https certificates leak all the time and we still use https. Something is better than nothing. Now, is it worthwhile to use code signing certs to try and certify the identity of the author? Maybe not, it was slowly phased out for https. But we certainly need something because the alternative (just download and run whatever) was tried and definitely did not work out. We don't want grandma doing the equivalent of 'curl
http://x | sudo bash' 4 times a week.