Have you ever worked with large repositories? You really don't want to read every single byte from disk just for signing a commit if you can avoid it.
For some people, an improved signing scheme over the SHA-1-linked repository format would meet their requirements based on their assessment of their security threats.
The scheme you just called a "screw up"?