| ▲ | 63stack 2 hours ago | |||||||
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent. | ||||||||
| ▲ | madeofpalk 2 hours ago | parent [-] | |||||||
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations. GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on. Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com. | ||||||||
| ||||||||