IMO: the lesson here is that restricting people to the OS vendor's software repository doesn't prevent malware. The only way to even help that is via community review (note that apple doesn't review internal behavior of the apps or instrument them in any way, they just have someone try using them behind a proxy) and enforcing public available source code like fdroid.