it is conceivable that such a system could work but it would have to rely on some kind of authenticity check on the binary/script that runs.
when "crossing your t's and dotting your i's" it is usually best to use an out-of-band method to check signatures, e.g. download binary installer, check gpg signature or calling them on the phone to verify fingerprints. even so, this cannot stop a MITM unless you do the key exchange in person, e.g. meet the software creator and exchange gpg pubkeys on the spot.
if by "cut down tall poppies" you mean bring mega's claims of security and privacy in-line with reality, sure.
there are plenty of people doing more interesting work with encrypted data storage. to suggest that mega is blazing a new trail is absurd. backblaze has been using a similar key-per-file encryption method since 2007, except they actually executed properly.
if the crypto implementation is this poorly thought-out, you can only imagine how shaky the rest of the backend code is.
it would not surprise me if the service is shutdown again somehow. i would guess they would lean on the banks of CC companies that process his CCs first.
it's only USD 10 mln :P