Skip to content

Comment on Booking.com ignores twofactor, lets everyone email-login without a passwordparent

Comments

2nd factor refers to an OTP code generated using an authenticator app, not the "magic sign-in" link that was sent to them (that was the 1st factor, an alternative to providing the password).

2FA is supposed to protect you even if you accidentally click on the magic sign-in link, but Booking.com is (apparently) not enforcing 2FA.

In my understanding the authenticator app is not the only way to have 2FA. It looks like here Booking was using the email for verification? This seems similar to a forgot password flow.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.