@Dashrender said:
It's a trust thing I guess. I hope that one managing a project like Elastix to do a pretty good or better job at securing their website, and I'd feel more comfortable pulling the hash from them than from a file sitting on the same file server as the actual file, especially since it's a hosting provider, not the content creator.
A better job than SourceForge? I'm not sure what you are looking for. SourceForge is a huge player and the source of the majority (I think) of the world's open source projects. At least those of any size. This is how a huge amount of open source is done.
SouceForge really is the content creator, in a way, here. Remember, this is open source.