> Most security nerds find app signing and sandboxing a good idea.
Those same security nerds have been doing both on FLOSS operating systems (BSD, GNU/Linux) for years, so that point is irrelevant to the original discussion.
Which is not the same at all with having thousands of proprietary third-party apps to distribute in closed source form (as opposed to having control of some open source repo with redistribution and re-compile/modify etc) right.
So your point is even more irrelevant to the original discussion.
Those same security nerds have been doing both on FLOSS operating systems (BSD, GNU/Linux) for years, so that point is irrelevant to the original discussion.