Earlier quoted context omitted.
The problem is that phishers register sound alike domains like info-secure-apple.com or atlanta-usbank.com, that were completely clean prior to issuance.
One could argue that should be okay for a class of certificate without identity/organization verification.
What we "need" more of is EV-style validation, so I can see that the site I'm on is an actual company registered in whichever territory. Otherwise all it indicates is that an email address with the associated domain is linked to the private key for this site. Not really what most people are looking for.