He seems to be discouraging signing every commit's individual data but encouraging signing the actual commit ID (SHA1) which should be perfectly feasible for something like homebrew.
https://www.youtube.com/watch?v=AsNwon4fjqY
A publicly available webcam pointed at an RSA SecurID hardware token...
(The optimist ion me hopes this was performance art. But I've worked with people who'd do that if it made their day ever so slightly easier...)