As a long time gentoo dev I am happy that this gets more attention. Although this is an open secret and completely obvious.
Gentoo's rsync-based system was always insecure. There have been multiple attempts to implement some kind of package signing, but it never made it to deployment.
A workaround right now is to use git-based sync over https. You can sync from https://github.com/gentoo-mirror/gentoo which is a copy of the portage tree with pregenerated metadata.