Earlier quoted context omitted.
GPG signatures are kinda useless (when hosted on the same server). If I am able to replace the download I could probably deface also the pages where you give your signature and key fingerprint.
APT can automatically verify GPG signatures against a preinstalled keyring. Obviously, that doesn't help in the case of this particular incident (ISOs), but it does help in day-to-day updates.
GPG is immensely useful for securely distributing packages and distros.