SECURITY Signal 623 2 feeds carried it
Security Is Hard, Y'all
A security expert mistook Cloudflare's legitimate new product flow for a phishing attack due to poor security UI practices, highlighting the difficulty of distinguishing real features from scams.
When legitimate vendors use untrusted domains and confusing OAuth consent screens, they train users to ignore security warnings, making actual phishing attacks harder to stop. It also demonstrates that even sophisticated users and automated support agents cannot reliably distinguish poorly designed legitimate flows from attacks.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Cloudflare launched a new wallet feature on a separate domain (cloudflare.pay) rather than hosting it under their primary domain.
The OAuth consent screen used a poorly placed green checkmark that mimicked spoofed display names used in phishing.
The author's attempt to report the suspected phishing was hindered by a broken CAPTCHA on the HackerOne reporting flow.
THE CLUSTER
↗