I wouldn't expect outright successful attacks like forged replacements
for arbitrary files.
I would expect someone to have on hand a small number of blobs that are
different but have different hashes and, eventually, to drop said files
into a blob-based infrastructure to wreak havoc.
So: a way to locally mark a given checksum as "controversial" seems
prudent, to me (hence, support for such in my blob-db code/spec).
-t