Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…
If, and only if, this is a legitament change done by a majority copyright holder(s) and/or project owner.
The only authenticity test that I can think of is to actively distribute a fork of TrueCrypt using the new license and wait to get sued. If you get sued by the copyright holder (who would have to come out of anonymity to sue), then you can be sure that the new license was unauthorized. Not the safest way to test authenticity, but it should work.