Checksums offer no security. An attacker can alter them right after altering the image. Now if the images were signed, it would be a different story...
Checksums are also found in the PGP signed release email.
As long as they send the cryptographic checksum through ssl/tls, you are fine. No need to send the whole file through it.
Unfortunately, ftp.freebsd.org doesn't seem to support https.
Just to follow up on this, what checksums do offer is a way to verify that the file you have locally matches the remote file.
Checksums do not offer this property if both the remote file and checksum are both sent unsecured. If an attacker can MitM the remote file, then they can also do the same for the checksum file.