Maybe they can make it more secure by having the dev kit sign the app before submission.
. . . possibly by, somehow, documenting the size of the file in the dev kit?