How do I know the second sig is to be ignored? I am just following a "don't trust, verify" ethos. I don't know what data is hashed with that secondary signature. I'm really just wondering why this application doesn't use the same validation scheme that every other application does? What is the additional signature and why is it tacked on?
To be clear, I am not accusing you or nunchuk of anything. I am just confused to what is happening and why.
