Earlier quoted context omitted.
The key has no value if anyone can sign the binaries in the name of the developper. Then the binaries might as well not be signed.
Not really. The point of origin is the private key, which does need to be protected. Lack of identity verification might make key revocation/rotation more difficult, but identity is not really permanently coupled to the keypair. If that were true then why is the only thing stopping me from circulating self-signed certificates with bogus info the lack of a CA signature?
If anyone can get a certificate from a reputable CA under the name of Microsoft Inc, then how do you know you are executing guenine Microsoft code? You don't have the public key of every reputable developer installed on your machine, and the CA won't check for reputability or malware, just that the identity is who the certificate claims it is.