The reason for outrage is that this problem is so glaringly obvious that we can't dismiss it as an oversight, especially with a company as advanced as Apple claims to be. They boast about the T2 chip and all of their security measures. So for them to leave the gate unlocked on something like this is problematic. It means they made the choice to expose and log users' activity, to some degree or another, on purpose.
To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs.
Why would they ever have logged IP addresses, if the goal is simply to verify the user-side authenticity of an app?