What others said. Checksums downloaded via HTTP are just as easy to spoof as the tarball. The VPN protects you part of the way but not the entire way. Now, if you said that I could verify the download because it was signed using the publisher's GPG key and that key was widely trusted, then I might have entertained the idea. Then again, that is very non-standard compared to getting a $10 TLS cert.