PowerShell has weird restrictions where it'll refuse to run scripts unless they're signed and stuff.
If the sysadmin chooses to, otherwise PowerShell can be run arbitrarily
The key is that unsigned scripts are opt-in, not opt-out. Chen is not going to suggest a solution that requires all users of the software to configure their computer to be less secure.
It's not really a security measure in that sense. It's a "safety feature" that prevents accidentally running such a script. Anything can trivially disable the protection using a bat script (or anything else) to bootstrap.
E.g. `powershell.exe -ExecutionPolicy Unrestricted`