What about if someone pretending to be @asdf makes an account with his name? Or, if he is hacked? Both of these seem like reasonable problems to solve with a verification or signing service. One is solved by verifying the identity of the user once, while the other would be more like each git commit.