Which is not true. Little green lock means the site has HTTPS, being safe requires much more than that. Security is hard to explain.
I even wonder how many people download an ISO or installer from a website, and do any sort of due diligence to find the signer's key from another 3rd party location, then verify previous builds, or require multiple signers of a key to give any semblance that the key is not fake? Or do we all just download the ISO and the .iso.asc file from the links provided and call it good? Even security minded people can be lazy in this situation.
Another reason HTTPS is easy is that it uses a centralized trust model, relying on CAs to vet each website.
GPG is neither. It tries to provide encryption at rest, and relies on a web of trust that we cannot reasonably expect everyone to operate securely.