Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
faust

Considering Spotify is the only service I get phishing mails about, I find the decision to not implement 2FA peculiar at best, downright recless at worst.

I have let my paid subscription lapse, and will not even consider adding payment data again until I am assured of the sites safety.

Meanwhile, I'll be enjoying my music from a different service that actually have robust security measures.

blue_oxen

Just got done recovering my account after someone managed to take over. I have two step auth with all my other accounts. Please increase spotifys security. 

chrisdothtml

Someone discovered my password, logged into my account, and was able to change my login email. I had to prove that I was the owner in order to re-gain access to my account.

 

This is ridiculous. Two-factor authentication has been the industry-standard for years, and any large company that does not provide it is actively making hackers' jobs easier

andrewpm

Spotify,

Will you please do something about your lame account securuity measures?  My account was hacked for the third time in less than 8 months and they managed to change the phone number and mobile network carrier.  Is it too much trouble to ask for a simple txt/email verification alert when something that important is changed?  The only way I knew my account had been hacked was because the songs and playlists were not my listening perferences.  I'm seriously thinking of closing my family account.  

Spotify hacked.JPG

digio1517

Just want to echo the most recent sentiments on this - my account has been compromised twice in the past two months, only affecting my Spotify account despite use of a unique, strong, password. 2-factor is a must!

This is a must have and should be implemented ASAP 

KQEN1

Why the heck wouldn't a service that's being used worldwide implement this service!??

GeorgeNotGina

Why in 2018 is 2FA still being "considered"? This is such bs. I just had to kick some random dude off my premium account because he was piggy backing off my account. You need to add this ASAP even if you dont have enough voters. This should be standard security for a platform like Spotify. 

minggli

My account has just been hacked and thankfully quickly restored. 

 

Spotify should absolutely have the option to enabling 2FA. Just to be clear, I am not talking about 2FA for logging in. It's 2FA for changing critical account details such as email address. 

 

At the moment, hackers can steal premium accounts by changing emaill address without being challenged. It's absurdly lack of secruity.

paxasteriae

What absolutely useless company doesn't even have a simple "confirm you're changing your email address" automated system?  I've just retrieved my account (despite having a strong password), but I guess I can look forward to someone simply hacking it and changing the email again because Spotify are apparently living in the previous decade.

 

But it's nice that basic security is listed as a "not right now" priority...