Skip to content

Comment on Booking.com ignores twofactor, lets everyone email-login without a password

Comments

Booking.com has one weird "feature" where they allow you to checkout without signing-in, and using the email of any other Booking.com user without verification in the checkout form. I had dozens and dozens of orders "placed on my behalf" this way; they were all no-shows and their CCs were declined, and they ended up disabling my account for fraud suspicion.

I had the same problem with some unknown party making a booking on my behalf. After digging deeper, I also discovered that anyone can place any booking with your account as long as no immediate payment is required. This spooked me, and I cancelled everything and deleted my account after more than a decade of being their customer.

VRBO allows the same thing. I typo’d an email during a booking, and they had no way of fixing it (talk to property owner). I ended up having to register a new domain with that email address so I could manage my reservation.

Insanity.

:D thats some out of the box thinking

This explains a lot, as this happened to me recently too. First, I thought that someone had managed to hack into my account. Booking support was not very helpful. In the end, I just changed my password and canceled the booking, hoping for the best.

It is baffling that a major travel website is allowed to operate like this.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.