Good point but one additional advantage on mobile is the app stores. Currently apps are (supposed to be) rejected if they ask for more permission than their app requires. The problem is that the permissions themselves are too broad. If permissions were divided between regular permissions and super permissions where the latter were flagged for extra approval time and care in approval, it seems like you could have a scalable system vetting the handful of apps that risk asking for them.
Additionally it seems like you could design proper super warnings that get adhered to. Do you know of any interesting examples of really severe/gated warnings that are consistently ignored? If you try to visit a website with a bad certificate, for example, it's almost impossible to get to it.