@mhoye I think all security warnings are an extremely hard problem, because they're almost always false positives (most people aren't getting attacked, thank goodness). It's really hard to be sure it's not a false positive so you throw up the alert, but then people get alert fatigue and etc etc.
(We sort of went through the same thing with browser HTTPS warnings until browsers made it really, really hard to get past them and everyone accepted that sites shouldn't screw up certs.)