Hashfile allows you to verify that installer you downloaded is exactly the same the web page offered i.e. it matches bit by bit and it wasn't broken or altered in any way during the download. PGP allows you to verify that exactly this file was signed by one of Core Team members (currently @flare ).