Update: looks like Apple's notary service doesn't send app hashes, it sends info about the *developer* certificate. So they know who wrote the app, not *necessarily* which app it is. If they block an app it would apply to all apps signed by the same cert.