Just want to say I super appreciate your balanced perspective here. I'm not a security engineer by trade, so getting this sort of feedback is quite valuable.
The no@ scenario is an interesting one. The opt-out would certainly be one clean approach here. Going to give it some thought!