I get the sentiment here, it's very annoying for developers (including me). Establishing trust is very hard problem, though. Let's move this to a productive conversation though. What can Microsoft do, as an alternative, that doesn't result in an identical or worse situation? Giving out free code-signing certificates also makes it easier for malware to get legitimate certificates. This is akin to LetsEncrypt for certs…
Absolutely. I think it's easy for the HN crowd to inadvertently forget what computers / phones / tablets / TVs look like to ordinary people. I would encourage people to come up with actual use-cases and pro-con scenarios rather than 100% "emotion mind" opinions.
It took me about 15 minutes to get my Android Phone infected by a malware by downloading just apps from Google Play. If Google is failing in such basic task for "ordinary people", all MS accomplishes is to annoy regular developers, making their apps "suspicious" to the public.