This is the entire point of the article. You can't know if it's the case, you can't either with any software distribution. When you type 'apt-get install opensshd', how do you know if you're getting the package from an uncompromised server?
You just have to trust that the public keys you got are the right ones, and their private keys have not been stolen.
So what the author is saying is that regarding that aspect web crypto is at roughly the same level.
The big problem of course is that there is evidence that the whole CA system is much less reliable than the old GPG signing party system.