Help Wizard

Step 1

NEXT STEP

Why is 2FA still not a thing in 2020?!

Why is 2FA still not a thing in 2020?!

So I had to change my unique password for Spotify the fourth time since I decided to buy the premium and I'm really annoyed with the way hacked accounts/paying customers are treated with the lack of safty of their accounts which people put their credit card information into.

My big question is: Why in the blue heavens is 2FA for Spotify still not a thing in 2020?!

I know that I'm not the only one wondering why it isn't implemented by now.
Like I said I had to change it the fourth time now. Every password I had for Spotify I created for just Spotify alone and I keep getting those Low-Fi songs in my Recently played listed.
But why? I'm a Rap & Hip Hop listener!
Why would I listen to that if it's not for me. I don't know the bands/producers, I'm not into that genre of music and I don't want it anything to do with it.

I know for a fact that I don't got on those songs by accident or whatever reason you could pull out. I ALWAYS listen to the songs I favorited, so it would be impossible to get to that music in the first place.

So what does that mean? Well I have to assume someone got into my account right? I've checked that no other devices are connected aside from my PC and phone and forcefully disconnected any devices multiple times, but it keeps showing me those songs after a while, then I change my password, it stays away and then it those songs show up again.

I'm absolutely annoyed that there is nothing I can do to secure my premium account, which I pay for, other then changing my password.
Since when is it the job of the customer to make sure their accounts are safe and do the nessesary precautions to somehow fight an invisible bad guy which maybe got your information already and you can't do nothing else then change your password again?
It isn't and especially it shouldn't.
There is 2FA for everything right now and for a good reason. You guys would be a lot less "busy" with hacked accounts if you implemented a secure system for 2FA. But why bother right?

I'm fully aware that this might be fully ignored or some dumb "automatic-reply-bot" answer getting posted. Trust me I saw the post on here from 2015 where the people from Spotify replied in 2017.

If I get a responds back I hope it's a solid one because if I see that it basically contains the meaning that 2FA can't be implemented right now then I'm **bleep** and cancel my premium that day or even sooner, depending on how long a reply is gonna take.

Not gonna lie, I like Spotify but the lack of security and reading about countless people getting their account hacked or credit card information messed with is not gonna keep me here until 2021 if this keeps getting ignored.
Account safety should be one big priority for a subscription service, especially with all the hackers around the world attacking governments, news stations, websites and whatever else. Do we really need another Playstation Network hacker attack to prove that this is no laughing matter in 2020?

So my final words here before a TL:DR is gonna be:
Please get your head in the game and catch up with your account security flaws because there are enough accounts hacked already.

Edit before posting: putting 2FA in the labels is not available here? Are you kidding?! (Screenshot attached)


TL:DR - 2FA still not implemented, getting random songs in Recently played list, 2FA being everywhere except here, and nothing you can do about people in your account, which you pay for and have no security over, other then changing your password. Also being aware that this might be ignored and that I don't want to see a reply saying 2FA can't be implemented right now.

New Message - The Spotify Community.png
Reply
Top Answer
Mihail
Spotify Legend

Hey everyone,

Thanks for sharing you're feedback and concerns.

We want to reassure you that we've passed them on to the right folks and that the security of your accounts remains our top priority. The development team is constantly looking into new ways to increase the protection of our users and two-factor authentication is one of the mechanisms under consideration.

We recommend that you head over to the idea that requests the introduction of this features and +VOTE for it. We'll inform on any developments there, as soon as there are any. So make sure to subscribe, if you haven't already. 

 

In the meantime it's a good idea to check up on our tips on how to secure you're account in this Support article.

Hope you find this useful. Keep us posted if you have any questions.

 

Have a nice day!

Top Answer
Ivan
Spotify Legend

Hey everyone, 

 

Thank you for all the feedback you’ve given us so far.

 

We want to let you know that we take both account security and the artificial manipulation of streaming activity on our service extremely seriously. We also would like to highlight some of the actions that @Eversome pointed out should be taken if that is indeed the case.

 

Spotify employs multiple detection measures to monitor consumption on the service in order to investigate such activity and we continue to refine those processes. Part of this are email notifications we send to users every time a new login has been detected, as described by @Eversome. Just recently we also ran a test that would prevent usage if an email wasn't verified as part of our continuous efforts to improve security.

 

As with any measure that could lead to legitimate account holders losing access to a service, we need to do our due diligence with rigorous testing to ensure there are as little friction or inconvenience as possible. For the time being, besides the mentioned notifications, we have built and provided tools in place that can help you quickly resolve an issue by yourself. Our support team will of course also be happy to assist you in regaining full control over your account. We also strive to provide information on how to protect your Spotify account. In both instances we try and raise awareness of the third party apps that @Eversome also mentions.

 

Regarding unauthorized streams, there are actually consequences of those and we utilize both technical and manual measures to monitor activity and action is taken, again just as @Eversome correctly states should be done. If you ever come across any suspicious activity on Spotify, reach out to our support team and make sure to report it so it can be investigated.

 

We realize this thread is gone a bit off topic with lots of questions in one place and some speculation of what is and is not done being mixed with it all. It’s for this reason we’re going to lock the thread. Since the best way for us to gather your feedback is via the Idea Exchange with one thread for each topic we suggest having a look at this idea. Check out this article for more info on how ideas work.  

 

Thanks! 

20 Replies

Hey everyone, 

 

Thank you for all the feedback you’ve given us so far.

 

We want to let you know that we take both account security and the artificial manipulation of streaming activity on our service extremely seriously. We also would like to highlight some of the actions that @Eversome pointed out should be taken if that is indeed the case.

 

Spotify employs multiple detection measures to monitor consumption on the service in order to investigate such activity and we continue to refine those processes. Part of this are email notifications we send to users every time a new login has been detected, as described by @Eversome. Just recently we also ran a test that would prevent usage if an email wasn't verified as part of our continuous efforts to improve security.

 

As with any measure that could lead to legitimate account holders losing access to a service, we need to do our due diligence with rigorous testing to ensure there are as little friction or inconvenience as possible. For the time being, besides the mentioned notifications, we have built and provided tools in place that can help you quickly resolve an issue by yourself. Our support team will of course also be happy to assist you in regaining full control over your account. We also strive to provide information on how to protect your Spotify account. In both instances we try and raise awareness of the third party apps that @Eversome also mentions.

 

Regarding unauthorized streams, there are actually consequences of those and we utilize both technical and manual measures to monitor activity and action is taken, again just as @Eversome correctly states should be done. If you ever come across any suspicious activity on Spotify, reach out to our support team and make sure to report it so it can be investigated.

 

We realize this thread is gone a bit off topic with lots of questions in one place and some speculation of what is and is not done being mixed with it all. It’s for this reason we’re going to lock the thread. Since the best way for us to gather your feedback is via the Idea Exchange with one thread for each topic we suggest having a look at this idea. Check out this article for more info on how ideas work.  

 

Thanks! 

Suggested posts