Thanks. So in other words, the first problem might possibly be hit in practice, and really ought to be fixed soon, but the second problem isn't likely to yield any real world consequences unless an attacker is in a position to generate tens of thousands of files with names that all hash to the same value. No?