This is weak. Making commits more meaningful does not mean we need to handle the history of previous unsigned commits as the article asserts.
You would simply enact a policy that says from this day, all future commits must be signed in order to prevent future identity theft.
Yes, bad people may have snuck bad code into your repo in the past. it does not follow that it is unworthy to prevent bad code entering the repo in future