As pointed out in other Gatekeeper threads, it would be nice if users could choose which signing authorities to trust. Signing is a good security model, but a single authority sounds risky to me. Perhaps I feel that Signing Authority Foo has a better definition of malware (read: which certificates to reject) than Apple has.