Earlier quoted context omitted.
Now that certificates are free, of course, all phishing sites use Let's Encrypt. Evaluating a website's legitimacy using SSL should not have been initiated by browser vendors. The messaging was wrong for the non-tech folks. They do not have anything to do with the site is fake/fraud/malicious. It was just the data-in-transit is safe or not.
That's not my point: My point is that it became a real world tendency because it was pretty accurate: The malicious websites weren't paying for certificates. If even some legitimate businesses balk at the cost of a VMC, your average scammer isn't going to drop that kind of money to get one either, especially since that cost is per-attempt and the approval is somewhat manual and likely involves humans seeing that it i…
If a thing like BIMI is not widespread, would it even help an average non-tech Joe who won’t even understand the reason behind that checkmark on a logo?