> mitm attacks can't do much other than see which packages you install
On the contrary, if you MitM the entire downloads page you can simply offer up a hacked/backdoored version of the software. There is no signature check if you remove the signature check in the version that you distribute.
Sure, in this day and age, it's slightly disconcerting to see a security-related website that isn't SSL, but on the other hand, the tendency to blindly trust the green padlock is probably even more dangerous.
http://keepass.info/integrity_sig.html https://keybase.io/reichl
It may be flawed, but clowning the CA model is beyond the abilities of the vast majority of attackers.
But TBH, if I am going to go through the trouble of MITM'ing the site, then I am going to rewrite the site to:
* include my awesome fingerprint
* link to my awesome key
* link to my l33t entry on keybase
Side note - the CA model has issues, but in what world is pointing users to a VC funded startup that has only been around for two years "safer" than the flawed, but well understood security model of the CA system?
I don't mean to impugn Keybase, from watching them I like what they are doing, but bootstrapping trust based on content they control is hardly ideal, and I would be shocked to hear someone say that Keybase is more reliable or more trustworthy than the CA/Browser Forum (10 years old) and the browser vendors (>20 years old depending on vendor/code base).