A blog on this general attitude: https://sandstorm.io/news/2015-09-24-is-curl-bash-insecure-p...
The difference between a digital signature and HTTPS for identity verification is probably somewhat of a toss-up, and a checksum hosted on the same server as the download is mostly useless for anything but ensuring your download of the malicious version completed successfully.