> As long as the walled garden can be easily circumvented, advanced users can do what they wish. "Able to learn about Gatekeeper and decide if they should turn it off" is probably an okay heuristic for "can tell a fake Flash installer site apart from a real one" or even "knows that Flash is pretty much abandoned, do everything you can to avoid it".
That's exactly how I see it! And this mentality continues throughout the chain, too—if you want to actually install unsigned kernel extensions, or inject code into other processes, you need to boot into recovery mode to disable SIP. This is still not at all onerous if you know what you're doing (and, like Gatekeeper, you only need to do it once), but it's definitely a next-level test for next-level privileges.
IMO, the way Apple designed this process is brilliant! And that's why I'm not personally concerned by the boiling water argument, at least not yet—whatever Apple's incentives, the current setup strikes me as the best way to handle things.
All of that said, where I am starting to get annoyed is with the root snapshot stuff in Big Sur. Having to reboot every time I want to edit a system file is a clear progression from "trivial speed bump" into "consistent pain-in-the-ass" territory. If you want to talk about Apple locking down the Mac, I'd start there!