What is GPG and why you should start using it
akashrajpurohit.com
akashrajpurohit.com
I wonder if someone could clarify this mystery to me: Supposedly the download process is protected by HTTPS, so it can't be tampered with. If we assume that it could be, then the signature that I read off their website also could've been tampered with.
Question: What am I missing?
You also typically download it from a different place than the storage location of the signed binary artifacts. This means that an adversary will have a hard time trying to replace a public key and remain undetected.
This is alright from a privacy perspective, because you can find out which packages are downloaded anyway by looking at the download sizes.