[PLUG] secure apt

I want to check that I've understood this correctly from reading
debian docs.  The new version of apt pays attention to gpg signatures,
but debs are not currently being signed.  It's recommended, then, that
I ignore this error on "apt-get install":

    Install these packages without verification [y/N]? y

or that I modify /etc/apt/apt.conf.d/70debconf to somehow say to
ignore signatures.

I want to be very careful about this, because it's initially difficult
to differentiate a bad signature from a broken secure apt.

Thanks much for any input.


