Authors put big-name travel and booking sites to the test to see how their security practices fare against other online services. Booking.com, Hertz, American Airlines and InterContinental Group scored poorly in areas like two-factor-authentication (2FA), and in assessing password strength when accounts are created. 96% of travel sites tested did not provide 2FA (two-factor authentication), where the system asks users to validate their identity on a second platform. Norwegian Cruise Line flunked on all points of security best practices, receiving zero stars.”]