>it's more like devices should consider security holistically and only offer an API that is secure
I am not against this, this would be ideal.
>Hacker News doesn't allow any users to edit any other's comment
Those comments are not yours, so this is a false analogy. I am talking about something that is technically possible and within your own device.
>Just because an attack may be niche it doesn't mean that the vulnerability should be ignored
True, but I also believe that preventing the users from fully using their devices is not good, providing an API like you said would be the perfect solution.
>Because the drive should be encrypted
The average user doesn't know about drive enryption.