Tomas Krizek:
  In any case, if you're worried about security,
rather than
 privacy/confidentiality, let me assure you that the packages are signed
 by PGP. 
it is also relevant for security (in depth).
example from the past:
https://justi.cz/security/2019/01/22/apt-rce.html