Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."
"we will never ask for this over the phone" takes second place to:
"we will send/save you money/time if you make it convenient"
dress it up to taste like developer needs, and you can hook the newbies.
Doesn't help that the banks then do, in fact, call you, and ask for this over the phone.
in my region AT&T has a very explicit statement not to reveal MFA codes to anyone who asks, is not part of thier system to do that.
there is 1 bank in my area that does voice call relay over the phone, the others keep it 10 fingers relayed from phone to authentication form.
guess who has the most problems with account compromise, and fraud claims? yes, that one bank. it has a phishing vector in its system.
A measure needs to be in proportion to the actual risk it seeks to mitigate.
And even when they are required, it's up to the person using the stairs to determine whether they wish to elect to use the handrail or not.
[1]: IRC R311.7.8
That means, handrails cost little and have nearly no downsides. Which is why I used helmets as a metaphor. The proposed restrictions has a lot of downsides to deal with a mostly theoretical risk.
It's easy enough to imagine that Google is trying to fix something they see as a problem, and not caring about the developer case rather than specifically seeking to destroy it.
When Apple fixed security issues that allowed for jailbreaking, they weren't doing it specifically because people use it for jailbreaking, they were doing it because it was a security issue.
We should have 100% control of our own devices. But we should have it by design, in a fashion that makes sure that we control them rather than other people.