Johnathan Nightingale of Mozilla has a good blog post explaining the rationale behind this: http://blog.johnath.com/2008/08/05/ssl-question-corner/ An especially pertinent point from his post: "Several CAs accepted by all major browsers sell certificates for less than $20/yr, and StartSSL, in the Firefox 3 root store, offers them for free."
As suggested by the original article, the correct behaviour would be to treat it as though there's no security whatsoever. After all, logically, how is being encrypted but unauthenticated worse than being unencrypted and unauthenticated?