Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

A group session took over my speaker

A group session took over my speaker

Plan

Free/Premium premium 

Country Australia 

 

Device iPhone 10

(iPhone 8, Samsung Galaxy 9, Macbook Pro late 2016)

Operating System: IOS

(iOS 10, Android Oreo, Windows 10,etc.)

 

My Question or Issue

I was listening to Spotify through my google home speaker this afternoon - having initiated the session on my iPhone.  I had been listening to one of my Library lists for a couple of hours when suddenly the song that was playing stopped half way through and a completely unknown song (not from my list) started playing. I had not touched my phone or said anything to the google speaker.  So I picked up my phone to see what was going on. It said I had joined a group session with someone named Andrew something. (I don’t remember his last name and I did not recognise his name. He is not connected to me in any way - on Spotify or through any other social media account.). I have never heard of group sessions before so I didn’t know what was happening.  I selected the song I had been playing before from my list but it only played for about 5 seconds before another song unknown to me came on. I tried to play my song again. And then I got a message to say that Andrew had left the group session.  

 

So tell me. How did someone I don’t know start playing music on my Inhome speaker WITHOUT MY PERMISSION? How did he add me to a group session WITHOUT MY PERMISSION? And more importantly - how do I stop this from happening again?? 

 

THIS SEEMS LIKE A SERIOUS BREACH OF BOTH SECURITY AND PRIVACY TO ME. I would appreciate an early response.  

Reply
66 Replies

Ok,so this is clearly not an isolated issue.

 

I'm starting to think that the speaker I was invited to join belonged to the the restaurant I was eating at... And all the restaurants have private, password protected wifi connections.

 

So why was I able to so easily connect to it?

 

I'm in complete agreeance with kmc2340, you've had multiple reports now, so why is this not being addressed?

 

My child has a Kids account, and to be honest, I don't even want to let them use it, given this highly concerning security breach being completely ignored by the company. I already pay for YouTube Premium, so I'll gladly switch to YouTube Music or another provider in a heartbeat over this malarkey.

I have the same issue. No unknown users (IP-ADRESSor MAC-ADDRESS) on the network and Bluetooth disabled. Still some user names Laxmi is listening to my unit. I dont know any person with that name and it's highly unusual in my country. 
This rise's concern about the security of your service. Doing some network logging to send to the Integrity Regulations Authority. 

Hey folks,


Thanks for keeping us in the loop on this and for the info you're submitting.

 

We're still looking into why this might be happening.

 

We'll keep you updated here as soon as we have more info.

 

Cheers.

AlexModerator
Help others find this answer and click "Accept as Solution".
If you appreciate an answer, maybe give it a Like.
Are you new to the Community? Take a moment to introduce yourself!

Same issue is happening to me. A user was "listening on kitchen speaker" so I joined the session and saw his name and picture. I found him on Facebook and messaged him. It turns out he lives in my town but is 6 blocks away. We messaged back and forth and found out if he casts to his living room speaker (google home) I can see it, join it and change his songs on his speaker. He could do the same for me. THIS IS RIDICULOUS! This is a huge invasion of privacy. I contacted my local ISP and told them they have a huge issue on their hands but it looks like Spotify is assuming anyone on the same broadcast domain for multi cast devices  is "on the same wifi network". This is utterly ridiculous and I can't turn it off by default! Every time I cast to my speaker I have to manually turn off the option of other people joining. Why cant I turn this off by default?? Why can I change the music on someone's speaker 6 blocks away?? 

I’ve pretty much stopped using Spotify.  It’s going to take while to transfer across to another provider - so I’m still using in a limited fashion until I can. They’ve just ignored this issue. 

I've only had this issue once (yet). When I went to open the app on my phone I got the notification that a person I don't know was listening to a bluetooth device unfamiliar to me, and that I could join the session. (I did not, because I DON'T KNOW THAT PERSON, and it freaked me out). I could see the device in my devices list, but I had never connected with that particular device before! 

 

Like everyone else in this thread is saying, this is a gross breach of privacy, and I would like to know what Spotify will do about this!

This thread is from March 2022. It's now almost June and I just encountered the same f***in' problem! Why can't Spotify fix this bug already?!? I really hate having to toggle off the "Multiple people can join and control this speaker" EVERY time I open Spotify. F**K! 

I got the same weird pop-up again this morning after opening the app.

Some person I do not know was playing music on a device I also don't know and if I would like to join the session.
Why the **bleep** would I get a message like this ?
seem like a privacy issue that has been going on for a couple of months now.

Hi there folks,

 

Thank you so much for keeping us updated and letting us know your current situation.

 

We can confirm that this is still being looked into.

 

As soon as we got any news about this we'll post in this thread.

