4 ms·
If your password is leaked, and you then authorize the verification email by clicking on the verify text, how else do you expect Booking.com to prevent access?
by elevatedastalt 2y ago
If your password is leaked, and you then authorize the verification email by clicking on the verify text, how else do you expect Booking.com to prevent access? The point of 2-factor is lost if you are careless with your second factor.
[People seem to be downvoting me but no one seems to be replying with what the reasonable behavior should be. Maybe my understanding of 2FA through email verification is lacking?]
- dns_snek 2y ago2nd factor refers to an OTP code generated using an authenticator app, not the "magic sign-in" link that was sent to them (that was the 1st factor, an alternative to providing the password). 2FA is supposed to protect you even if you accidentally click on the magic sign-in link, but Booking.com is (apparently) not enforcing 2FA.
- elevatedastalt 2y agoIn my understanding the authenticator app is not the only way to have 2FA. It looks like here Booking was using the email for verification? This seems similar to a forgot password flow.