If you had never visited the site, how would modern security practices
have prevented the attack?
HSTS is useless in this case isn't it?
HSTS is useless in this case isn't it?
Technically, if the domain had DNSSEC enabled, it might prevent this kind of attack, but no regular consumer is using a validating stub resolver, so even DNSSEC wouldn't work.
Now that browsers are saying "Not Secure" by default for HTTP pages, users are apparently expected to notice this popping up where it didn't before and realizing they're on a phishing site.