An example of the bad side is that Nvidia says they cannot develop drivers for their cards because Apple hasn't allowed them to (Apple develops the drivers). I technically believe they can, but they would have to make the user jump through some very unreasonable steps (reboot into a maintenance mode and disable integrity protection).
Just confirming this is accurate. SIP wouldn't need to be disabled completely, just the blocking of unsigned kexts. (Apple allows you to selectively enable and disable pieces of SIP).
I don't think this would be so wholly unreasonable. The types of users installing third party video cards in their Macs are the types of users who should know how to do this. At the cost of their security, you could argue, but of course you still have normal Unix root restrictions to protect you there, as long as you're savvy enough to not grant such permissions to any random software.
Unless of course by enforce you mean taking control of the sandboxing away from the user, in which case I totally agree that should not be done because I'm against that kind of user-hostile bullshit.
Nearly every effort I've seen by OS makers to implement sandboxing by default also makes the sandbox difficult or impossible to disable. iOS, UWP, the list goes on. I agree they shouldn't be connected, but they nearly always are. And it's always done in the name of protecting users.
macOS is the one bright spot here, and even then, the new dialogs in Mojave that can't be disabled fare crippling if you make heavy use of apps that need access to other app's sandboxes[1]. I'm convinced that if Apple moves to ARM, it will likely come with a massive tightening on user restrictions, in the name of security.
[1] https://apple.stackexchange.com/questions/339509/edit-tcc-db...
Sandboxing should be done, treating users like children who need to have control stripped from them for their own good should not.
As soon as you implement the option at an OS level, there are going to be (many!) developers who want it enforced for all users. It's the obvious path to go down.
Note, I use Dark Souls as an example here (as opposed to, say, Skyrim) because Dark Souls mods were very much not developer-sanctioned at the outset. If From Software had needed to explicitly allow mods, you can bet they never would have happened.
Maybe if these notifications were less vague, they wouldn't be hounded as annoying and useless... Just saying.