> As far as malware, I’m not sure why it would be more of an issue on an open platform than it would on Android.
> I use Linux as a daily driver, and as long as you’re getting software from trusted sources, it’s not much of a concern. I don’t see why it would be different on mobile.
Not sure if that's true – doesn't Google keep the Play store mostly free of serious malware? Apart from stunts like sideloading Fortnite, I'd expect the vast majority of Android users to get all their apps from the Play Store, so that should be reasonably safe. Of course, Google can pretty much force everyone into the Play Store by denying access to Play services and their huge customer base if you don't, so it's a one-stop shop for next to everyone.
But if every company, publisher, developer may host their own, including their own OpenPlay Services, how do you tell what is a trustworthy source? How do you tell if OpenRando Store is trustworthy when a Google search tells you it has this TokTuk app you've heard of? This isn't like server Linux, where most people are reasonably careful with what they install, sources are relatively few and policed well, and people tend to be at least somewhat knowledgeable, so tricking them is quite hard; this also isn't like desktop Linux, which doesn't have market share. This would be a reasonably large mobile platform used by everyone and their grandma to run a large part of their lives.
I'm quite sure most people wouldn't want to have to have a thorough understanding of how apps, app stores, installs, updates, the OS, typical malware, scams etc. work, just so they have a chance at noticing when things are off in some way. I've next to no idea how iOS works, and that's fine with me, and I'm someone who runs Kubernetes clusters for fun. Whoever spares people from having to have that knowledge and do that work and actively manage their phone like a piece of complicated corporate IT equipment will get all the users; they'd get me, for sure. My phone really just has to work and be secure.