Hacker News new | ask | show | jobs
by mcintyre1994 2628 days ago
They obviously should but it wouldn't really help here. Realistically if a scammer gets my Airbnb email and password they're probably not going to be able to do anything that won't expose themselves, and I'd expect to eventually get my money back from Airbnb if it was all on their platform.

The idea is really to get you making a payment on their fake website. They don't need you to log-in at all, I imagine they use it to look for password re-use more than to log in to the victim Airbnb itself. Skipping login is less suspicious and when you've contacted them on Airbnb they have your name, they can put that into a query param (mine already did this presumably for tracking) and show you logged in addressing you by name.