It might work for things like bots, but a dedicated phisher is next to impossible to deter. Even I could post an application the next day that has some little hidden, highly obfuscated snippet of code that will help get passwords in some way.
Hell, I once made one to show a server owner why they shouldn't save passwords locally since I could just send the file that has both in it to myself via smtp.