Firefox does not use the OS's certificate store. They use their own, and each root cert must pass Mozilla's own policies. There are long discussions about some cert issuers; see Mozilla's "dev-security-policy" mailing list.
Somebody should file criminal charges against some of these outfits for violation of the Computer Fraud and Abuse Act. From the article: "the installers are so tricky and convoluted that we aren’t sure who is technically doing the “bundling,”". Now that's a good argument that the user gave the "bundler" permission, and they have thus "exceeded authorized access", as the Computer Fraud and Abuse Act puts it.
That would be great if the CFAA and the relevant police resources were actually used against fraud and abuse, rather than being used against copyright infringers all the time.
Fair point (and kudos to Mozilla), but unfortunately this doesn't protect 90% of other traffic passing through the host. As many (if not all) of the victims of this kind of attack are laypeople, a broader approach may be warranted.
Somebody should file criminal charges against some of these outfits for violation of the Computer Fraud and Abuse Act. From the article: "the installers are so tricky and convoluted that we aren’t sure who is technically doing the “bundling,”". Now that's a good argument that the user gave the "bundler" permission, and they have thus "exceeded authorized access", as the Computer Fraud and Abuse Act puts it.