There is already a standard for this, called SRP: https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...
If the phishing site presents a ui that looks like the real site, the user could be tricked into entering his real username/password which the attacker could then use to log into the real site.
Or am I missing something?