What I mean is that SSH and WWW have very different usage patterns.

I guess it is technically possible to verify every TLS certificate out-of-band. But would you really be willing to do that for every TLS-enabled web site you connect to? And even if you were willing to do that, the average user would never do it.