Open
Description
This issue was brought up here: https://twitter.com/maybekatz/status/890320508813586433
We should do a better job of explaining why the preferred way of installing yarn is not via NPM or don't mention this at all if we don't have a good reason.
Right now I think the package signature verification aspect is important but I'd like to hear more to come up with a solid explanation.