upvote
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.

GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.

Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.

reply
Once upon a time, RuneScape ran a promotion where World of Warcraft players could join a special world with double XP or something by clicking this promotion link.

RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...

reply
Fricken Proton has a separate domain that lists all of their apps, https://protonapps.com/. This absolutely screams "scam", but no, it's real.

Ffs, just put this on apps.proton.me or something so I actually know it's real!

reply