Gatekeeper is meant to prevent a wide-ranging attack. If you've got someone custom crafting an attack vector for you specifically, you've got some serious problems. I don't think Gatekeeper adds any more false security than an antivirus app would, and I don't know of any software that'd prevent an attack like this.
At best, it adds a small amount of information for authorities to try to track the attack. I doubt it'll be fruitful, but it's better than nothing.
So yeah, I guess in a certain light, a machine that can't launch apps is definitely secure.
That sounds kind of shitty to me... Is there any simple way around that?
It's true that we could do that, but their original purpose was to protect us in the first place. The same is true for code signing certificates, to a certain extent.