While agree this BIOS update situation is poor, is there any proof a large number of 'common users' are affected by MITM attacks? The average Joe is not doing harbouring any state-secret. This is similar to 'stage-fright'? Please give numbers who got affected?
On the other hand, I find people are very relaxed enabling remote desktop or teamviewer (as it promises them to access their file anywhere) and using the same password.