The issue is not that Linux lacks a central authority that holds some encryption keys and controls what software you can run.
The issue is that you should not run any software from a source that can't be trusted. When we used to run only software from community distros or that we compile ourselves, launching a malicious program was a non issue.