ELSEIF
Your brief EB
284 stories from 72 feeds 54 clusters Refreshed 9 minutes ago next pull 20:20

SECURITY Signal 623 2 feeds carried it

Security Is Hard, Y'all

A security expert mistook Cloudflare's legitimate new product flow for a phishing attack due to poor security UI practices, highlighting the difficulty of distinguishing real features from scams.

WHY IT MATTERS

When legitimate vendors use untrusted domains and confusing OAuth consent screens, they train users to ignore security warnings, making actual phishing attacks harder to stop. It also demonstrates that even sophisticated users and automated support agents cannot reliably distinguish poorly designed legitimate flows from attacks.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Cloudflare launched a new wallet feature on a separate domain (cloudflare.pay) rather than hosting it under their primary domain.

02

The OAuth consent screen used a poorly placed green checkmark that mimicked spoofed display names used in phishing.

03

The author's attempt to report the suspected phishing was hindered by a broken CAPTCHA on the HackerOne reporting flow.

THE CLUSTER

Same story, 2 feeds.

ORDERED BY FIRST SEEN
Lobsters Security is Hard, Y’all Open ↗
Hacker News Security Is Hard, Y'all Open ↗