True, I didn't find any notes on what key to use and the key I typed in is the one the signature itself said was missing (so it is in fact a bad choice). Your criticism is valid. Sorry if I misled anyone, I meant to fix that but I didn't find much guidance on the gnu site as to what signatures to load to bootstrap trust.
Just a note: I think I was hoping (but didn't confirm) that I was downloading the key from GNU and the file from a mirror. So I thought I had the minor protection that I was at least safe from somebody who could only alter the mirror. But I agree with the criticism: not being clear what you are claiming to actually check in a crypto-situation can confuse others and cause harm. Sorry about that.
No worries, end to end PGP leaves a lot to be desired, but I feel it's important to point out when the common recipe steps fail to protect against exactly the adversary one would think they do.