Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
IrvHammer

I messaged Spotify on Twitter asking about this. 

"
When can we expect to have 2-Factor Authentication as well as Device Management implemented on Spotify...? These are basic services that have become commonplace everywhere with the exception of Spotify, a company being as big as it is."

Their response:
"Hey there. We're afraid we don't have any info on this at the moment. Rest assured, we'll get this passed on to the right team. If you ever need anything else, just shout and we'll come running /BY"

I responded with:
"Please do pass it on to the team. The Customer's personal information including payment info, email, and passwords should be of the utmost importance, setting aside everything else. Including profit. Without the customers trust, there is no profit."

In my opinion, there is no sense of urgency with them to protect you or your information. My advice? Let them know on twitter how much you want this to happen. Make it visible there. This should be a top priority for them with the amount of transactions they handle.

jadeatriz

3 years to put it "under consideration", and 2 years after that, this is still a problem? Come the **bleep** on, you're talking about users that are spending money on your platform having their accounts stolen on a regular basis right now. I didn't think people would seriously want to steal a Spotify account, but hey, it happened to me.

ParentalControl

Looks like Spotify added a "sign in with Apple feature." https://support.spotify.com/mt/account_payment_help/account_help/sign-in-with-apple/

 

This is nice but still doesn't leave the other log in loop hole of just the password.

AL511

This was requested back in 2015 this is 5 years ago are there any new updates as to 2FA or it's been forgotten? I would think security is a priority but this doesn't seem that important the last update was in 2018.

Norbzz

My account was hacked some time ago...come on guys!!! Are you serious???? We need 2FA - ASAP!!! I am shocked this is showing as - under consideration

lednar

Why is this under consideration? Does Spotify not take information security seriously? Come on- 

aeseidel

How is this not a Feature yet this is security 101? it's been 5 year cmon

sampanda

I keep getting hacked... keep changing passwords, email accounts, and signing out of all account. I have locked security on all online accounts, with individual passwords, and am using lastpass vault to host complex passwords that should be secure. I can't figure out where the security breach is, hoping it's not malware on desktop. The hacker keeps leaving messages and sabotaging my playlists, this is so frustrating I'm close to deleting my account and going back to good old fashioned local music libraries. Sort this out Spotify and set up 2-factor authentification. 

Send a message with your wallet, stop paying for this garbage and just have them delete your account, for the record,  I've had a Pandora account for many years and have never had this problem.

Mohamed-Magid

This post is 5 years ago, why it's not implemented by now? I see a lot of .txt files on telegram channels filled with hundreds of premium accounts' logins, implementing such a feature is not a luxury is a necessity!