Earlier quoted context omitted.
Yes, but their point is: Why would you need code signing if https is working correctly when downloading software?
Because somebody might’ve changed the files on the distribution servers. We’ve been signing executables for decades?
If someone has changed the files on the distribution servers. A Hacker News reader will have no problem recognizing it and stop installing, another one will compare the signature and keep it as evidence.
Of course, the overwhelmingly majority cannot recognize it though.