But the reality is different. On my smartwatch (an older Samsung, but same Google OS merged with Tizen) there's a PIN required if you enable payments on the watch. I understand why, the secure element requires it. But it makes every other feature of the watch useless to me. I don't have any secrets I want a watch to protect. I want to be able to time workouts while standing on a treadmill.
They could solve this, only have large amounts require the code while letting me buy a coffee without it, but I'm sure there's some line in an agreement between Google and the banks prohibiting this. The risk has to be transferred to the customer, even if the likelyhood of somebody buying a coffee with my watch is low.
Product design should consider all of these things, but getting out the next smartwatch without thinking it through is more inline with quarterly objectives. There isn't even a Steve around to piss off enough to do something about it.