[1] https://blogs.microsoft.com/on-the-issues/2017/05/18/fight-t...
There has to be some sort of curation. Algorithms and automation can help with the curation, but there has to be something.
Same thing with Chrome extensions. Mozilla has solved this same problem in near perfection by just having a few actual human beings look over the code of newly submitted or updated extensions.
Google has magnitudes more money than Mozilla, so they could easily afford to just copy that, too.
Is F-Droid a walled garden?
Walled gardens just keep small developers out of the marketplace by rising the bar. Now you need to pay money or have a name, so WhatsApp, Viber and similar shit can retain monopolies and keep their users despite being filled with ads and offer less security than competitors. Jabber clients and independent media never get a "verified" badge.
If you want to download "genuine" WhatsApp, go to their website, check their TLS certificate (you can never be sure, they don't even bother to get a EV cert, even for WhatsApp web; https://app.wire.com/ has an EV, for example) and follow the link to Google Play. Software repos are not here to do the job of CAs.
There's a list of guidelines your app must conform to, and Apple is generally more aggressive about catching violations before app release compared to Google. There are consequences to this, like Safari-WebKit being the only permitted browser engine on iOS. Any other browser must wrap this engine.
The grandparent post is likely pointing out the dissatisfaction that devs express regarding the Apple app store review process. It seems like it comes down to an engineering trade-off. At some point you have to choose between developer experience and end user security.
I prefer solutions that offer both, freedom and security. Such as proper application isolation, user review systems (a tough nut, yes) and generally having better reputation/quality signals than just a company name.