The concern is about phishing via URL spoofing. For example, a user might see a URL like `google.com@mycoolphishingsite.se` and believe that "google.com" is the domain. The warning is intended to point out that "mycoolphishingsite.se" is the real domain.
Comments
On Firefox, I just get a warning: "You are about to log in to the site “news.ycombinator.com” with the username “test”"
I'm not entirely sure what the concern is to be honest. If it's tracking, this doesn't provide anything on top of query parameters e.g. ?utm_campaign=
The concern is about phishing via URL spoofing. For example, a user might see a URL like `google.com@mycoolphishingsite.se` and believe that "google.com" is the domain. The warning is intended to point out that "mycoolphishingsite.se" is the real domain.