Security UX Inconsistency
Security UX Bug Report: The 'Protect your account' modal explicitly instructs users to verify the URL is service.ringcentral.com. However, the OAuth flow redirects to login.ringcentral.com. This creates a trust-gap and trains users to ignore URL discrepancies, increasing phishing risk. Requesting the modal text be updated to include 'login.ringcentral.com' as a verified domain.
2
votes
-
Kevin
commented
Also, modal describes contacting support@ringcentral.com which reply’s “This mailbox is not monitored by RingCentral.” - this is an opportunity to improve that, too.