Feel secure with SSL? Think again
blog.bintray.com
blog.bintray.com
It's like saying "Feel secure using SSL? Think again, a burglar can still break into your home!"
The article's point about signed artifacts may be valid, but has nothing to do with the click-baiting, FUD headline.
Maven Central has users sign content with PGP keys. PGP keys are also a poor means of verifying content. Especially if you have no other channel to verify a PGP key.
These are all known things, and have been for quite a while. Apparently it is news that users of Maven Central trust this this to give them a false sense of security.