There is nothing to steal, so in-transit protection isn't required. And if our distribution network is compromised, that means the secure datacenter of our hosting company is compromised (we use a corporate hosting environment, not direct internet attached servers or VPSses), in which case not having TLS in transit is the least of our worries.
If GPG signing is enabled, you immediately block all other people of buidling an image from our source, and you immediately block creation of packages by third parties, as obviously we would keep our private key secret. So while that is a possibility, it is complex and has a lot of downsides, it is not something one would implement on a whim...
Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Ultimate (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)
Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.
Many answers to your question can be found in our new and improved wiki.