Given that they could just as easily fake the checksum, they might as well use a 1-bit checksum. The security of a 1-bit checksum is just as good as a 256-bit checksum in that scenario.
Yeah, that's why I wrote it "prove" - it's not proving anything. There's absolutely no way they can prove that the code in that box is the same as on the repo, not to mention all the other upstream issues - it has to send that count somewhere to be aggregated, and now we're even further removed from all the possible points of "failure".