Yes, I mentioned that - but trusted public sources, who often post on places like Reddit or personal websites run out of the US and the like, can post NFOs but can’t post the actual game. If you knew the correct checksum, you could then turn around and grab the game from an untrusted source.
Distributing the game itself is the dangerous part (in terms of making the copyright pinkertons come after you) so it’s better if it can be done as anonymously as possible, but that conflicts with the need to have it distributed by someone trusted. Putting the checksum in the nfo, which is widely reposted by trusted sources, would help avoid this problem.
Why don't nfo files contain a checksum for the release?
I assume there’s some historical reason for this, but currently, the way scene releases reach most people seems to consist of:...