HTTPS can be MITMed by anybody with a root certificate (or who is able to dupe the holder of a root certificate). Signatures rely on (at best) multiple hosts or domains not being compromised. You can also mirror and cache distro ISOs when retrieved by HTTP or bittorrent.
In the end, who cares how you downloaded it, so long as you can verify it with a GPG signature?