I am currently developing a project which should alert the user if he receives fakes binary updates from his OS supplier. Even if signed with the right keys he might get a forged and specially prepared build to snoop onto him.
Initially I was inspired reading one of the books of Cory Doctorow, attack surface.
If anyone has similar ideas, have a look at https://binarytransparency.eu for more info, source and api usage.