For developers with multiple applications, then sure, that's not going to be as clear as individually identifying the application.
But there are plenty of developers around with just one popular application. Sending the dev certificate for them is effectively the same as sending the application hash itself.
I get it, we're all supposed to trust nobody and have 7 billion independent islands where you don't have to trust anyone or work with anyone.
I have not seen any solution, just people piling on. Having PKI and signatures using a central authority is the least-worst solution we have right now, and until something better is created we don't really have a lot of places to go (unless we accept downgrading common user's security and usability).
"They already know they exist ..." doesn't really seem to match up? Like, of course they do.
Anyway, I was just pointing out that the communication still seems pretty close to sending Apple the list of applications being run. At least, for applications created by dev's with only one major program for their certificate.