Your mom would have to go out of her way to find and install a separate app store. You could make it give all sorts of warnings that would scare off a non-tech user like your mom.
Agreed. I primarily work as a sysadmin and the amount of people in my organization that fall for phishing is alarming. It’d be incredibly easy to get someone to turn on the “Allow third party apps” setting and install malicious software. People don’t read warnings, they’ll just click “ok” as many times as they need without reading.
That being said I don’t think that’s necessarily a valid reason to completely lock things down, but it definitely should be prohibitively difficult for a vulnerable-to-phishing person to enable.