Second, because no mechanism is immune to manufacturer tampering.
Both Chrome and Firefox ignore pinning errors when it's signed with a local root.
You can't be more secure than the OS you're running on.
Alternatively, the next Superfish could just patch that check out.
But if the portal was going to redirect you to some ads or other "value-added" content, then they may not want that window to be killed. My former local Barnes and Noble would explicitly whitelist Windows' detection URL, so that they could redirect you to the BN home page instead of to the page you were trying to visit.
Cisco has explicit documentation on whitelisting Apple's URLs... and in turn, Apple has switched from testing a single URL at apple.com to "as many as 200 websites". https://supportforums.cisco.com/document/11934456/captive-po...
And seriously, let's admit it - the "value added" thing is bullshit, and captive portals are mostly either useless (TOS that no one reads anyway) or evil ("value added"). And as I see a few of my cow-orkers working on a captive portal right now, I can't help but think that marketers indeed live inside a strong reality distortion bubble, not realizing that the product they want is making everyone's life worse.