They appear to take a SHA1 Checksum from an unencrypted (non-HTTPS) website to verify the integrity of the download.
Surely if you're worried about the integrity of the file you should also be worried about the integrity of the source website also?
Surely if you're worried about the integrity of the file you should also be worried about the integrity of the source website also?
The best way is to check the signature, but that requires GPG in the first place (and trust on the key remains hairy). At least they could serve the site with HTTPS (GPGTools does this right).