Update: A version of transmission that contains malware has been distributed very recently. Quoting this ars technica article:
It appears that somehow the Transmission website may have been compromised as it was served via HTTP rather than the primary HTTPS Transmission
Original question
I want to download the transmission bittorrent application for mac, from here. There is a sha1 checksum on that page if you mouseover the link to the .dmg
file link, but as the page is not served over https, I cannot tell if this is authentic. My main concern is a man in the middle attack (to corrupt the data). The fact that https is not used seems silly, because another page on their domain can establish a secure connection with a signed certificate.
I wonder if I am missing something, though this Q&A seems to agree with me. I would also like to know if there is a method to still find out if a file is authentic in a scenario like this, or in my particular case.