Spotify and Facebook: Is that phishing?
weluse.de
weluse.de
The problem is that Spotify added itself to the user's list of apps and granted itself access to the user's data without any communication that this would occur. I guess you could say that permission for Spotify to do that is implicitly granted by giving them your Facebook credentials. But these days, federated authentication and authorization are two different things for end users -- especially so for Facebook apps. Spotify should at least prompt the user before making these changes on their behalf. Very underhanded behavior.
Here's a screenshot: http://i.imgur.com/oWDstiC.png
It's also not entirely obvious to me what happens in every case. If I close the popup, does it still count as my giving consent? If I close the app? My guess is that most people skim over the copy and click the big blue button, totally disregarding the checkbox down there.
The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users will _always_ use it.
We have thousands of usernames and passwords for users on our services. If we then tried using these to log into our users facebook accounts in order to install an app of ours we'd be rightly prosecuted. Yet this is exactly what Spotify are doing.
As an example, using FB to authenticate with Quora does not list access to friends list in the permissions but Quora will send an email to every friend of yours already on Quora to notify them that you joined.
Another issue with this is that if you have never given any Facebook permission to Blizzard, but happen to use the same email address as listed on your Facebook account then Blizzard will attach your real name to your account without your permission.
As far as I know, spotify uses username for login, and not email. By using your email, it's assuming you want to use facebook.
Of course, the lesson here (besides that spotify cannot be trusted) is that you should never use a password for more than one account. Sure makes me glad I switched to using a password manager that uses randomly generated different passwords for each service I sign up to.
http://benjamin.sonntag.fr/Moglen-at-Re-Publica-Freedom-of-t...
Are you trying to suggest that a mutual investor somehow has enough product control to strong-arm Facebook and Spotify into this?
But you were clearly trying to suggest that shared investors have something to do with this. There's no other information in your comment except that the two companies share investors. And in the context of this incident the only possible implication of your comment is that shared investors somehow influenced this. Otherwise why post the comment at all?
There's not just a shared investor group - there's also a partnership between the two companies. And it's pretty strong, as in; yes, it does seem like they have shared product control or at least great influences on each others product management
Mark Zuckerberg is listed and quoted as one of the references on their sign up page, by the way.
If the intention was to paint the companies as working closely together, talk about how they actually work closely together, not about how the same VC firms at two different points in time happened to give them some money.
I did a test by creating an account with the email benjamintesterton@mailinator.com (not linked to a Facebook account) and username benjamintesterton. When I tried logging in with the email, it failed, but with just the username worked.
If logging in with the email did work, it would mean that Spotify authenticated you with their server and then abused your credential re-use to hack your Facebook account. However, this appears not to be the case.
They should just check email=[input] OR username=[input], but that may be backwards-incompatible and break the functionality of people who use their Facebook credentials to login.
Regardless of Spotify's intentions here, they're benefitting from users' trust in normal login processes to get Facebook account access. Lots of designs exploit users' automatic behaviors like that; see Dark Patterns [1].
The username field says "Facebook Email or Spotify Username". So when you type an email, you log in using a Facebook account.
It's not that hard to understand. By the way, that account you made on the sign up page is still unused: you logged in using a Facebook account, which is a different account from the one you just registered, so you have two spotify users now - one you signed up w/o Facebook and one you actually logged into.
Spotify are knowingly logging into the OPs Facebook account without OPs permission. Shouldn't this qualify as unauthorised access, as in a Federal offence?
Also, this is yet another privacy threat that I dodged because I use the PwdHash extension (https://www.pwdhash.com/). You type the same password for all sites, but the extension invisibly uniquifies them on a per-site basis.
http://zx2c4.com/projects/password-store/
It works damn well.
Think Google's different domains (google.com, google.co.uk, google.nl, gmail.com etc.) The demo gives a different hashed password whenever the TLD differs. And seeing that Google by default redirects you to the homepage of whatever country you're in at the moment, you might end up getting burned by the extension when travelling.
In short, Cryptasia uses a Google Spreadsheet entirely owned & controlled by each user as a 3rd party data store. Each row contains the friendly name of the site, the login URL, the password generation key, a list of allowed characters, which characters are required, and the length of the password to create. By using the same generator key and character sets, one can have the same password for multiple websites. The password can also be changed for a website without having to change your master passphrase, since just changing the generator key (say, adding a "1" afterward) completely changes the created password.
