Right now the rust binaries are accompanies by gpg signatures, but rustup does not check them.
I don't want to bring in native dependencies unless they are dead simple to build. We should probably try the gpgme bindings first, since those would be compatible with our existing gpg keys. If that doesn't work out then we can explore more exotic options.
Previous thread.