See another user's comment: https://news.ycombinator.com/item?id=38594247
Security is an onion, perfect is the enemy of good, etc...
Why make it easier for the adversaries? While annoying, running EPP on your desktop OS is not exactly neuroscience.
Ideally, it's furnished by the OS provider so that there are fewer parties to trust. I hate to say it, but Microsoft is now teaching by example. MS has factually one of the best-in-class Endpoint Protection agents on the market.
If resources allowed, all other desktop OS providers should follow suit, otherwise they are just shirking responsibility.