FWIW, sha1 sums are embedded in the zsync files. If you download via zsync, it checks that for you - if not, you can view the .zsync file in a text editor.
Not sure if those were posted to google code though.
That said, I still would trust md5sum. Being able to get a collision - sure. But to do that so that the compression is still valid ups the ante a lot.
I do believe that's possible. However, doing that without significantly changing the file size, that feat I do regard as improbable enough.
If there was a TinyCore iso at 37mb, that should raise a red flag
