Right, but a targeted phishing attack against an internal user is just as likely to rely on an application (or a facsimile of an application) you
don't control, like a benefits management portal or something that supposedly authenticates through an SSO.
I guess if your argument is that there would be high value in eradicating open redirects wholesale, I sort of see your point. But the incremental value of eliminating one open redirect is marginal at best.