I think a lot of people have been spoiled (beneficially) by using large, professionally-run SaaS services where your only serious security concerns were keeping your credentials secret, and mitigating the downstream effects of data breaches. I could see having a fundamentally different understanding of security having only experienced that.
What people are talking about doing with OpenClaw I find absolutely insane.