In fact, if the HTTPS change is faster, this should be prioritized, given that the other issue might take a lot of time to fix: the old validation mechanism will have to be supported for a long time to keep older clients backwards compatible...
I'd take that the VLC guy had a bad day, otherwise that'd be a terrible reaction from someone involved in computer security.