People make mistakes. Security engineers need to understand what sort of mistakes people are making and mitigate that risk. Brushing it under the rug as silly users making mistakes doesn't protect anyone.
Also, many of the top 100 domains serve user-generated content (like AWS/S3). Blindly trusting anything from them just because they are big is so woefully misguided it boggles my mind; I seriously doubt that anyone is actually doing what is described in the article.
If we expected airplanes or cars to be able to be safely operated by people with zero understanding of how such vehicles work, nobody would be getting anywhere.
You eventually reach a level of stupidity and/or incompetence after which trying to alter the product to coddle those users becomes counterproductive.