All that's needed is a single signature. Everything about this is absurd. It just seems he's clearly exploiting this to gain some fame to promote his company.
I read that. He doesn't give the message that is signed (just the digest and a screen shot of a small portion of the file). Without the actual data, this can't be verified.