Yes, they are signed, but not with the official key. If you add it through the UI, it will auto-accept the key from the repository. (I'm not sure how it exactly works, it might ask the user for the confirmation)
If you do it from the command line, by editing files, you will have to add the key manually.
But most inexperienced users will just copy/paste and run the "curl | sudo apt-key add" command from the shady repository website, because they want to run the software.
This is not much different from downloading an .exe from an untrusted website, and ignoring the warning from windows when running the .exe.