Regarding the gpg key used to sign
Any chance that that key could be available for downloaded by way of
https://, or perhaps just have its fingerprinted listed on
While the https:// CA model is far from perfect it'd still like to think
it being a step up compared to regular http://, and at the same time a
lot easier to document than the process of following the signatures in a
gpg web of trust.
// Andreas