http://sigma.i2p/post/66
The only thing you can rely on is pre-existing trust, both to the source of the data (say, a release group), and to your immediate contact (say, a tracker, its users and mods). In this case, you don't even know whether it is a potentially original file, or a potentially manipulated file, as you don't have any external release info (with hashes, etc.) received via secure (i. e. also trusted) channel.