> Why do we pretend that social engineering scams don't exist outside of installing anti-viruses?
That's was an example, but only an except. I think equally plausible is "my bank called and told me my app was broken and that I needed to redownload it. I tried logging into the new app with my bank username and password, but it didn't work. What's wrong with my phone?" Now, Apple doesn't have a perfect track record for catching and blocking these things. Their security controls are definitely better than not having them, though.
> The solution to this problem is EDUCATION
No, no, no. One of the things drilled into your head at security engineering and management conferences is not to ever trust the human factor. Education is a good thing to have in addition to all your other controls, but is a terrible first line of defense. People make terrible choices all the time. Maybe they're sick, or they've had a drink or three, or they're worried about something that happened at work, etc. etc. etc. Even smart people who've completed security training still make dumb mistakes.