We technical people instinctively know there's a fundamental difference between those 2 domains. Normal people don't. And why should they?
We (tech people) have to get the situation to a point where we don't expect normal people to have to know all these silly details.
I'm not doing anything to help achieve this, I'm hoping other people are :)
When my car makes a noise, I take it to Don the Car Care Man because aside from replacing the battery and windshield wipers I can't do much. If they told me I needed to get part X replaced, I'd trust their input and buy part X.
When people visit eBay, there is an inherit level of trust placed in that site. It's a legitimate business used around the world. If a listing links outside of eBay and is asking for personal information, not everyone understands that such behavior is a sign of an attack.
My grandma doesn't know what a URL is. If I told her to visit my companies website, she would ask where it is in her bookmarks. Just like I would ask where part X in my car goes. To me that's a very basic question; to a car expert they might be thinking: "Good thing this guy is having us take care of the problem".
Someone learned enough to start up a computer, log in, access their web browser, navigate to an online storefront, select products they want to buy, navigate through the checkout process, and enter their details to effect the purchase has already demonstrated the pattern matching skills and knowledge necessary to answer the easy question "Is the picture of the lock there?" and the slightly more involved question "Do the words up match with where the page says I am?"
I'd be willing to bet your grandma can understand "When you're shopping somewhere, make sure the lock icon is in that bar at the top of the window before you put your credit card in". This is stuff that's been drilled into people since the early 90's when eCommerce began to become a thing.
It's not arcane knowledge, hardly "expert" level, it's a basic skill that anyone who shops online should have.
The idea that we can advocate against users having that skill provides dubious benefit to systems security and a handicap to what is the weakest link in any secure process, the human element. Anything we can do to make end users more skeptical is a Good Thing.
We've been trying to drill it into people to look for the lock icon before entering anything personal for decades and it's kinda starting to stick.
Is it really that much more to ask that you double check to see if the URL you're putting your sensitive information on matches what it claims to be?
It's literally right there. A glance upwards. No clicks or any special arcane knowledge required.
On one hand they want the site to be friendly to the power-users that make up what I would guess is the majority of the products that sell, on the other hand are users that are deciding between eBay or Amazon and don't care to know the difference.
My guess is that eBay isn't competing with some other auction site or even Craigslist for most buyers, but Amazon.
So I go to http://www.beamng.com. I click the link that says "buy it now". I'm suddenly redirected to http://sites.fastspring.com/beamng/product/alpha
Both of these sites are unencrypted, and the second site has nothing to do with the first site. Do I book it out of there? All signs say yes. I wanted to buy a game from BeamNG, not from Fast Spring, whatever the hell that is. I've never even heard of them.
If we train users to follow the best practices, this game would never have a single sale. If people want to buy this game, they have to ignore that. How do we teach exceptions? Now we're getting into the territory where it's too difficult to teach to people who aren't techies.
If I have a cough, I take Robitussin. If it doesn't go away, I go to the doctor because I am not a medical expert. It's not that I can't be taught how to tell what is wrong with me, its that it's unreasonable for me to know that and still keep my day job. If I knew that, I would be a doctor. If users knew every exception to security, they would be security engineers.