I'm not sure if "any site I visit can add itself to my list of primarity authorities as evil-username@evil-domain", but I do know that the login to the authority is done using Public Key authentication, which unlike passwords isn't subject to phishing. There's no risk in logging in to a rogue authority, since the key never actually leaves your machine.
I don't mean logging into an evil authority, I mean tricking the user into using an evil authority to log in to a relying party. There evidently is or will be a way for web sites to tell your browser that they can serve as a primary authority for some particular email address at their domain. When you visit the evil site, it would register some misleading email address, which your browser would then show in the list of identities whenever you log in to a relying party.
At best, we will still need some way of filtering out junk from the identity list.