The whole point of a well-designed, well-implemented cryptosystem is that even if there is a dude sitting outside my house, he's not getting a single bit of my data. This is just as true for government secrets as it is sending a recipe to my mother. This service is broken, as all such services are. Bad crypto is never, ever, ever excusable.
Not if you're the government. Just send the root CA a "National Security Letter" and bob's yer uncle.
But this is besides the point of in browser crypto. The interesting thing is, you need a reliable delivery platform for your crypto code, but this implies you have a TLS connection. So either a third party can break your TLS and modify the crypto code, or your connection is secure in the first place. The scenarios you are then dealing with, is that the server is potentially malicious, but a malicious server just serves broken crypto.
[Edit spelling]
Even if you are an author, assuming you have visited the site over SSL at least once, then it can't be stripped on future visits since the site seems to use HSTS.
There are many things that can mitigate an sslstrip style attack, but coverage from those things is patchy.