Allowing a user to add system certificates a good thing. The user owns the device.
Everything in the category "the user owns the device" is tricky. For a lot of users, "It's really hard to break" is a value-add. Every capacity the user has to modify permissions is an opportunity for an attacker to compromise a device. You can see an example of this in web browsers these days, where sites have to `log` a big scary "Don't paste anything someone tells you to paste into here" message into the built-in…
"It's really hard to break" should not be conducive to the dumbing down of the populace. Enabling power users is therefore more desirable.
And importantly, the two do not have to be mutually exclusive.