Earlier quoted context omitted.
It comes with a list of the notaries and their public keys. So, the only concern is if your initial download is MitM'ed. http://www.cs.cmu.edu/~perspectives/notary_list.txt
Or the attacker could just block those servers and then spoof that file with new URLs and public keys.
Hard to spoof a file that you've already got a local copy of...