I don't disagree that SSL/TLS doesn't add much security (though it does provide privacy regarding the packages being pulled), but don't conflate it with the CA system; they could just as easily pin the SSL/TLS cert at install.
For maximum security and user experience I'd say both though - validate you are connecting to who you think you are and also validate the PGP signature. For how often packages are installed vs how high of a risk remote code poses to the system I think it's a bit foolish to say we can only do one and when we do we are perfect.