Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
Joegod

Last week I had 3 attempts from someone trying to log in my account…

When are you going to implement this feature for the premium subscribers?

TRISTAN20

Recently, personal account thefts have been taking place on the Spotify platform. The information i have collected shows that the account cannot be stolen without access to e-mail - and yet it happens.

 

The ideal solution to this problem would be to introduce two-step verification for personal accounts. Unfortunately, this function is only available to Artists, and "Plans" to add such a function for personal users fell through in 2018 (According to the Spotify Ideas forum).


This thread is a rehash of an earlier idea that hasn't been introduced since 2018.

DECAPRIO

Please Spotify, atleast enable 2fa authentication login by Notification or Email or SMS

jsips

My Spotify account was recently accessed (hacked…) by people in Brazil and Portugal. I was notified of the sign-ins, and immediately changed my account info. However, Spotify then flagged ME for suspicious activity (not the sign-ons from another country…?!) when I changed my email address, and switched it back. I had to then change everything AGAIN. Couldn’t help but think how this all could’ve been prevented, if modern security measures were used by Spotify. Ideally, Two-Factor (2FA) or Multi-Factor Authentication (MFA). Spotify also won’t let me change my username, so these hackers will continuously be able to keep trying to access my account trying to crack the new password, and there’s no additional measure I can take to prevent it. I get that they don’t want people to change usernames, but in the case of protecting people’s accounts, I would think there could be an exception? I can’t even use a phone number for additional verification. In short, Spotify really needs to beef up account security measures. 

jsips

IMG_1481.jpeg

IMG_1482.jpeg

IMG_1484.jpeg

monie121

I’m aware that this post already exists, but I’m trying to boost this idea. I was hacked by multiple people in various countries OVERNIGHT. I was asleep, and therefore couldn’t react appropriately until I woke up this morning. Spotify desperately needs 2 factor authentication!!! 

kristjano007

Hello! I'm also passing on an important development idea to your company! It's already 2025 and considering the size and technical capabilities of the Spotify company and your staff, it's high time to create additional two-step login security for users. Google Authenticator is the best and most secure solution in the world and it would be super easy to implement. I believe it would be easy for your company to create one as well. I see that previous reviewers have also pointed out this shortcoming before, but your company has not yet dealt with it. This would be the very first step that should be taken for the security of users! My account was also hacked last summer, my email and password were both changed, and I couldn't get my account back for several months. Finally, because the hacker changed my email for some strange reason, I got it back and I was given the opportunity to change my password. Usually, hackers don't return anything voluntarily and you can't count on it anymore. No one can guarantee that hackers won't take your account away again soon. Thank you very much in advance for creating a two-step login system for us, as customers and users, as a matter of urgency!

Sparagus

Spotify you need to add 2FA asap. 

davegarri

My account was hacked because your Spotify's, or whoever they sell our data to's security is trash. I have been hacked 3 times in 24 hours. This is so stupid. My bank has had 2 factor authentication for over 10 years. It isn't a brilliant concept. If you house financial or sensitive customer information such as credit cards, phone numbers, or addresses, you better protect it. This is crazy.

 

I'm about to cancel my account and go back to youtube music.

SaschaG1

Congratulations on the 10th anniversary of the Spotify Idea for 2-factor authentication and the simultaneous status “under consideration” for over 6 years. @Spotify, have a great day, enjoy the weather and get rich.

.

Feel free to send the support team this cake by e-mail for their birthday.**bleep**

Translated by deepl

 

10th_birthday_2fa.jpg