Some feedback:
* don't use md5 as a security feature! I suggest to replace the use of md5sum with sha256sum (not even sha1sum is really safe anymore). The only use of seeing md5 in security contexts is to indicate that the person recommending its use doesn't understand security, which may admittedly be a worthwhile feature in itself. Perhaps you're really saying "this is one of the weak links in our security chain, the source code we're getting here might be hijacked or have huge security holes, and I haven't checked the sources, so it doesn't matter much anyway whether you're using the same sources as me anyway"? Then perhaps point this out, like using sha256sum and at the same time mention "(although I haven't verified the source code against security issues or backdoor (yet?))".
* I'm not a cryptologist, but regarding "the security of encryption depends upon how random the pseudo-random number generation on your system.." I think that's the wrong use of the term "pseudo-random number", as /dev/random really is about randomness, not pseudo-random numbers at all. /dev/urandom does stretch the collected entropy using pseudo-random number generation, but I think even the phrase "how random the pseudo-random generation" is mathematical nonsense, as it's not random at all, just random-looking when not knowing the generator inputs. Perhaps say "The security of encryption depends upon the randomness of the random source used on your system"?
(* I think the NSA is able to track you anyway, regardless of whether you're using your own server on the same IP or not. Thus the suggestion "make you more vulnerable to traffic analysis" will probably only hold for companies trying to track you.)