Good point about old-and-vulnerable versions. That seems like a strong argument in favor of using HTTPS. I’m curious why the Debian folks haven’t thought this a serious issue either. I’m going to try to dig up the discussions.
But the use of a weak signing scheme is just an argument in favor of switching to a better signing scheme. Though I guess it is also real world evidence in favor of defense-in-depth.