The site owners could do all of that even with HTTPS, and no-one would revoke their certs. Just saying.
And the best Windows malware is actually digitally signed.