Because if the hole exists at all, malicious actors will find a way to abuse it. But if non malicious developers have to jump through too many hoops to provide useful functionality to users they will just give up and users lose out.
Yes, they will. So the question remains: why expand the hole?
If I can unlock your computer with your password or with the word "hello" and you have no intention of removing the "hello" feature, would you not agree that we might as well remove the password entirely?
How do we increase the attack surface of service workers by adding background sync, when we can get nearly identical behaviour using push?
If you goal is purely to not increase the attack surface, you might as well never add any new APIs ever.
> when we can get nearly identical behaviour using push?
The devil is in the details: is it nearly identical behaviour? How nearly is it identical? I personally don't know.