I will disable it when it comes but I think it should be "opt-out" because otherwise the OS becomes insecure by default. And it will hurt majority of the people.
Apple can ask it on system start like Siri and analytics.
If it were a pre-downloaded list then this is not surveillance. What it is doing it ensuring that software hasn't got malware in and/or that the developer's certificate hasn't been removed (e.g. for distributing malware). That's a good thing, like running a checksum on a downloaded file.