* Javascript is, as noted in the article, extremely dynamic; what looks like a reasonable key generation routine (as reasonable as you can get in an environment without a secure RNG) could be redefined 1000 lines later to be entirely predictable.
* The bindings in a single page environment are populated from a variety of sources; some of the most important sources are content-controlled, meaning the trusted code base in your crypto library has to play Core Wars with things like DOM attributes.
* There's a "view source" UI, but there's no common UI to easily inspect the current definition of every symbol in the interpreter; you have no way of knowing whether some interaction between the code, the DOM, and the (implicitly trusted) server hamstrung your crypto code.