Web security is too hard
SMRTR summary
A developer almost reported a legitimate Cloudflare product as a phishing attack — because it looked exactly like one. The new Cloudflare Wallet feature launched on a separate domain (cloudflare.pay), used suspicious green checkmarks, and triggered OAuth-style permission prompts that mimic real consent phishing attacks. It's a cautionary tale for web developers: poor UX choices on legitimate sites make life harder for users and URL reputation services alike.
SMRTR provides this summary for quick context. The original article belongs to Hacker News.
Read the original article