You know what else is reasonably obvious? Those checkboxes saying "Yes, I want to also subscribe to this other site for an addition 29.95", pre-checked on the final checkout screen.
It's not reasonably obvious that after turning the passcode on, that it effectively doesn't secure anything, and it's irresponsible to think that way.
There are a grand total of 6 fields on that screen. One of those fields is prominantly labelled as "Siri". It's not like it's being hidden in small print.