The author argues that phishing failures are a system design problem, not a user problem, as modern login flows redirect through multiple third-party domains making it impossible for users to distinguish legitimate auth from phishing. The piece highlights how SaaS ecosystems fragment authentication across unfamiliar domains, undermining traditional security advice like checking URLs.
Background
Multi-domain authentication flows are common in modern SaaS ecosystems, using OAuth and identity providers like Okta, Auth0, and similar services.
- Source
- Lobsters
- Published
- Sep 10, 2026 at 11:14 PM
- Score
- 6.0 / 10