'A bad guy could put up a phony website at "yourbank.com" with an identical look and feel to the legitimate website "www.yourbank.com".'
This is incorrect. If the bank registered yourbank.com, then they also control all subdomains including www from the same DNS. Subdomains can't be registered...