What percentage of them do you think has the capacity and capability to use ADB?
All of them: they can follow procedures, plug a cable, and push buttons if they really want to. Most won't bother: capacity isn't willpower.
it’s a pain in the arse
That's the idea: welcome to an effective deterrent.
even I’m not going to do it to install a trusted open source app
Good, then it'll deter as designed.
the only reason
Nah, the use cases are legitimate:
- It will actually deter installation of malicious software once it's been identified & flagged that way in their system.
- It also verifies install packages haven't been tampered (possibly maliciously) from their original releases.
Malicious software on devices connected to everything including highly sensitive information poses high-cost risks that you & casual users overlook because muh inconvenience 😭. If casual users can't bother with a straightforward procedure as you say, then how prepared are they to handle the real challenges of a successful attack?
From a security perspective, it makes sense for OS designers to choose to limit exposure to that threat to power users who can be expected to at least have a better idea of what they're getting themselves into.