Exactly.
> Secondarily, because the files usually sit on a different server than the site itself, the hash lets you detect some cases of your download being tampered with in-flight, or the file itself altered on the server.
That assumes the download file is on a different webserver, but if they can gain access to one server, its not beyond the realms of possibility they can alter the hash values on another webserver.
I just find all this crypto stuff to be misleading whilst it overstates its effectiveness.