Huh, that's just security theater. The phisher could set up a website that does require authentication, thereby avoiding the warning.
The sensible thing to do would be to display the warning if the username contains unescaped dots. (I.e., http://cnn.com:article123456@fakenews.example.com/ would provoke warnings, but http://cnn%2Ecom:article123456@fakenews.example.com/ would not.)
http://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning
Then I tried http://security.wellsfargo.com@customerLoginv=ar3351RandomDa...
Which stretches way past my laptops viewable URL bar... and it takes me right to badsite.null (or a valid site like example.com). If you need HTTPs you can redirect on badsite.null's web server. Very wild.