Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
PandaBearEar

Well i would recommend to just use a strong password. if your password is 123456 than of course its easy to get into your account

 

im against 2 step authentification i use spotify almost everywhere. anytime im swithcing now into a public wlan or in wlan in university i would have to authentificate me always. this would be getting on my nerves, because im using spotify to relax and calm down, therefore i want a easy and comfortable way to use spotify.

 

pejarnagin
Sure, nice and comfortable for hackers get access to your account.. sounds comfy to me!
kylclrk

PandaBearEar, you're an **bleep** that obviously knows nothing about 2FA. They can make it so you only need to do it per device, regardless of what network you're on.

 

I've always had very strong passwords (10 or more characters, capital and lowercase letters, special characters, and numbers). And they managed to hack my account. So your argument is invalid.

pejarnagin

Whining about having to click a button when switching networks isn’t a viable alternative. Suck it up buttercup and read some books about security.

GeorgeNotGina

@PandaBearEar wrote:

Well i would recommend to just use a strong password. if your password is 123456 than of course its easy to get into your account

 

im against 2 step authentification i use spotify almost everywhere. anytime im swithcing now into a public wlan or in wlan in university i would have to authentificate me always. this would be getting on my nerves, because im using spotify to relax and calm down, therefore i want a easy and comfortable way to use spotify.

 

Okay well maybe just dont use it if they add it? lol wth? Don't favor less security because you're too lazy to use 2FA 


blue_oxen

I use an alphanumeric with uppercase, lowercase and special characters. My password contains no actual words or sequential numbers. It is unique to Spotify.

 

My password was not the issue. Even an email to verify I was changing my account would have stopped this. 

LittleNickey

I don’t see why Spotify won’t implement this, it’s a basic security feature which all major services should provide.

 

You don’t have to force users to use it, just make it optional.

 

Make use of Google Authenticator and you won’t even have to do that much developing.

Any chance to review this, especially regarding the new W3C standard WebAuthN based on FIDO U2F & 2FA?

 

mlchangerdair

This should be reviewed. Although following https://support.spotify.com/fr/account_payment_help/privacy/protect-your-spotify-account/ advices, it seems an attacker could get access to my account, take ownership, change password and wipe everything through third party apps connecting to spotify.

Alathea
it happens all the time. We pay for family spotify and we've had to reset
our PW and take back our account three times in the last year, and this is
using 'strong' passwords of multi-case characters and symbols.