You're right on the issue! I've described the situation few
minutes ago
exactly the same way on my Weblog, at
http://www.webweavertech.com/ovidiu/weblog/archives/000023.html
I think Xemacs needs to have cryptographically signed packages by
default on its main site. Right now we don't do any check to verify the
authenticity of the packages, and a malicious hacker might easily change
the packages.
XEmacs isn't alone, Debian doesn't have signed packages either.
I think it would be nice if this worked, but IMHO this isn't an immediate
problem. It should be added slowly so it doesn't cause problems for
users. If it causes problems, people will dislike it regardless of its
merits.