I was pretty much suggesting that to some guys during DebConf: If you want to put trust in non-DD, why don’t you just install some script that sigs and uploads their (correctly signed) packages? This would have, for them, the same effect as beeing DM. But nobody feld comfortable with that... --nomeata