Skip to content

Comment on Mysterious leak of Booking.com reservation data is being used to scam customers

Comments

I understand that a hotel needs to know the name & booking reference of the guest. But surely Booking.com could operate an email relay so that the hotel never gets to see the user's real email address?

That way Booking.com would be able to see the contents of any messages and shut down spammers more easily. They could do the same with a phone / SMS relay as well.

If done, booking.com would be accused of hiding customer identities as a way to lock in customers to their platform. I don’t have a reference right away, but similar concerns were raised with the “Sign in with Apple” scheme.

How would Booking.com go about identifying scammy emails from compromised accounts? Is that even possible at their scale?

To put that into perspective, has Amazon managed to reliably detect and shut down compromised Marketplace shops yet?

They do do this, just not in all cases

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.