My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
Ffs, just put this on apps.proton.me or something so I actually know it's real!
RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...