Yea trust is a major issue.
But I'm not sure if you can trust an open source software 100% either.
Or for that matter any software who gets updated automatically.
The author could just send a malicious update once he thinks its worth it.
and it doesn't even have to be him, what if his system gets compromised, and some else releases an update in his name ?
so the chain of trust in Bitcoin is very limited.
thats why I think a liveCD is one of the most secure methods were going to have since it will always stay in the same state.
I guess its better to make on your self and not to trust any one else but for most users that wont be an option.
so if you can get one from a trusted source you should be safe (as per release bases)
thats one of the reason I created an OTC account so I could gain trust in the community and hopefully in the end people will
be able to trust me for future release.
but that doesn't mean This current release can't be validated.
I wrote a small post of how I would have test a liveCD like that on reddit
http://www.reddit.com/r/Bitcoin/comments/1c9ht1/bitbuntu_r2_an_ubuntu_livecd_with_all_your/and I highly encourage any one known in the community to give it a go and validate this specific release.
if you approve it you can ad your public key/sha256 hash to the iso so people will be able to test its the same iso
and I haven't changed it (the disadvantaged is that this has to be done again for each release)
Anyway I hope that for my next release when I'll add Armory etotheipi, will be able to validate it has not been modified.
And I think most people will be able to test gitub bitaddress.org source vs the local saved source and see its the same.
I know that if any one finds an issue with this CD he will notify the community (which is exactly what I would have done)
but if you use this CD and test it and find it to be legit, it will be very helpful to let people know, since it as important users wiil know what they can trust as to what they cannot