At the same time, a lot of modern security discussion is centered around the user being tricked or guided into making mistakes or that it's hard to differentiate between a user or a malicious program.

For example, forcing automatic updates with no postponement because users simply won't apply security updates otherwise. Taking freedom away from users? Yeah, kinda. Increasing security? Absolutely.

