The security model is well-known among developers to be "based on the assumption that 1) you only pair with a device you trust" (quote from #424889 comment 3). This should be displayed prominently prior to pairing. It is not self-evident in the GUI. The need to explain in the bugzilla and the various open bugreports based on the wrong assumption are proof.