Can't quite grok it on this post, but where they describe "end-to-end", how exactly are keys generated and distributed? Are key fingerprints verified out of channel? How are they not susceptible to MITM attacks? Which, admittedly may be difficult, but still possible. How is this any better than sending CC data from browser to server via SSL, which at least has a CA system (as shitty as the whole CA thing is)???