You can't E2E with a web app?
I know this is as pathetic as "why aren't scientists working on cancer instead of X", but we have WebXXX including Bluetooth and USB, you'd think we'd have "WebVerifiedApps" or something. Even content-addressable URIs aren't being allowed.
It's funny, given the rise of things like Tutanota, which provide basically zero security over Gmail. (In fact, probably worse, since Google's sec team is way better.)
update No. EME is only intended to be used by content consumers; even if it could be hacked to encrypt uploads / outgoing transfers, that use case wouldn't even be considered important as the spec evolves. Super lame.