On the one hand, as a developer, I agree with you.
On the other hand, as a user, and one who has to do de facto IT support for my family, I strongly disagree. Having an off-store method of installing apps is just dangerous. You could argue that it's a question of Apple having an incomplete security model, in which they enforce through human review that apps do not perform malicious behavior. But Apple is just pretty good at this -- the rare app that slips through their net is usually quickly caught and killed, and their security on-first-use opt-ins "Allow this app to access your camera", along with enforcing that apps for whom the permission is denied must still function, is critical, compared to the Android "Allow this app to access all device state forever including private information and your entire DNA sequence" that you get on app install.
On the gripping hand, advanced users, like developers, can basically sideload whatever the hell they want. The barrier here is a lot stronger than a checkbox in settings saying "allow sideloading apps" and thus is intrisically more difficult to access, and then only by people who know what they're doing anyway.