@ caffeine addict
Safari doesn't just wily nilly download stuff. The USER has to click on a link, etc. to download something. The USER knows where they are browsing and what they click on to download.
The USER can also change this behavior, if they want to change the location of the download or be asked before a download, those are all options they can change within Safari preferences. They can also deny ALL downloads, cookies, etc.
The fact that IE or other windows programs will start a downloaded executable out of the blue, without asking it to, is definitely a problem, and M$ needs to fix this.
If a USER was navigating around nefarious sites and they the USER clicked on spoofed links that downloaded malicious executables, then this is a problem... however, EVEN IF Safari was set to ASK before downloading what the USER clicked on, the USER would mostly likely 100% of the time say YES, and click "don't ask me again"! If it really is a spoofed link, then the user won't know the difference anyhow, and accept when prompted. This would be the case UNIVERSALLY with ALL browsers.
So again, it is up to the USER to be smart, not to walk in bad neighborhoods. You walk in bad neighborhoods, you could get mugged, shot, or worse... just don't do it! It's the same with the web.
Now, if the USER simply got lost because of being naive, I agree, there should be more Cops around to direct the poor soul back to safety... however, it's again up to the individual to listen. In contrast, if those Cops consistently give bad advise, wrong directions, or over state a non-existent danger... it feels more like a limit to our freedom, then a protection.
On that topic, we also have to be careful, as the most dangerous alarm, is a false alarm. False alarms, condition people not to listen to alarms at all. Then when it's real, people die. It's the same in the web and browser world. Too many annoying false alarms, and people just turn them off, as they don't work. Additionally, alarms that don't work, give people false security. Therefore, if security is to be implemented, in needs to work 100% of the time with no false positives. Otherwise, it's better for the user to know that they need to be alert, and stay in the good neighborhoods and how to spot spoofed links and sites that could be dangerous.
CYA security is not real security, and does more harm then good IMO.