scams that require two-factor authentication,

How does that work? To pull that off, they should have your phone number beforehand, right?

Like the other day I noticed a phishing website purporting to be a fairly large Saudi bank held a certificate issued by an Israeli CA.

Wait, what?

