And you base it on what exactly ? It's "just" making sure the build process is always ordered.
If anything it will make attacker's job easier, as Ubuntu package will have same files structured exactly same way as Debian one.