"Why shouldn't we assume the NSA has subverted the CA system?"
Broadly speaking, we should. And that's why there's been a lot of work lately in doing things that either build on or bypass the CA system. For instance, even if you get a valid CA certificate for a site you want to spoof, it still has to be a different certificate, so there's more work on certificate pinning. Sure, that doesn't help if the spoof cert is up the first time a given person visits a site, but it still raises the bar for successfully attacking a site surreptitiously, because anyone who hits the site post-pin will get a big warning, which can be picked up with other things. Now the attack has to be even better targeted.
And there's other work going on lately, and while it may not be immediately visible to the general public because this all takes time, it really seems to me this has all gotten a lot more vigorous over the last year. I don't even think it's all Snowden per se... it seems to me generalized security consciousness has gone up lately, like we passed a critical threshold of people's work feeding back on other people's work and the community as a whole has moved to a new level of effectiveness. It'll still be a while before we really see the changes but I think some changes are coming. (Not Utopia. We've still got a long ways to go. But some general improvements.)