Earlier quoted context omitted.
I think that what Apple has done here is an acceptable tradeoff. The app store trades a small amount of privacy for a lot more security. Looking at Android's perpetual issues with this makes me think that Apple made the right choice.
So we have forgotten XcodeGhost already or the iCloud hacks?
Which isn't to say I don't think there are advantages to Android's model and that of more open package repositories in general, especially for power users. However most of Apple's base is people who don't care about openness or extra repositories, they want their iPhone to work with a minimum of fuss and not have to worry about malware like you do on Android.
The fact that we can only point to a single (XcodeGhost) cromulent exploitation of the Apple App Store stack is a testament to how good Apple is at maintaining the relative security of the iOS ecosystem.