From what I understand of PKI and the way the Internet is right now, trust in identity would be very hard to build if clients engage in PKI.
But taking encryption into one’s hands basically brings back control into one’s hands. You do not specifically need an encrypted connection in such a case, just a tamper-proof connection.