Neither developers nor consumers should be comfortable with this, as this breaks the trust model and is extremely worrying. The site is of course downplaying it given its name, which is a huge shame.

What trust model? Is there anyway to verify that an app from the app store is the same as the one the developer uploaded?