Is it possible to manually verify the code signature with Apple's built-in public key before installing?
The manual-download pages on http://support.apple.com/downloads/ publish SHA1 sums. Unfortunately those pages aren't served over SSL. You could download the update and compare its hash against those of your friends: at least then you'd all be installing the same thing (preventing narrowly-targetted attacks).
c06a63982b522e43997a05cedc04b0bdb1a10207
which matches my download using `shasum -a OSXUpdCombo10.9.2.dmg` pkgutil --check-signature OSXUpd10.9.2.dmg