TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Booking.com says typos giving strangers access to private trip info is not a bug

8 pointsby stalfosknight5 months ago

3 comments

nerdjon5 months ago
This seems like a fairly standard practice used in a lot of systems.<p>Quite a few times I have bought something somewhere as a guest with my email, and then later signed up with that email and all of my history was suddenly in my account. With no confirmation of my email. This doesn&#x27;t seem that much different in practice.<p>Admittedly there are a couple of odd things here. Them refusing to do anything about it and not contact the original purchaser, giving the last 4 digits of the purchasers credit card, and some other things probably should not be the case.<p>I would assume they have a process for &quot;Put in the wrong email address at purchase&quot;, but maybe that falls apart when that email address is associated with another already registered user?<p>That seems the real problem here and not anything about privacy (and I am generally lean on the side of privacy here) when it all boils down to a mistake on the person there made the reservation and accidentally giving someone else their information.
arbol5 months ago
My email address has been used by someone in America to sign up for an online fashion brand. I get emails of their receipts every time they buy new clothes.<p>More recently, they signed up to some tanning salon and I got a receipt for a Brazilian wax!
f33d51735 months ago
I got emails from one of these food delivery services a few times for someone elses delivery. Probably from a typoed email as well. I mean yeah there&#x27;s an information leak, but it&#x27;s the users own fault, and there really isn&#x27;t any way to turn it into an attack, and even if you somehow could it would be quite tricky to make money off of it. So in short this is fear mongering by ars imo