Comment Re:Probably a good thing (Score 1) 53
In a mirror network, the TLS cert is a weaker assurance than the signed payload from the presumably trusted source. A mirror host is more exposure and more risk that the actual content gets modified despite having 'a' valid certificate.
So the TLS assurance is redundant and less specific and less rigorous than the content signature validation from the originator. Further, unencrypted protocols are friendlier to things like proxying, which can dramatically reduce load on the internet hosts if proxies take on a good part of the burden from certain institutional clients that may use an HTTP proxy to improve their performance.
So yes, if it's worth downloading, it's worth validating as best as possible, and for a lot of content the best as possible is something like GPG validation not TLS validation.