2: The whole user interface is set up so users believe in what they see in the web interfaces.
And you want to tell me with a straight face that users will do their own crypto foo instead and validate hashes?
Even if the users used that CLI, that does not help. As we saw with Ethereum. They simply pushed out new code that rewrote history.