“Trusted” Vendor Update?

I like this (from XKCD: “Debian Main” is the title) …
Debian Package, with Locusts
I especially like the fact it works as artwork, in case I ever do a presentation on unauthenticated/untrustworthy package update mechanisms. It reminds me of Skype, when they try to unilaterally update my machine, or Apple, when it tries to claim Safari – the initial installer – is an “upgrade” to iTunes for the Shuffle.

