That is good to hear. You cannot count on being lucky twice.
It always takes events like this to make changes .. I really hope other distros learn from your mistakeS.
Would be great if Novell, Canonical and Debian would openly disclose how their infrastructure is protected. (In detail.)
At the end of the day my system is dependent on a secure infrastructure from supplier of the binary packages.
Security by obscurity does not work .. let people openly discuss the measures taken and you will deter attackers and possibly strengthen your system by getting new ideas or by finding (obvious) flaws.