Announcements

Help Wizard

Step 1

NEXT STEP

[All Platforms][Other] 2-Factor Authentication

Spotify should, as a matter of good practice and safety, implement 2-step authentication.

 

Previously, Spotify enabled the option to log out other sessions other than the current session.

 

This would prevent hackers from stealing accounts, which would additionaly lead to less account hacks and less work for Spotify employees to assist in these cases.

 

More info: https://twofactorauth.org

Updated on 2018-10-18

Hi everyone, thanks for bringing us your feedback in the Spotify Idea Exchange. We’re ready to mark this idea as ‘Under Consideration’. 

 

We are currently investigating various solutions for account security for our users, e.g. 2-factor authentication. Any news regarding user-facing security updates will be posted to this thread as a status change.

 

If you'd like further information about protecting your account please visit our Support Site here.

Comments
dshadows07

Having just had my account taken over by someone and recovered by spotify support - I Strongly suggest they implement this for at least changing of email addresses to prevent the account being taken over in the first place.

marcusneipp

Especially for administrators of Spotify Family it is very neccessary to have the possibility to use 2FA!
That's by far the only point why I'm not completely confident with the Spotify service...

I work in the IT department and nearly daily I get to know someone whose account has been stolen.

It's really irremissible to add the 2FA feature as soon as possible!

meahtenoha
Status changed to: Good idea, vote for it
Updated: 2016-06-09

Hey @ThomasVH we also think this is a good idea.

Please continue to leave your comments and kudos here and we'll post again here if we have any updates on this. Thanks!



Nethead

anyone at spotify awake?

 

the world is crashing around us because people are not using 2FA and spotify doesn't even offer it

 

using a net service today without 2FA is like having sex in Zika Lands without a condom, don't do it

zeroxxx

Why is this still not implemented? Ugh Spotify....

bleedyblue

Is someone at Spotify actually reading the comments?

mackoy85

Yes I think so. They should be reading these comments

SuperSluether

If Spotify adds 2-factor authentication, they need to use something more secure than SMS codes. The National Institution of Standards and Technology updated their guidlines and highly recommend against using SMS. It's unencrypted, easy to hijack, and is only as secure as the cellular service. (case and point when someone successfully changed Verizon plan info using only the last 4 digits of someone's SSN)

 

2FA needs something you know (password) and something you have (phone, computer, etc). Maybe they could add the feature in-app, similar to Twitter's (now unavailable) "Login Requests" which would send a request to the app when someone wants to log in.

lobor7

Yesterday my account was hacked and someone -not me- was playing from my account. Even though it was likely my fault in the end due to the usage of a very very old password  that shall NOT be an excuse for the POOR security that Spotify provides which is pretty dissapointing and what is more important, Spotify is clearly aware about this issue -this post is quite old already- and  yet NOTHING has changed. Please, improve it!. Let the users control which devices can connect to the system. Add a second layer e.g. security text code / Phone call authenticator what's so ever while a new device tries to connect to the account and so on.... Otherwise I will have to explore  an alternative music service. 

Hopefully someone from Spotify read this

Nandu88

We've seen criminals selling stream services hacked account access now and then. Please reduce this risk. 2FA is a must for any service from people who care about security.