Request: publish checksums of official builds to at least one, and preferably several, webpages authenticated by HTTPS.
A thread like this would count as one. The plain-HTTP sf.net files area does not.
The PGP-signed SHA256SUMS.asc is the right idea but requires extra steps to check.