Actually the simple solution is to incorporate something like Gatekeeper which verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered. Just stop using the App Store as the only means to software installation. Problem solved. Why deal with this issue in the first place is what Apple needs to be thinking about given the current political environment. You can still have the Apple store, but then no one will be claiming that they are forced to buy only from the Apple app store.Simple solution - Allow side loading and different app stores, BUT have a switch in settings that allows only downloads from the Apple App Store. Make that the default setting. When the user decides to side load an app and turns this off, they get a warning telling them that that are about to lose their warrantee, AppleCare if they have it, and all service options for their phone by doing this. They take full responsibility for any cost viruses will add to their system.