As for point 1: that depends; if your business operates on keeping the center of the bell curve happy, and you don't like to risk that, than implementing something that degrades that doesn't seem like a sound business decision. Keep in mind that this is from the 'producer' perspective.
As for point 2: that should indeed be how it works, but the circumstances have changed, especially for large scale general purpose computing, and for various reasons and stakeholders as well. This is also the (wrong) fuel on the (wrong) fires in the current discussions on ownership, repairability and shared systems; it often tries to compare the "now" with a chosen "back then", and leaves out externalities causing the whole comparison to be useless.
For example: it used to be that you could run whatever code you wanted and you didn't need anyones permissions and nobody could stop you. Now, at scale, that means everyone from teenagers at schools circumventing the implementation of a usage policy to state-level actors extracting information would run whatever they want. They are of course already doing that to some degree, but this would be so much bigger and so much easier when you just 'run whatever code appears at the JMP', we might as well not have an internet.
This, in turn, means that you have to have some form of control, and some form of distribution or supply of such control as neither the will, nor the skill exists at the required scale to have everyone do this individually. How does one assert such control? Cryptographically. And now you're in PKI hell, or you're in DRM hell with DRM servers that go offline and render systems unusable. Oh, and you get DMCA and Legal requirements for free too.
It would be amazing if we could figure out a way to operate shared systems, and have some form of delegated control without having a PKI-like authority as the only way to ensure it. But I haven't seen it yet :-(
And this is just one of the many issues.
Take hardware for example; you can do plenty of nefarious things with hardware, and the user would never know about it. Want to backdoor an audio module so it constantly streams what the microphone picks up to an actor of choice (a social media company, advertising company, your abusive spouse, the government of a state that will hurt you on detection of dissent), you can do that and no normal user would ever notice. How would you then prevent such modification? Well, you could make hardware hard to access or hard to modify without visible marks. That's one area (slightly) covered, but then there is the software, imagine hacking that remotely. So how would you do something about that? Perhaps signing the software and checking the signature. Bam, back in PKI hell.
And if you were to make hardware hard to access, now you have a bad UX when someone comes to your service department and gets presented with a huge bill because your device had to be rebuilt because your kid put puke in the microphone hole. But if you make it unsafe you have the other problems again. No winning deal there. Or what if you use seals, now you have no idea why the seals are broken. Did someone tamper with it? Was it just a service call that's not registered in your system because it was done elsewhere? Who can you trust? What if you fix the reported issue but now something else breaks and you don't know if you did it or the previous tech did it? Guesses everywhere, everyone is sad, nothing works. yay.
Again, no real solution here. Say you do the (not very often implemented) secure boot method where you insert your own CA; that's great for yourself, not great for a shared system, because now everything else that requires you to be securely booted needs to trust that CA too. This, hoever, is an area where you can do a partial fix: if you just want local verification and you have the CA and CT you can at least know for yourself. But that doesn't work at scale. We can't expect billions of people to be PKI experts. And we can't expect them to understand the ramifications of the lack of verification either. (which includes effects on them, but also effects on everyone else they are in contact with by proxy) So now you still need that 'magic' central authority making a policy and a verification for that policy and enforcement. PKI hell all over again!
(keep in mind, I don't name PKI hell a hell because PKI is bad, I think it's great and I love me some hashing, public-key cryptography and root-of-trust chains -- it's just that there is no solution right now where you don't end up having an authority that can use it for good and bad at the same time)
There are a lot of scenarios where we could mitigate 'some' of it:
- Authenticated core but leave peripherals alone (your mainboard and CPU and AV chain would be on its own, but your keyboard can be key logging you as much as you want)
- Unauthenticated mode but no interaction with shared systems (would work great for things like farming equipment)
- Offline or do-it-yourself mode (again, no interaction, but you'd be offline anyway)
But then you're still in the realm of real-world abuse (want to know your ex'es password? backdoor the keyboard! steal your boss's documents? backdoor the printer!).
I don't know how to fix all of this, but removing all forms of authentication and still having shared systems isn't the way.