Taking away the user's ability to manage their own security should bring with it the responsibility - and liability - for any problems that derive from the imposed settings. The paternalistic attitude that users are and always will be ignorant is not only offensive. it is counterproductive. Security is not a product, and keeping people ignorant of the trust models they are relying on is a recipe for disaster in the l…
I very much agree with the liability responsibility and liability argument that you're raising. I also fully believe self-driving car makers should be 100% responsible for accidents and hacking incidents of their cars and they should fully compensate the victims of such accidents and hacks. However, I think this is generally a good thing. When Android has 50 different OEMs (or whatever the number is), then some stand…
I'm ok with this. Even if I can't add a custom root certificate, I would like the ability to distrust any root certificate I explicitly do not like. That coupled with standardization of certificates loaded by default makes this sound like a welcome change.