Help Wizard

Step 1

NEXT STEP

Making security better

Making security better

Hello! Today my Spotify account got hacked. I've changed my password, logged out all devices, and revoked offline access to all units. However, I still feel a bit uneasy about the whole thing as I discovered the hack a bit randomly and think there's a lot of things Spotify can do to make sure this experience, although annoying, could be made a bit better.

 

1. Whenever a new device logs into your account - send an email to the registered email address. That way you'll get notifed directly if something might be going on.

 

2. When your password has changed - send an email. This is also a good way to know that something might be up. I can't see any emails that confirm that my password had been changed before I discovered I couldn't log in, and I didn't get a confirmation after I changed my password just now. In 2017, going on 2018, I think this is a bit careless.

3. It'd be great if there was a record of where you're currently logged in in the "Log out everywhere" section, along with where in the world the device is. If I'm currently in Sweden but have a logged in device in the US, that might also be an indication that my account has been compromised.

 

4. It'd also be great to have the country information, as well as some type of device information (like the name on the device and/or IP address, take a look at Google for inspiration), under "Offline devices". Right now I have no idea if the device(s) I currently have on there is mine or not.

 

I really hope the Spotify team takes this on board to help users be in charge of their account.

EDIT

 

5. If there was somehow a way for me to remove the playlists/music the hacker listened to from my Spotify data, that'd also be great since I'm now getting recommendations that is based on what they listened to + it affects things like "My year in music".

Reply
0 Replies

Suggested posts