Nobody verifies the checksum. It installs just fine (probably) if you don't. Just like reading the EULA.
Sure, it's a good step if you're extra paranoid, but otherwise people are just allowing installs from unknown sources and immediately installing, especially since Android takes you straight to those settings when you try to launch a downloaded APK.