Or use a U2F key as a second factor. Avoiding MITM fishing attacks is one its explicit design goals. In short: the MITM does not have the right key handle, so it cannot initiate the challenge-response.
https://developers.yubico.com/U2F/Protocol_details/Overview.... https://developers.yubico.com/U2F/Protocol_details/Key_gener... https://developers.yubico.com/U2F/Protocol_details/fido-u2f-...
U2F is supported by Google and Dropbox (since one or two weeks). Keys cost ~10-15 Euro a pop. Buy two keys, keep one with you, put the other in a fire-proof safe.
In theory, a phisher could register a company with a similar name to the target website's legal name, obtain a valid EV certificate for that, and then phish using a similar looking domain with a similar looking EV certificate legal name. In practice, if that were to begin happening, I'd like to think that the authorities in charge of legal entity registration (eg. Companies House in the UK) would start requiring identity checks for the legal entity registrations, and then phishers would not have an easy path to exploit this route.
> I'd like to think that the authorities in charge of legal entity registration (eg. Companies House in the UK) would start requiring identity checks for the legal entity registrations
Wait, they don't require that now?