Sandbox settings?

This is a hard question to make so I will do my best.
In D+, Sandbox Settings, we have 2 options:

  • Automatically detect installers/updaters and run them outside of sandbox
  • Automatically trust files from trusted installers

With the releases of digi-signed malware, I ask from professionals/experts this:
Is it better to turn on for ease of use or turn off for security?
Languy, what would your recommendation be?
I would disable the autodetect installers/updaters
(unless your update/install software every hour on the hour like some of us techie’s)
Keep Automatically trust files from trusted installers check

Thanks, Jacob, that was very informative and helpful, my respect to you, will proceed per your instructions!!! :-TU