What kind of verification would you suggest for a voluntary mirror? If you add too much
overhead, good mirrors will just walk away and you will lose. That isn't the gateway where you
should be adding security. You should assume malicious mirrors are already present and work to
mitigate that within the distribution.