@capngloval I'm a bit skeptical still. #Microsoft has historically done much to harm #FOSS, and #GNU + #Linux in particular. For example, requiring a distribution to sign its releases with MSFT signed key in order for (most) people to replace the OS on hardware they own.
I'm in favor of signing and hashes, but user / owner should decide whose keys to trust, not Microsoft.