On one hand, users are told that they should never ever, ever install applications from untrusted sources. They should always use the play store because applications are scanned for vulnerabilities and whatnot.
On the other hand, we have people telling us that one of the great advantages of Android is that you can sideload apps - bypassing the store security model completely.
On one hand, a VPN needs root access for transparent proxying (or at least TOR does). Changing the hosts file needs root access. Changing gps.conf requires root. Lots of useful operations need root access, so if you are concerned about privacy and security, or just want more control, you probably want root.
On the other hand, root is stupidly hard to obtain, and users are strongly discouraged from doing it anyway because it opens all sorts of attack vectors. Unless the manufacturer provides a legitimate method to do it, the operation of obtaining root itself, like on iOS, often relies on an unpatched local privilege escalation vulnerability. Note that any application can exploit this, not just the rooting app.
I don't support Apple's walled garden approach, but we can't argue that they have a much clearer picture with regards to security, and the results speak for themselves. Malware in the Apple devices is rare, whereas in Android it is rapidly becoming routine. Unfortunately, you sacrifice flexibility for enhanced security.
And they support a lot of devices. I dug out an old Moto G (1st generation, falcon) last week and it runs Lineage 14 (based on Android 7/Nougat) smoothly.
Also, one can sideload apps, if you have a Mac, onto iOS. Obviously, that's not anywhere as integrated but maybe that's a good thing. Heck, maybe Apple even added that so people in China could sideload VPNs. Maybe iOS VPNs are good enough (no root, no TOR?)?
[1] https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xc...
[2] https://www.google.com/amp/s/www.cultofmac.com/128577/apple-...
Don't conflate unpatched Linux systems with the Play Store. Anybody who uses Android and cares about the security of their device (like anybody who uses a Linux-based router and cares about the security of their network) uses vendors who deploy timely security updates.
But lately Google has decided that rooted phones are a security issue. So if you do choose to install some sort of su utility, some functions like Android Pay may cease to work, not because of technical reasons but because Google deliberately disables them on rooted phones.
[1] for example https://wiki.lineageos.org/devices/lux/install
What they've done could be said to be more authoritarian, and indeed if you do the analogous of throwing everyone in jail by default because they could be guilty, then you will basically have no crime. The question is whether that's actually a good idea... it's the old "freedom vs. security" argument.
Here's OpenVPN.
https://play.google.com/store/apps/details?id=net.openvpn.op...
There's also Tor with Orbot and Orfox.
https://play.google.com/store/apps/details?id=org.torproject...
https://play.google.com/store/apps/details?id=info.guardianp...
But only explicitly configured apps will use this proxy. Proxying all traffic does require a rooted phone.
In general, Android gives you more options but iOS seems to offer a more privacy-minded configuration OOTB.
Same with Tor. You can use an unlisted bridge to get on the network.