How to rickroll Spotify for Android
github.com
github.com
Really great stuff.
I do have some experience in music, and this is likely for uncompressed or hidef playback. Some labels force encryption for hidef (but in general most of the music services stream straight progressive unencrypted even though their contracts require encryption in all cases).
Edit: but doing this is really tough. You're going to need to stitch together those two stream without a gap. This takes a lot of engineering. I've done this in flash and pure js. So this is not an arbitrary decision.
Obviously the NSA would.
Edit: exclusives. https://qz.com/949942/spotifys-new-deal-with-universal-gives...
Edit: the HTTP vs HTTPS is interesting. My guess is because it is slightly cheaper to use HTTP and they serve a fuck load of music. But this only saves you from MITM attacks. People can still grab music out of their cache. So confusing.
Also, as long as it's only streaming audio over http (no auth details etc) the security risk is fairly low considering the added overhead, so it might not be a terrible decision.
Now - is that very likely? Probably not, even if such a vulnerability exists modern exploit mitigation tactics often are able to prevent it from becoming very harmful. But it's worst case.
Android itself has had big media decode vulnerabilities in the past (looking at you libstagefright) but they basically turned out not to be readily exploitable due to ASLR on modern devices.
That's what the optimist says.
The pessimist says, "Android itself has had big media decode vulnerabilities in the past and they only turned out not to be readily exploitable due to ASLR on modern devices".
Unfortunately that dream never came to light.
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2...