Sort:  

Maybe something has changed since the 90's, but in the past, when I got a file with a hash, a hash was signed by a known entity (a trusted PGP signature) so that you could know that it wasn't tampered with in between. A hacker could have uploaded their own malicious file and then posted the new hash up on the website and it would match. Something like this would prove that the website wasn't hacked and that the entity uploading the file proves that they did indeed sign it and not some hacker...

https://keybase.io/verify

I know you must know about these things, but this step seems to be missing.

Coin Marketplace

STEEM 0.04
TRX 0.33
JST 0.102
BTC 64900.10
ETH 1881.53
USDT 1.00
SBD 0.39