It is not always enough. For example, recently I have found several ways to spoof the URL and HTTPS lock on Google Chrome. So phishing seems to be a concern.
The fact that you have found "several ways" is intriguing. You are either mistaken, or you're one of the greatest security researchers out there.
In response to your first comment, I should clarify that checking for a valid HTTPS URL SHOULD be sufficient, barring implementation errors in the browser. Of course, if the browser is insecure, all bets are off wrt web security. Implications may range far beyond phishing attacks in that case.
I guess this is a no go for now, then?
>There are three more they are working on.