Additionally, if can find a way to trick a user into installing a malicious kext, why even bother with PACMAN? You already have arbitrary kernel code execution!
/s, though not entirely, moving more stuff to unprivileged contexts would be nice
But yes, there was a time when editing even /etc/sudoers required disabling SIP. That time is long gone.