I am pretty sad they're posting MD5 sums of the correct images: It's pretty trivial to collide MD5 -- and when you've got an active attacker, this is something you should worry about.
SHA1/2 at least, but preferably a gpg signature would be much better.