I'd consider this a genuine security issue, and wouldn't be surprised if the dev console at least got moved behind a lot more 'here be dragons' warnings.
or hide it behind a turing-test-for-engineers ... 'solve the following code test to enable the dev console' ;)
Another place where you see this sort of thing: banks that try to prevent password managers from filling in your credentials (also I've seen a few recently that try to prevent you from pasting in your password).
There is a tradeoff there too: like this Facebook trick helping save some users, bank tricks probably help some users from accidentally saving their bank credentials on some public or shared computer, but it makes it really annoying (or not possible short of opening devtools and setting the input box's value manually) for those of us that want a unique and more-or-less random password for each site we visit.
It's neat for small changes as you don't have to write a whole extension just a simple script.
javascript:alert('hi ' + document.body.innerHTML);
If people can be tricked into executing code in the dev console, then why not this too?edit: Ooops, someone had already made a post to this effect. Sorry.