I'm not sure what the point of that page or posting it here is. This system (and others like it) is neither new nor special. It's also not a bad thing, and I haven't seen anyone come up with a better alternative. Generally you see all major distribution options have signatures with a CA-type trust structure no matter what you use, be it open-source, free or commercial paid software. On Windows, macOS and at least all…
Question for you: what exactly does Notarization protect against? I have watched all the videos about it, I read the developer documentation, I notarize my apps because it is required by the OS…but I still have not gotten a single good explanation as to why it's useful. Apple claims that the process is extremely tolerant…so does it try to accept everything but blatant malware? Does it let malware through? What happen…
From what I understand, the most common use case here is to match against known malware inserted into an otherwise normal release, either from an infected dev machine or by way of an attacker coopting stolen credentials. It's not going to guard against truly novel malware for obvious reasons, but the vast majority of malware is a repackaging of stuff that's already out there.