I wouldn't say it's the result of bad heuristics. It's coming from not being able to fully trust your user and Goodhart's law. A small minority of your userbase might be extremely motivated to attack you, and giving them explicit reasons for your actions will just make your security policies ineffective faster.

