Homebrew, rbenv, rvm, to name a few. Never understood it either. If you could get ahold of a domain write a malicious script at /some-script.sh, you could do a lot of damage.
apt-get:
$ ls -l /etc/apt/trusted.gpg.d/
Source Installation: $ wget http://nmap.org/dist/sigs/nmap-6.01.tgz.asc
$ wget http://nmap.org/dist/nmap-6.01.tgz
$ gpg nmap-6.01.tgz.asc # apt-get --allow-unauthenticated ...