7. What does this mean for people who distribute packages?

This will require no change for Debian maintainers. They've already done their bit by getting their keys into Debian's keyring.

For now, even those who want to create their own apt sources don't have to change anything until you want your sources to be authenticated, in which case you'll have to generate and sign Release files, and find a secure way to distribute your key. Someday, APT might force all sources to be verified, but those kinds of policy decisions have not yet been made.