I think the answer might be to codify some of these assumptions.
It might help set things apart from say ubuntu, which doesn't engender the same amount of trust such as opt-in.