~snip~
Above both website is fake even they used https. They will steal your token or password.
~snip~
Using
https is always not have to be legit site. Anyone can buy an SSL and add it to their website. It encrypts the contents of a website only. It does not give you the authenticity of an identity.
Before trading with any website you will need to be very sure about the full domain name. It's same as knowing a person in real life. If you know a person very well in real life then even his twin can not trick you. So, always keep the full domain name in mind.
Remembering only "bitcoinTalk" is not enough. You need to know the full domain name which is "bitcoinTalk.org". If you don't then you may discover yourself visiting the ".net" or ".to" version of bitcoinTalk which are phishing sites. If you remember "bitcoinTalk.org" and see they do not have the
https anymore then still it's the original site.
So, having
https does not always mean that it's a legit site.