The difference is IE7 took anything that wasn't on Microsoft's list of "approved" certificates (including self-signed) and put a great big warning on it, rather than actually explaining why it doesn't trust it.
It's a big annoyance, since most of the people I work with don't need, let alone want, to shell out money to get an "approved" certificate, but keep getting calls of people in a panic, thinking their site's been hacked because they're using this piece of crap from Microsoft.
Opps, sorry. Is my bias showing? ;)