Essentially the issue is that you can register domain names using international character sets that look exactly like English, and obtain SSL certificates for them, and it is extremely difficult for the end user to be able to tell that he/she isnt dealing with the English website. Working example of https://www.paypal.com/ demonstrated. |