Not a security expert here but it seem like akamai should also be required to use a root CA that does not use md5 for it's encryption. It am under the impression that md5 based encryption has been broken since 2008:
http://www.win.tue.nl/hashclash/rogue-ca/#sec71
Regarding "All software downloads should be provided only over HTTPS", this is very expensive to provide, but is allowing users to compare a checksum an equally secure option?
By expensive you mean in CPU cycles, right? Isn't it becoming less expensive all the time thanks to Moore's Law? Is it really all that expensive these days? (I'm really asking because I don't know, this isn't rethorical.)
Must be cool for Colin to have Tarsnap featured there (as secure backup provider Tarsnap puts it, "[b]ackups are supposed to be a tool for mitigating damage — not a potential vulnerability to worry about!")