Skip to content

Comment on Booking.com ignores twofactor, lets everyone email-login without a password

Comments

Who are these “thousands” of other people you are referring to? Is this a Reddit/Twitter/Lemmy thread?

I've been getting those for a longer while now, but didn't realize how bad this scenario was until now.

Reddit just this in the past year:

https://www.reddit.com/r/techsupport/comments/18zewqa/keep_g...

https://www.reddit.com/r/Scams/comments/15oq4pn/bookingcom_v...

https://www.reddit.com/r/Scams/comments/1bblo8a/verification...

There's also posts on twitter and here on hackernews.

But at its core numbers don't matter, the fact that they ignore twofactor and let everyone login by clicking on the request e-mail is a complete failure of security.

Non tech savvy people will absolutely get compromised by this at some point given enough requests, and they don't post to Reddit about it.

I see the top comment in your top link makes the same recommendation I made in another comment here (https://news.ycombinator.com/item?id=40720789).

If it works, you should definitely solve the problem for yourself even before booking.com eventually suffers enough to address the problem more generally.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.