Hackers mostly are using free comodo certificates?!

Do I ever know that?

So, for the forums with DV-certificates where I log in frequently, the pre-established trust is authentication enough?

And to return to your article, is the real problem DV, or is it that a person who enters its login credentials on what looks like a PayPal-site, but has a totally different URL, did not look at the URL-bar at all, not noticing the incorrect URL and the missing EV-indicator?