You're probably right, I am not a security expert and might not be seeing the whole picture. You log into your bank website connected to an open WiFi hotspot ? I never would do that. I think there is a point where you have to apply common sense.
I do not care about the downvote, my opinion is what it is and I maintain my position. As I see it (me not been a field expert), HTTPS Everywhere will not save the world. You will still have people connecting to the wrongly spelled site (HTTPS or not). Some will even have a false sense of security which would be counter-productive.
I access my through HTTPS explicitly typing the URL. My bank ask confirmation out of band for every dangerous action (by SMS). IMHO, one should be educated to take necessary precautions. In Europe, banks have to cover frauds, the positive side effect is that some banks started to educated user on security (it's cheaper !). I don't know how it is in the rest of the world.
Just to be clear, I am not against HTTPS where it makes sense. I am against HTTPS everywhere as the only security measure. Because, that's what it will come to, "We have HTTPS so we're good, security checkbox ticked". That is not, IMHO, not a good way of thinking about security.
I guess my point is HTTPS everywhere is not the solution and should rather/also educated better/more on the risks of Internet.
That said, I wouldn't mind being pointed at a screencast/viedo (on youtube ;-)) showing how the scenario you refer to would unfold.