@Gertjan:
IMHO: that means getting the pfSense from on unidentified source.
I guess that will never happen. And If I see one, I would never download it for that reason.
Mirrors exists because they are syncing with the official source - and no one else.
Note that 'mirrors' often propose more then only pfSense. Thousands of projects uses mirrors, so they are always busy.
I have nothing against "Bittorrent" but I would never use it to download an executable. Other type of files, ok ;)
The official mirrors could have the BitTorrent file. Torrent files contain SHA1-160 for each block, and each block size is known, so you can't just pad block sizes to more easily forge a SHA1. As someone else has pointed out, one could just verify the final image's SHA256 with what's on the site.