2 pointsby throwaway892017 hours ago1 comment
  • jprezant5 hours ago
    I don't think Google would consider this an open redirect. It displays a notice and requires user interaction.
    • throwaway892015 hours ago
      It doesn't for me at all. If I go to the URL I provided in the OP, the Google server responds with a 301 status code and Location header. Both when logged into a Google account and without logging in. Strange that it behaves in a different way (?) for you.

      It will probably filter the URL through Google Safe Browsing, but that doesn't help much for phishing as they mostly use new or reputable domains, and browsers check that list on default settings anyway.