make something that isn't trivially turned to oppression without allowing users a trivial escape from the devices protection model? Isn't installing your own OS on your general purpose computer a trivial out? Shall we likewise disable that ability on all general purpose computers?
Sometimes oppression could come from a central authority, and sometimes it can come from a rampant criminal element taking advantage of exploitable human behavior. We have to balance defending against both. > Shall we likewise disable that ability Not on all computers, no. But I should have the option of buying my grandmother one which is very, very hard for someone to convince her to give them admin rights.
You would build chains for millions of people so that granny will have to give scammers her money some less convenient way.
I'd rather not.