Many of our mirrors offer https. If you worry about MITM, please download from those.
No, you can't get authentic link of mirror from a hijacked non-https website.
IMO, it's pretty ridiculous that a site serving OS downloads isn't using HTTPS in the letsencrypt era.
Indeed. This unnecessarily makes the website and even the OS itself less reliable.
Is there any reason tinycorelinux.net still isn't https, given that forum.tinycorelinux.net is https?