It's a protocol issue because signers can't possibly inform what is supposed to be decrypted (not even the kind, apparently). A malicious app could tell you it's for "encrypted settings" or whatever, and instead use it to pull your nutzaps and rug you.
DMs are just one kind of thing that can be encrypted. Obviously allowing all makes that even worse.
