Not an article, but this is a register-based VM that should be simple and straight-forward to understand. Also comes with an assembler, disassembler and debugger.
If my password is catsanddogs, there is not much entropy in this password. If the connection was based off symmetric crypto from the get go, where the key was seeded from that password, you could capture some traffic and offline attack the key based off a weak user password.
The alternative is safer. You would have to brute force the login online.
I think you don't know what an IV is. The IV is not secret. Maybe that's where the confusion comes from?
I have no idea what the truth actually is, but my experience would lead me to believe worst case.