I seem to miss the point. Are you aware that anyone can generate and upload
a key with some uid like "Jeff Garzik <firstname.lastname@example.org
Yes, that's why you need to trace the web of trust. If it's a long chain of Bitcoin related people but all on an island, it might all be fake. At some point some of those people will have ties to say well known kernel developers, who in turn have a large web of trust. Those are unlikely to be fake so you can have reasonable trust in this key, unless somehow one or more people were duped into signing the key of course.