2nd factor refers to an OTP code generated using an authenticator app, not the "magic sign-in" link that was sent to them (that was the 1st factor, an alternative to providing the password).
2FA is supposed to protect you even if you accidentally click on the magic sign-in link, but Booking.com is (apparently) not enforcing 2FA.
In my understanding the authenticator app is not the only way to have 2FA. It looks like here Booking was using the email for verification? This seems similar to a forgot password flow.
Comments
2nd factor refers to an OTP code generated using an authenticator app, not the "magic sign-in" link that was sent to them (that was the 1st factor, an alternative to providing the password).
2FA is supposed to protect you even if you accidentally click on the magic sign-in link, but Booking.com is (apparently) not enforcing 2FA.
In my understanding the authenticator app is not the only way to have 2FA. It looks like here Booking was using the email for verification? This seems similar to a forgot password flow.