TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Mysterious leak of Booking.com reservation data is being used to scam customers

78 点作者 cjg超过 2 年前

5 条评论

coldcode超过 2 年前
People rarely realize that making a hotel booking at an OTA (mostly reduced to Expedia Brands and Priceline Brands these days) is a combination of their systems that then call the hotel systems to make the actual booking (or sometimes just a fax or email if the hotel has no IT). So information that Booking collects is mostly sent to the hotel system; there isn&#x27;t any other way. Booking could add something to their side which is passed only to the customer (such as an ID of some kind) to ensure anything coming from them is legit since a leak of a hotel system would not have that. That would not help emails purporting to come from the hotel however and is likely doubtful to help much. I doubt most hotel brands would accept an email relay, they are already discounting the price to provide the OTA profit margin so not getting the actual email would be a sticking point.<p>Having worked at an OTA (before Expedia got us) I refuse to book at anything other than a legit hotel system. OTA&#x27;s are fine for price discovery but you often get a better deal (and better service) from the hotel&#x2F;brand directly. The front desk knows you booked via an OTA instead of the hotel directly.
评论 #34776318 未加载
评论 #34774605 未加载
评论 #34776256 未加载
评论 #34774906 未加载
评论 #34775022 未加载
评论 #34774592 未加载
edent超过 2 年前
I understand that a hotel needs to know the name &amp; booking reference of the guest. But surely Booking.com could operate an email relay so that the hotel never gets to see the user&#x27;s real email address?<p>That way Booking.com would be able to see the contents of any messages and shut down spammers more easily. They could do the same with a phone &#x2F; SMS relay as well.
评论 #34774317 未加载
评论 #34774389 未加载
评论 #34774465 未加载
Hackbraten超过 2 年前
Assuming that Booking.com is telling the truth, i.e. only a number of property owners has been compromised, how come 2FA is still not mandatory for property owners?<p>How come their (optional) 2FA only offers SMS, which is known to be insecure, even though FIDO2&#x2F;WebAuthn&#x2F;TOTP has been a thing for years?
评论 #34773801 未加载
评论 #34773705 未加载
flemhans超过 2 年前
A slightly related super annoying thing that&#x27;s beginning to happen more and more often, is that after the booking is confirmed, the &#x27;host&#x27; will send a link to a third party service that asks you to upload your passport&#x2F;ID and enter other personal information, for them to perform a pre-screening of you, whether you&#x27;re a pedophile, a well-behaving person in general, all under the pretence of making your stay easier and more comfortable for you.<p>After making a lot of fuss, they&#x27;ll eventually waive the no free cancellation policy, but then I still have to go over the whole process of finding another place to stay.
sorokod超过 2 年前
<i>Russian shortening service nah.uy</i><p>For Russian speakers there is a joke in there.
评论 #34784181 未加载