I also brought mine with. Took it out while I was waiting and realized it was full. Put it back in my wallet. When the pharmacist came in she handed me a new card.
You can make rules network-wide, per-app, or per-incident. The latter is useful for getting a handle on app behavior. Like if you see it contacting 'updates.somedev.com' weekly, you can choose to allow or disallow permanently based on how benign you think the app is. But more likely, anything trying to phone home has a dozen CDNs it's trying to hit rather than an easily identifiable URL. Block one, it tries to hit the other. Maybe today, maybe next week. It gets overwhelming (which IMO is a feature for the dev, not a bug).
I happen to like having the edges of my fingers or hand touch the screen inadvertently every time I pick up my phone. Bonus points if it's unlocked and something unintended happens as a result.
Your username suggests you might be a bit biased in your assessment.