I encountered a Debian machine that, when trying to update packages, threw the widely discussed "GPG error: http://security.debian.org wheezy/updates Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 8B48AD6246925553". In oder to import the current keys, the package debian-keyring needs to be installed.
But since the keys on the machine are no longer valid, how can I be sure that the packet's contents have not been tampered with?