Earlier quoted context omitted.
Not to mention it introduces a single point of failure, that once compromised can start pushing malware directly to user. With maintainers in the loop, there is at least one more person that can notice something is fishy. Not to mention there is usually so time before packages are updated, so there is more time to notice an attack.
> With maintainers in the loop, there is at least one more person that can notice something is fishy Also one more person who can inject malware or break something. How did that Debian keygen issue happen again? Oh right.
The people on the openssl mailing list said it was fine. That's how it happened.