Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
msephton

Some press: Spotify Won’t Enable Two-Factor Authentication

 

Let's keep it coming!

msephton

Instagram hacked in a big way (6 million accounts)

http://gizmodo.com/instagram-done-got-hacked-1798732634

 

How long until we see such a serious Spotify hack? 

SuperSluether

According to Instagram's blog, No passwords or other Instagram activity was revealed. (Apparently the random number string in the post's URL "is not permitted in this community"???)

 

I don't think 2FA would have helped in a situation such as this. 2FA only helps when passwords are leaked or brute-forced.

ungratefulninja

Having just received an email that my spotify email address was changed, unbeknownst to me, I would really appreciate a 2 factor authentiation option.  I have enabled it with all of my logins on sites that support it.  Please reconsider this sort of security feature. 

Chosenbc

I know this is going to cause more work, but it is more difficult to get into accounts that use 2-factor authentication, you wouldn't have to be so particular with your privacy statement that is sent after someone got hacked if it was more difficult to get into and take control of someones account. You may want to rethink this. Any company not using 2 factor is not going to last, Google, Amazon they all have added it because of people getting hacked. I think your lack of response to something that has been requested for a few years tells us how much you care about your Customers and in turn the company.

Leuthil

This is absolutely ridiculous how Spotify will not support two-factor authentication. It is not only standard but also become a necessity for any Internet service. I shouldn't have to continuously manage my own security by signing out of all sessions and changing my password whenever I find someone randomly listening on my account. If this is not going to be implemented then I will have to switch streaming music providers to another company that takes their user's security seriously.

Dudefish

In an age with fingerprint technology and mandatory 2fa on any site worth a darn, Spotify sit in their armchair made in switzerland some time in the 1920s.

 

"Ho-ho, Geoffrey, can you believe that people get their spotify accounts hacked?",

"Are you kidding? In today's age where hackers run spam bots and force crack accounts? Impossible, my password is 20 characters long - it'll take 1 machine 10 years!"

"Oh, but they can run thousands of these bots, can't they?"

"Don't be preposterous - you think they have the time to run multiple iterations of the same password cracker on millions of users? I simply don't believe you. Tell the plebians that they just need to put a bunch of exlamation marks - they'll be fine".

Gowillie

You guys just revisited this, but my account being hacked has me very much wanting this. 

thmd

Hi and sorry for butting in!

but I would seriously second that 2-way auth system! (Or as an additional though, get an automated email system saying to people that you don't recognise the devices of other devices other than the ones you usually login to.)

I've aparently been hacked without me noticing recently, indicating people for 2 months back had been adding themselves to family-sharing feature which now exists.

So instead of paying 99SKR I had to pay 149SKR two months straight!

And a little bit more angry respons:

thanks for NOT letting me know beforehand for the attempt! Dx

 

Alright, I am done with ranting xD

 

I hope this message will speed things up for 1 way or another to implement something! 😄

YBlackmore

Awesome, really good security options being dropped... at least let us use another authentication services that are way more secure to create an account, without using passwords.

 

This are best practices used by all the big players.