Mind, this was also intended for a world where internet connectivity was not to be expected. The majority of PC owners were not online.
I feel like either way, you'd need the key to be different for every CD, otherwise you could just share the shared key. But if the encryption of every CD is different, why not just share the block cipher key directly? They can have a list of CDs and the associated key(s).
What additional security or functionality does an RSA like step add here?
Also the same way we got viruses, long before anyone I knew had the Internet.