I am pretty sad they're posting MD5 sums of the correct images: It's pretty trivial to collide MD5 -- and when you've got an active attacker, this is something you should worry about. SHA1/2 at least, but preferably a gpg signature would be much better.
... collisions=/=second-preimage attacks
>SHA1/2 at least, but preferably a gpg signature would be much better.
SHA1/2 isn't any better, you're never going to get hit by file corruption that magically also is a md5 collision.