Ephemeral keys, sure. Negotiated with... well... who exactly? The person you thought you were talking to, or someone else?
The available solutions are shared secrets with zero knowledge proof (like OTR does), voice verification (like various "secure phones", a web of trust, or CA infrastructure.
Crypto everywhere will improve things immensely, but (repeating myself) ultimately the user needs to understand how they can trust that the other party is who they say they are. So far we do not have a magic (automatic) way to do that for the user.
Unless NSA has a great Max Headroom version of me, I think people will trust that they are talking to, or listening to me. That's why I wrote "realtime communication."
For store and forward you need public key exchange and a mechanism for trusting identity. However, in most use cases where you have a mix of realtime and store and forward communication, you have ample opportunity for key signing where you can trust the identity of the person asking for your signature.
The available solutions are shared secrets with zero knowledge proof (like OTR does), voice verification (like various "secure phones", a web of trust, or CA infrastructure.
Crypto everywhere will improve things immensely, but (repeating myself) ultimately the user needs to understand how they can trust that the other party is who they say they are. So far we do not have a magic (automatic) way to do that for the user.