But why do USB devices even accept unauthorised data at all? There's probably a good reason for it that I don't understand, but it seems to me it's rather obvious that blindly accepting data from unknown devices is quite a big security risk. And yet I keep seeing these new data port standards (USB, thunderbolt, etc) that just blindly trust whatever gets connected to it, and allow it unreasonable control over the device. I guess the reason is that you want to be able to plug a new keyboard into your PC and have it just work.
Or maybe the user just shouldn't give physical access to devices that are not trusted.
As for not giving physical access...easier said than done. Looking around, I see multiple such devices lying around here, with the owner within 20 m, but not paying attention. IMNSHO asking for authorization is far more logical than assuming "whoever can get their hands on it is authorized."