Here is the way this works.
The person who posts PDFs on websites with MD5/SHA1/SHA256 hashes adds a watchdog to verify that those hashes aren't changing - Once you get the framework together, adding a new page with hashes to the watchdog takes just a few seconds. That way, if the random ISP(s) or third parties are modifying those sums on the fly, will trigger the watchdog.
As to whether most people check the sum - I have no idea, but at least anybody who wants to take 90 seconds to authenticate the document can just go:
x=Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf ; md5 $x; shasum -a 1 $x; shasum -a 256 $x;
Keep in mind - I totally agree with you that this isn't a great mechanism, but I would argue it's better than nothing at all. (as long as someone has a watchdog to confirm the hashes aren't being modified in flight - they could probably help their case a little by at least serving those pages with HTTPS).
A much better mechanism would be to use OpenBSDs signify (http://www.openbsd.org/papers/bsdcan-signify.html) which solves this whole problem of trying to sign documents with something simple that doesn't involve byzantine chains of trust in a very elegant way.
They could just create a key pair:
signify -G -p threatpub -s sec
And make their public key, which is short, and easy to copy/distribute everywhere - looks like this:
untrusted comment: signify public key
RWQw2u3UPjm6spK9OYJxylK2jSKz2agskG2EKPsxwFN4IjHVw66dYPhT
And then, with each document they create, they just sign the PDF:
signify -S -s sec -m Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf
Which provides a signature file, signed with their private key:
untrusted comment: signature from signify secret key
RWQw2u3UPjm6svkWhs4fgy1Qi0P72hp+uDuTxX8bDSvd/qr/7vc55v+PndgDdWOWj0JiLco/CCfOzw6Alau9RTi5gBiHSzuRHAs=
Now, those two documents, the PDF and the Signature file - can be distributed
everywhere - and are not subject to a malware attack because everyone has ThreatConnect's public key, which they can use to verify
any threatconnect file and signature, with the simple command:
signify -V -p threatpub -m Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf
I'm presuming that's the better mechanism you have in mind for this sort of thing? I think I'll forward our thread over to the threatconnect team, see if they are willing to upgrade their procedures.