There's people who seriously think commit hashes are there for security purposes? Furthermore, there are git MAINTAINERS that think this?
How absurd. Author is completely right, making SHA-256 the default implementation serves no purpose. SHA-1 is a completely valid algorithm for non-security use cases, which is precisely how git uses it. This is a solution looking for a problem.
I think he's maybe overblowing the impact of this change. Realistically, the only ones who are going to be impacted are the folks who maintain git-related tools and forges, as he mentions. The rest of us probably won't even notice. But that's still a ton of pointless work for those folks.