If the binary you're downloading might have been modified, how do you know that the hash you're checking against hasn't been as well?
Sha1 collisions...
what's wrong with doing <insert hash function>?
Making a hash of the release is just a small part of it (and is the first part of what they are doing).
The trick is to be confident that you're getting the same hash as everyone else - and that's what requiring a proof that it be added to a CT logs gives you some level of assurance about.