"By default". Most developers don't bother to register, and lots of people change the default (and after that, they can right click to open the app and bypass the warning).
I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name.
[0] http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
(There is third party tool named RB App Checker which does make these tasks a bit easier, though)
――――――
¹ — https://en.wikipedia.org/wiki/Installer_(OS_X)
² — http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_insta...
“The two KeRanger infected Transmission installers were signed with a legitimate certificate issued by Apple. The developer ID in this certificate is “POLISAN BOYA SANAYI VE TICARET ANONIM SIRKETI (Z7276PX673)”, which was different from the developer ID used to sign previous versions of the Transmission installer. In the code signing information, we found that these installers were generated and signed on the morning of March 4.”
From: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
and that didn't ring any alarm bells?
“And according to the analysis, this is exactly what they did. They used a different cert to sign their malware. I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name.”
“Yeah, I think this is a major issue on OS X. For the average user it is impossible to tell who signed an app, if it is sandboxed, and what permissions it has. Hell, using the codesign command to extract entitlements from all binaries in a package is hard even for advanced users... (There is third party tool named RB App Checker which does make these tasks a bit easier, though)”
…in this comment thread: https://news.ycombinator.com/item?id=11234966
[0]: https://forum.transmissionbt.com/viewtopic.php?f=4&t=17835
Many people would uninstall and download it over again when running into that kind of error message.