Apparently their login mechanism lets everyone login as you as long as you click a huge "I verify this is me" button even if they are on the other side of earth, so one fumble with your phone and you grant some random person access to your account
Can I enter an email address on their site and click "I verify this is me" to steal an account? What does the "fumble with your phone" refer to?
Someone goes to booking.com, puts your e-mail address in the sign-in field.
You then get an e-mail with a huge button and if you click it they are granted access to your account without a password, even if you've enabled twofactor.
They do this many times a day so one click wrong in your e-mail app and you've granted someone access to your account.
Oh I get it! So this is the pattern where just clicking the link on ANY device is treated as email confirmation, rather than ensuring it's the same browser that started the request (difficult when people may be checking their email on their phone while signing in on their laptop).
The best fix I've seen for that one is to go straight ahead if the cookies say it's the same browser, otherwise require a six digit code that was sent in the email.
Comments
I don't understand this bit:
Can I enter an email address on their site and click "I verify this is me" to steal an account? What does the "fumble with your phone" refer to?
Someone goes to booking.com, puts your e-mail address in the sign-in field.
You then get an e-mail with a huge button and if you click it they are granted access to your account without a password, even if you've enabled twofactor.
They do this many times a day so one click wrong in your e-mail app and you've granted someone access to your account.
Oh I get it! So this is the pattern where just clicking the link on ANY device is treated as email confirmation, rather than ensuring it's the same browser that started the request (difficult when people may be checking their email on their phone while signing in on their laptop).
The best fix I've seen for that one is to go straight ahead if the cookies say it's the same browser, otherwise require a six digit code that was sent in the email.
Email login: so a message is sent to the email address and one careless action grants the other party the ability to login/continue.