Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
BastianReCruz

@Flagg2kj They did help me. It took 2 hours for the support team to answer my email. They logged the account out from every device and reset my email address. They also sent a link to create a new password. I’m happy I was able to recover my account (I have it since 2013), but I think this is not a proper solution since it can happen again and I don’t want to be waiting until I get an answer. The people who accessed my account were able to see my address, my PayPal account info and other sensitive information. I’m really disappointed, and now that I’ve read this discussion has been active since a long time ago, I’m considering switching to another service.

Flagg2kj

@BastianReCruz, you may want to see my post before this one.  Perhaps you can use a temporary (disposable) email instead, and the Privacy.com free service.  I use Privacy already, but have to start using a temp email so that if I get compromised I'll just trash the temp email, etc.  Perhaps it would help, but to create a new account after with new temp email would probably lose my playlists 😞

 

just a thought. I'm very glad you came through on that problem.  I'm still going to try not to switch to quickly and see if the temp email idea works.  If not, then Apple.

Troopahloop

After 8 years - still no 2FA.. what is going on with Spotify's security team?

When2FA

7ywodp.jpg

don't know what to do with this meme ¯\_(ツ)_/¯

MemelistasMX

Any updates on this? 😞 Two factor authentication still not an option, at least on my profile 😞

Atheos1

Well 1 November price goes up, but functionallity keeps getting worse, no 2fa and search is getting worse and worse so now after 6+ years as paying customer I have closed my Spotify account and went to Youtube family instead (youtube music included) I had both for couple of weeks and did not miss anything in Spotify.

joeycjohn191

Proposal:

Spotify should alter its security system design to allow for 2-Factor Authentication or have a method in place to allow for users to confirm that they are indeed the logging into a device. 

 

Reason for Request:

I like to use Spotify at work. My work has very strict network security measures in place and as such utilize private network and proxy. Every time that I log into the desktop Spotify App on my work computer, I receive the following email 6-7 hours later:

joeycjohn191_0-1698949005408.png

 

I've lost count of the number of times that I have received this email and have had to reset my password as I'm trying to use Spotify on my phone after my drive back from work.

 

The email offers no way to way to inform Spotify that this was in fact you but only demands you reset your password. I would have even been willing to pay the extra 5$ (VERY begrudgingly) for Duo thinking that maybe if Spotify thought I had 2 accounts they wouldn't bother me but when I asked Spotify customer support, they stated that the level of my subscription plan would not fix this issue for me.

 

Justification:

2-Factor Authentication is almost universal and a necessity in today's day and age. Additionally, most applications today allow for some sort of confirmation via the user's email or text asking for confirmation of login or at the very least warning of suspicious activity BEFORE enforcing a pure reset and logout. Implementing either of these solutions would not only supplement the existing account security safeguards but also save me the pain of resetting my password for a 50th time.

 

Please Spotify I'm begging you. I've had this account for more than a decade, please don't make me switch.