And I think you're right about EV? Ignoring gross CAs trying to juice the web, it makes sense to try to link the web's web of trust to our... non-web web of trust. The web is still pretty new, it's still pretty unfamiliar, and a lot of the signals we use to suss out a fraudulent physical shop don't really apply to the web.
I would counterargue, though, that you're really mythologizing physical stores. I think tons of fraud and abuse happen in physical stores, up and down the stack. The "paper trail" is like 45 minutes on LegalZoom. I think it's worth separating things like banks and bank websites from like, illegal casinos and gambling websites (crypto exchanges are what I mean here).
When you kind of pick away at the "physical stores have no fraud" pillar, then I think the web's security/trust model actually holds up. I don't simply rely on TLS to tell me that bankofamerica.com is legit, and I don't think anyone does, which is good because it doesn't! I also have totally different behavior when I'm doing online banking than when I'm [insert risky/shady thing here], because the threat model is different.
And there's where I think we hit a crossroads, because that "risky/shady" thing for everyone is "getting an email that looks like it's from your bank". This is an attack that doesn't really have an analogue in meatspace, but it's super effective because again, we don't have all the signals we normally do. If it were meatspace, I'd notice this wasn't my usual branch and then probably notice some other differences that might give me pause, but the web makes it possible to create a very convincing copy.
So, I think you're right in the large and I super agree. I just think that phishing is very bad and you shouldn't say you solved it when you in fact haven't solved anything. That's (almost certainly) browsers' fault, but that's a little irrelevant imo.