Earlier quoted context omitted.
I'd doubt users of an encryption app not using a simple checksum to verify its legitimacy before using it.
Probably not true. E.g., do you think the average user of Tor takes this precaution? Thinking back to the times I have downloaded Tor, I never did that. It reminds me of a time when I wanted to get in touch with an HN user... they had their pgp key in their user page... I tried sending the email but it didn't work (formatting issues). Finally I reached this user and asked what was up with it... and he responded by sa…
It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.