I totally agree they're easy to dismiss and start to feel cumbersome, but if "protecting users" is their actual motive (I doubt it), this would be a reasonable way to handle it while giving power users the flexibility they want, and that there's high demand for.
Log in to Facebook.com and hit developer console. Can't totally idiot proof it, but people do read enough warnings if you yell loud enough. Which puts it on them.
Half the issue is, people need to acquire the same wisdom about cybersecurity hygiene as they do looking both ways before crossing the street, but even that's too much to ask for some people. They just don't do it.
At some point, it has to become the responsibility of the potential victim, if liability is such a concern from big tech companies.
Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."