Easy to say. Care explaining? These signatures seem like exactly the thing to prevent mitm attacks. I trust signature A; i won't load the package unless it's signed by signature A.
Most people won't be that strict in informal development, but that's not really what this is about.
Most people won't be that strict in informal development, but that's not really what this is about.