Fortunately, it's not true; the situation is actually much better than the comment suggests. As the Protonmail rundown points out, the better PGP clients should be unaffected, and secure even with in-transit interception.
But "another recipient leaked the data" isn't actually the same security breach as "my data was observed". If the message was sent twice to different people, no one even has reason to believe I was sent the data. If the message was sent with multiple recipients, GPG encrypts it symmetrically, then provides an encrypted copy of that key to each user - which means there's no way to check that I actually received a valid copy of the message.
It's a good point, though, that if you're planning the Arab Spring by group email or something, you should currently treat messages as at higher risk even if you use Protonmail.
Not really. PGP provides both signing and encryption. Encrypted unsigned HTML messages have the same level of protection as plaintext, but that adds two very strong qualifiers. Encrypted unsigned messages already make little sense and should be a red flag.
Confidentiality is a separate concern from authenticity of the source. There are obvious cases where the authenticity of the source is irrelevant, e.g. if a message contains anonymous feedback or a tip.