I know it's not as easy to use as a browser extension, but when I visited Europe it was nice to be able to hop on any computer in one of the hotels and check my email.
I can throw this on Github if anyone's interested (the source-code is all in unobscured JS, too).
[1] crypt.asia or http://www.cryptasia.com
Good point. This could happen. I'm assuming by "burned" you mean "unable to login". If so, you can always type in your home country's domain into the webapp version and get the correct hashed password. I agree this isn't ideal. Just saying that there's a plan B.
I greatly prefer KeePass + Dropbox, which also lets you securely store usernames and notes. And the passwords are random and not derived from anything.
Agreed. But OTOH it's a very lightweight solution, which is an advantage. And in any case, it's MUCH better than using the same unhashed password everywhere.
I'm claiming that using PwdHash is strictly better than not using it. YMMV.
It takes two to Tango, but I see incompetence on both sides rather than maliciousness.
So if the user provides their facebook email and the correct password to match, which this user did, the correct behaviour is to log the user in via facebook. Which of course Spotify did.
No bug there. I'd say that this is mostly user error - but possibly Spotify could make it more obvious.
But, as I said before, Spotify could make this clearer.
Also see this comment: http://news.ycombinator.com/item?id=5267040
Another strong possibility is that he has an existing Spotify account which was created using Facebook Connect. Creating an account with FB Connect would provide Spotify his email, and Spotify would likely have created a user record for that email (this is the recommended behavior from FB).
If either is true, then I think this is what happened:
- Spotify has an old user record in their database, associated with his Facebook account. He might not realize this, especially if his Spotify account was created via FB Connect.
- When he created the new Spotify account, Spotify had a bug/feature which linked the new Spotify account with the old Spotify account.
- Spotify then sent a "logged in via FB Connect" signal to Facebook, which caused his Facebook account to reactivate. This is normal behavior for Facebook - FB interprets any login gesture as a signal that you want to reactivate your account (be it a 3rd party login via FB connect, opening the FB app on your phone, or logging into the FB website)
This seems plausible to me, and wouldn't indicate any malice. Whereas Spotify's engineers writing a screen scraper to login to Facebook and secretly install an app seems exceedingly unlikely.
http://www.facebook.com/help/224562897555674?_fb_noscript=1
That's in Swedish for me but I assume it's localized. It says that there are two options, one is deactivation, and if you don't believe you'll need your account again, the other is deletion.
I'm still not sure how or why it happened.
I really hate that, but what if you're using something like coughBangYourFriendscough Spotify, deactivate your Facebook account and can't use Spotify anymore? Maybe you're a paying customer to Spotify? How do you cancel your membership if you can't login anymore?
To me this seems like a Big Communication Problem™ between the User and the App/Facebook. The Facebook API needs a functionality that says "Using a deactivated account for Facebook Connect re-activates your old account automatically".
I totally disagree on methods like this, but i seems plausible in that way.
Just because Spotify accidentally (or purposefully) took advantage of that hole doesn't mean it's not Facebook at fault here.
1. using the same password for spotify and facebook is a dumb thing to do. don't do it.
2. by entering an email address instead of a username means spotify will use facebook auth (it should be made more obvious to users).
3. using facebook api to auth will re-enable your facebook account (apparently restoring photo's and friends lists).
4. facebook adds spotify as an app and gives it access to your facebook account data without explicit permission.
https://www.facebook.com/music
You have the ability to pause and play music from Facebook (which I doubt exists for any other music player with any sort of Facebook integration)
Sounds like it's no longer required, but I suppose I still don't trust them enough to try their service.
Best way to avoid this sort of stuff is just to sign up to spotify with throwaway email.
I have found that it's worth buying a domain name and just tying it to a VPS with SMTP installed (or using a third part service that offers unlimited addresses). That way you can just generate throwaway email addresses as you need them.
[0] http://www.mailinator.com/ [1] http://mailinator.blogspot.com/2008/01/your-own-private-mail...
I just create lots of alias emails associated with a domain name I used to use and still own. Works like a charm and they are always accepted.
I hear mailinator email addresses don't always get accepted by some services (though I haven't experienced this myself to verify).
As for Spotify, as a long time user I love it. Very much worth a try.
I did. :/
For very similar kind of thing.