Just to add on top of this: I also really don't understand how Paint.net paying $600 to sign its releases would have actually changed anything about those malicious ads, because a malicious ad can still point you towards a resource that isn't signed that claims to be Paint.net.
If a user has the presence to know whether or not they should expect a specific Open Source program to be signed, then they probably can get it directly from the website? And if they can't find an official download link, then they probably won't realize anything is wrong when they get an unsigned application because how on earth would someone know whether or not Paint.net is signed without visiting the official website to check? So either the malicious ads get caught and they aren't displayed, or... I mean, I don't know, unless there's something I'm missing I just don't see how a malicious ad that directs someone to a fake download page for Paint.net isn't going to be able to get crap on a victim's computer regardless of what Paint.net separately does to the real binaries.
The user doesn't download the real binaries, that's the entire scam. The user doesn't know if Paint.net signs its binaries and they don't know if the warning they're getting from the OS should or shouldn't be ignored. So on top of shifting the burden onto the wrong people, it's also not 100% clear to me that shifting the burden onto developers actually improves security all that much?
I'm not against application signing, it can be an important part of security, but not when it's a manual process that costs $600. And not just on its own in isolation, and not when it's an optional process that (because of the cost) many applications aren't going to participate in to begin with. I'm not against signing applications on a conceptual level; I like being able to verify releases. But the Windows/Mac signing process sounds a lot like security theater to me.