The one side (I'm summarizing here) says that HTTPS only means that the data transferred over the wire is secure and has nothing to do with authenticating that you're actually talking to the correct website. And that's correct, there are all sorts of MITM attacks, etc. that could be done and people shouldn't automatically trust that seeing a green lock means it's safe to put their password into a website. And that's correct.
The other side says: nothing is 100% secure and security is all about defense in depth and these EV certs can be really helpful. Consider the Washington Post:
https://www.washingtonpost.com/
There is a whole cottage industry of unscrupulous advertisers who make their living off of scraping the look and feel of websites like the WashingtonPost, setting up a URL like washingtonpostnews.com and then making up a fake story about how the Rock was arrested because he had some special muscle growing formula on him that oh look they have a link to buy for only $15/mo.
It's quite unlikely that an EV cert would be issued for washingtonpostnews.com and it doesn't seem crazy to think that there is some value in having the EV cert on the proper www.washingtonpost.com website.
They'll also point out that even DV cert issuance pre LetsEncrypt was a mixed bag of good and bad. Some CA's wouldn't issue you a cert if it had certain habitually abused trademark names, etc. in it. You'd have to do more than just have an email address or a DNS entry for it. This is for terms like BMW, Tesla, Facebook, etc. and this practice legitimately tripped up (but likely didn't stop) a metric ton of phishing sites.
I think LetsEncrypt is awesome and makes a ton of sense and probably has made the internet safer in general. But the general response to things like LetsEncrypt issuing upwards of 15,000 different certs for domains containing "paypal" [1] is that you should rely upon sending your browsing information to Google, Microsoft, etc. so that they can tell you "Warning this is a possible Phishing Site" [2] which worryingly seems like we've then replaced multiple CAs (which we thought were too centralized) with an even fewer number of browser vendors (which are even more centralized).
1 - https://www.bleepingcomputer.com/news/security/14-766-lets-e...