A fine workaround ... from my timewarp ftp was the web, not the workaround
You could I suppose to be ultra-thorough also post the signed hashes of source and pre-built binaries files put up on github by the other devs (so as not to centralise trust on gavin's sig.) ... e.g.