This should also serve as a reminder to use a password vault (like 1Password or LastPass or your browser's built-in functionality). If you use a password vault, it's immediately obvious when you're at a phishing site because the vault won't fill it in.