#singpolymaI *do* think that providing phishing protection at the IdP level mitigates this, and the lack of common phishing protection at the end-website level means that if your IdP has phishing protection you're actually *safer* with a redirection-based auth