Earlier quoted context omitted.
It does. But as we all know that model can’t just be lifted over to WWW.
Note sure what "lifted over" means exactly. I once explained PKI to someone in their 70's who grew up without the personal computer and at one point they stopped me and asked "Why don't they just publish their public key in the newspaper or some directory like a telephone book?" Later, as an experiment I printed a public key and then used OCR to reproduce it electronically. Of course a key intended for www usage can…
I guess it is technically possible to verify every TLS certificate out-of-band. But would you really be willing to do that for every TLS-enabled web site you connect to? And even if you were willing to do that, the average user would never do it.