I so wish security takes would be based on user experience.
Can a user on a touchscreen device read the URL they would ~click on? No, you just lost like half of the web.
Are most URLs even readable? Nope, thanks to URL shorteners.
Can people other than developers read the different parts of a URL? Vast majority doesn't and when it comes to phishing… your brain is going to trick you by auto-correcting typos.
Can a browser make the different parts easier to read? They've been doing it for the current location like a decade ago, sadly they haven't done that in the tooltip yet.
And so on.