Earlier quoted context omitted.
I feel like the "authentication company should have known" thing is unuseful; most developers at "security" companies are just ordinary generalist developers. Ironically, I think they boned themselves by trying to be too clever here, not too casual.
You don't think a company whose entire reason for being is providing security services for other companies should have designs related to authentication reviewed by security experts?
That's the assumption everyone makes and it's dangerous.
The fact that someone or some entity does something and only special doesn't make them the best at it (or even close). It's just what they do to survive (and earn).