This is just terrible news. Android's treatment of user-added certificates is already terribly broken (why does it warn me that my network connexions may be monitored when I install my own certificate, when Android already trusts e.g. Symantec?), and this makes it worse. What they should have done was gone the other direction entirely. If I — the owner of the phone — choose to trust a certificate authority, then ever…
For in case YOU didn't put the CA on your phone.
At some point, it should recognize that you've continued using the cert XX times or for XX days or both and stop trying to guilt you into removing it via the use of some illusory 'you might be insecure' bogeyman, when Symantec, an already 'trusted' CA, could issue any cert for any site and you'd have no recourse or ability to tell if they should have.
Everyone 'might be insecure', that's just how it works.
*Maybe this goes away at some point months down the line, but it's at least 30 days and has to be some number in the 1000s of uses if the warning eventually quenches.