The SECOM client doesn't seem to use the "SecomSignatureProvider.validateSignature()" function to validate the incoming signatures. This might be useful when testing a client but it should really be a bit more secure and not require the use to do it on their own.
At least the option of automatic validate should be provided.