Earlier quoted context omitted.
Unfortunately the most vulnerable will be easily manipulated into bypassing whatever prompts are needed. The threat vector is facebook telling users to install Instagram/FB from their own app store instead of from the App Store, both eroding their privacy (since they won't be mandated to respect the "do not track" popup) as well as training them how to install apps from third-party sources and that "it's OK to sidelo…
I doubt it, otherwise we'd see this in Android. And while it does happen of course, it's vanishingly rare. Anecdotally I have plenty of friends and family who are neither technically proficient nor well educated and they seem to be doing just fine. Instead it's a boon, especially for folks like myself who use a fair amount of software from alternative stores/installers.
In addition, exploitation might be transparent to the user, i.e. a botnet that runs in the background[0] or replacing ads in other apps to steal their revenue[1]. People use iOS and recommend it to their friends/family because of its simplicity and the built-in safeguards the App Store provides, since installing a sideloaded app is a much more involved process.
0: https://cyble.com/blog/daam-android-botnet-being-distributed...
1: https://www.theverge.com/2019/7/10/20688885/agent-smith-andr...