Important Notice to Our Users
news.spotify.com
news.spotify.com
It has the package name 'com.spotify.mobile.android.ui'.
The new one is 'Spotify Music,' which appears to be brand new. https://play.google.com/store/apps/details?id=com.spotify.mu...
It has the package name 'com.spotify.music.'
To me, this indicates that the signing keys for the Android app were also stolen during the breach.
The new app is signed by "CN=Spotify, OU=Android, O=Spotify, L=Stockholm, ST=Stockholm, C=SE", the old was signed by "CN=Anders Bond, OU=Mobile, O=Spotify, L=Stockholm, ST=Sweden, C=SE". The new key was generated on 2014/05/24.
https://support.spotify.com/us/problems/#!/article/downloadi...
That article has a link to com.spotify.music
Because right now `com.spotify.music` is just over 1MB (down from 15MB) and just shows this screen:
http://i.imgur.com/lZYDyBt.png
Hitting the "Download" button takes you to the "Spotify Music" app page on the Play store.
https://play.google.com/store/apps/details?id=com.spotify.mo...
Use this online tool to install on your device, then open it from the notification drawer and you'll get the screen above. Then do the same from here:
https://play.google.com/store/apps/details?id=com.spotify.mu...
and also scroll down and note that the size is 14MB - i.e. com.spotify.music is the new one.
Anyway, whilst you had that wrong, I had misunderstood. I think Shank was saying that the signing keys for com.spotify.mobile.android.ui were stolen which is why they then changed it to com.spotify.music - which is a reasonable explanation. I had thought that he meant the attacker uploaded com.spotify.music or something.
The reviews are a disaster though. I know those people are just the minority of morons who don't understand what's going on, but holy shit they shout loud. As a Spotify Premium customer I hope it doesn't cause them any major issues.
The alternative explanation would be that Spotify has adopted a total transparency policy that includes even the smallest of incidents, but the total lack of information about what the Android update actually changes doesn't support that.
Am I missing something here?
"Hey, this also has the nice benefit that customers will upgrade to our latest version."
This is likely just a side effect of the new version being an entirely new Android app instead of an upgrade to the existing one. If the local playlist data and/or offline settings were sandboxed to the old app, a new app wouldn't be able to access it.
security is really hard to measure
1) How were the passwords stored (hashed? what algorithm? what parameters?)
2) How were the CC #'s stored (encrypted? what cipher/mode/etc?)
This phrase seems to appear often in press releases and I feel that it usually indicates the opposite. If you feel the need to SAY that, it's probably because you've done something that implies you don't.
-Scope of breach? Check
-Actions taken? Kind of (investigating, patching apps)
-Actions required by users? Check
-Reassurance that everything will be alright, stop cancelling your credit cards? Check
"Cher membre eBay,
Afin que les utilisateurs d'eBay continuent de bénéficier d'une expérience fiable et sécurisée sur notre site, nous demandons à tous nos membres de modifier leur mot de passe.
En voici les raisons : nous avons récemment découvert que notre réseau informatique avait été la cible d’une cyberattaque. Cette attaque a eu pour effet de compromettre une base de données contenant les mots de passe des utilisateurs eBay.
Il est important de souligner que rien n'indique qu'il y ait eu accès à vos données financières ou que celles-ci aient été compromises. Par ailleurs, votre mot de passe était crypté. "