Probably not true. E.g., do you think the average user of Tor takes this precaution? Thinking back to the times I have downloaded Tor, I never did that.
It reminds me of a time when I wanted to get in touch with an HN user... they had their pgp key in their user page... I tried sending the email but it didn't work (formatting issues). Finally I reached this user and asked what was up with it... and he responded by saying, "Oh, noone in the past 10 years has made use of this!" And this is a pretty smart security guy.
I think there are very, very few people who actually take the trouble of verifying checksums and everything. I used to do it /sometimes/ years ago, but it gets to be a hassle pretty quickly and you start taking shortcuts everywhere. A lot of us sort of plan to start doing it, but never actually do it. Kind of like exercising or eating healthy or whatever. :)
Anyway, as for this news about ISIS having their own encrypted chat app - I'm happy to hear it. If they made it on their own, it's bound to have a good dozen holes that NSA will have no trouble poking through. :)