The whole setup makes installing apps from other sources obtuse and 'scary' to the average user.
I'm not sure how say an app from f-droid is more 'unknown' than an app from the play store myself. Then of course, just to install f-droid, I have to download it, allow installing apps from my file manager, which comes with some scary popups, then I have to again enable the setting for f-droid, again after some scary popups.
The goal really does seem to be do make the idea of installing software one acquires outside the 'official garden of known apps' to be something terrible and scary nobody should ever want to do.
...yes? It's not a bug, it's a feature. For the average Android user, it SHOULD be obtuse and scary to install apps from a third party source. Power users can still use a third party app store.
It's a tradeoff for freedom vs a false sense of security. On android at least, the walled garden approach hasn't seemed to stop malware, the majority of which, comes from the play store. All it's done is teach users to blindly trust apps just because they come from a supposedly trustworthy source. If anything it's taught people to think less about security and the kinds of apps they install. It's on the play store right? Must be ok.
Scary in terms of telling my mom to do it - absolutely. At least the Play Store has some (imperfect) curation, and SafetyNet.
For the layman, the walled Garden is a feature.
I've also helped other people deal with these problems before. I found that aftwr taking the time to show them how they end up inatalling that crap, the kinds of things to avoid and setting them up with some removal tools they tended not to make the same mistakes.
Jesting aside, it's not a bug in the sense that Google also gains nothing and actively loses money from making it easier. At this point it's just to avoid PR nightmares that they are keeping it in.
Not only that, but every now and then when trying to update an F-Droid installed app, Android pops up an unexpected dialog asking if I want to enable "Play Protect". Its unpredictable, breaks the flow of the update process, and seems to have no way of disabling it.
To which I say....have you seen how complex the process is on android?? I can't imagine that that is going to be a problem. They will be just sent a dodgy website link that will steal their bank details, not some app that most people won't figure out how to install.
So that would then be a good thing, right? RIGHT?
I think things have become a bit more saner with Android 11 in that regard (though there might still be some pain points left), but instead the next random thing Google has broken is that you can no longer replace the default camera app - unless whatever random app you might be using specifically whitelists your favourite third-party camera app, you can no longer use it other than in standalone mode (i.e. if I understood things correctly, the same hare-brained situation you were in until very recently on iOS with regards to the default browser or other default apps).