Skip to content

Comment on Booking.com ignores twofactor, lets everyone email-login without a passwordparent

Comments

Someone goes to booking.com, puts your e-mail address in the sign-in field.

You then get an e-mail with a huge button and if you click it they are granted access to your account without a password, even if you've enabled twofactor.

They do this many times a day so one click wrong in your e-mail app and you've granted someone access to your account.

Oh I get it! So this is the pattern where just clicking the link on ANY device is treated as email confirmation, rather than ensuring it's the same browser that started the request (difficult when people may be checking their email on their phone while signing in on their laptop).

The best fix I've seen for that one is to go straight ahead if the cookies say it's the same browser, otherwise require a six digit code that was sent in the email.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.