It didn't protect you at all, it was more of a package manager GUI than a proper store, it just had some repositories where you could upload paid packages. And generally, you wouldn't really install apps from it (with both notable and non-notable exceptions, of course). You would install 'tweaks' which normally were iOS plugins/modifications of various sizes and functionality. They all had root privileges an a lot of it was trust based. I don't think there have been a whole lot of malware distributed in this way.
An alternative store with open-source apps, without the opening of the jailbreak and that could be verified by users, would be a good amazing start.
The EU seem to stopped fighting against misuse of power in IT. Only when a competitor has money fight?
On the other end we have this awful Cookie-Directive. A disaster and misuse is now on even worse.
The legislation is really good actually; it orders sites that want to place tracking cookies (Google Analytics for example relies on this) to request consent from the user before they're allowed to do so. That's all it requests.
This could easily have been implemented in any number of user-friendly ways - ie. Store one cookie for Google Analytics as a whole that is just "I don't consent", that would have been enough to comply. Just check "did user consent or not". If they didn't, then don't show the popup on any site using Analytics. Problem solved, consent obtained and/or rejected.
The reason it's so obnoxious is because these businesses know that if they start being honest with what's being tracked, they'll lose a shitton of income (Facebook reportedly lost 12 billion just because Apple allowed users to randomize their advertisement ID). They don't want that, so now CJEU has to slowly but surely beat actual compliance into them.
Nowadays you have to have an opt-out option that should be as easy as not opting in (so no more "50 million tracking slider" nonsense), the opt-out option can't be obnoxious to find and click, the opt-in button may not receive extra promotion compared to the opt-out button and so on. The only step that's not yet complied with is that if the user indicates that they just don't want tracking period, then they shouldn't track at all (basically enforcing the good old DNT header).
The problem is that “tracking cookies” is defined so broadly that it can be interpreted as nearly any kind of cookie, and risk-averse legal teams want to make sure they have all their bases covered.
The GDPR was supposed to outlaw spyware. 5 years later, Google and Facebook are still in business.
If the enforcement of the DMA is like the GDPR's, you're gonna be waiting for a long time.
However, because the law will actually go into effect in two months, I expect the EU's inevitable case against the various gatekeeper companies to take into account decisions and practices from this May and onward.
Looking at the way the GDPR introduction went down, I expect large websites to start posting panic posts around January 2024, telling us how the DMA is going to kill our kids and poison our wells.