 

Let us know if we can help you with anything else in the meantime.

 

Take care!

JeremyModerator
Help others find this answer and click "Accept as Solution".
If you appreciate my answer, maybe give me a Like.
Live, love, laugh and listen to music 🙂

I'm sorry, but it's now been nearly four months.

 

If Spotify really cared about the privacy issues at play here, the feature would have been disabled immediately and investigated via a sandbox option. Posting sporadic comments that "it's still being looked into" does nothing to ease the concerns of what appears to be an ever growing number of Spotify listeners.

 

I've got a YouTube Premium subscription that's a heck of a lot cheaper than the plan I'm paying for, and unknown people can't just connect to it whenever they want... I'm just going to cancel my Family plan.

 

Just had the same issue. On holiday currently and saw that someone had connected to our speaker which is currently at home and turned off. Asked to join their 'group session', unable to kick out the rogue connectee. Had to ask a family friend to visit the house to check nobody had broken in!

Unacceptable breach of privacy and caused unnecessary stress on myself and my family. Please fix!

I'm so glad I've finally found other users who are upset about this. My personal smartphone has to be connected to my Workplace's public Wi-Fi, there is no separate, secure, network that our personal devices are allowed on. This "Join Session" feature pop-up allows any other user that joins the same network as me to take over my phone / earbuds / Bluetooth device and decide what I'm listening to. And vise verse, I get pop-ups asking if I'd like to "Join [random person's] Session". I don't!! If it was actually someone I knew I could just create a group session and send them the link!! Why on earth is this "local network discovery" feature even a thing, much less enabled by default. GET. RID.

Plan

Family

Device

Google Pixel 3

Operating System

Android / google

 

My Question or Issue

Lately, when I open Spotify I get pop-ups asking if I want to join a session with another device/connect to another device. These are not people on my family plan and seem to be random peoples accounts. I have accidently tapped this pop-up a few times and have also changed what they are listening to. I then don't know how to disconnect from their device without restarting my phone. I have tried turning Bluetooth off and on, it reconnects. How can I stop this from happening without going into Offline mode? I don't want to use a bunch of space downloading everything. Thanks so much!

Hey there @jenadpantano

 

Thanks for reaching out about this and welcome to the Community.

 

In this case, we suggest that you head over to Settings > Devices > turn the Show local devices only option on to see if that makes the difference. This way, only devices that are connected to your local WiFi will be displayed in the devices menu. 

 

Let us know how it goes.

EniModerator
Help others find this answer and click "Accept as Solution".
If you appreciate my answer, maybe give me a Like.
 
“Music acts like a magic key, to which the most tightly closed heart opens.”– Maria von Trapp

That setting is already on. 

Same issue. I have a paid family plan. Every setting turned off to allow this, and it still connects me to random persons and devices. They are preventing multiple posts about this by "merging" them to this thread. Sounds like Spotify doesn't want to admit they have bad coding and security issues. 

See, that "local Wi-Fi" part is the issue, here. Not sure if that's been made clear to Spotify devs yet:
If a user's device is on, let's say, Starbuck's public Wi-Fi, Spotify still reads that as "local Wi-Fi" as if the user is on their (hopefully secure) home Wi-Fi, so it offers the user to "Join Session" with other users of that local Wi-Fi AKA strangers at Starbucks!!
There needs to be a way to tell Spotify whether or not Wi-Fi connections are "trusted/secure". Either manually, or if it can be programmed to somehow automatically see that the current Wi-Fi connection is secured through a password. Then, if it's not secure, don't offer the user to join random sessions!

Hey folks,

 

Thanks for all your replies and for the info shared 🙂

 

We received some news from our engineering team. They made some changes backstage, so make sure the app is up-to-date and then, let us know if this is still happening.

 

If you notice the inconvenience persists, we'll need you to send us the following:

 

  1. Exact Spotify version you're running.
  2. Make/model and OS version your devices.

We'll be on the lookout for your replies!

AlejaRModerator
Help others find this answer and click "Accept as Solution".
If you appreciate an answer, maybe give it a Like.

It's still happening. The Google Play store doesn't say my Spotify needs updating either.

Spotify Version: 8.7.62.398.
Google Pixel 6a, Android Version 12.

EDIT to add: This issue was also happening on my previous phone, a Google Pixel 4 XL, which was also on Android 12.

A screenshot of the problem is attached below, it popped up as soon as I opened Spotify. The device and user in the popup are both completely unknown to me. I'm currently connected to my workplace's public/guest Wi-Fi, and this is a daily occurrence.
EDIT to add: It's too easy to accidentally join! I always have to be extra careful when pressing that "Not Now". This should be a feature that get's tucked away with group sessions or something.

Spotify.png

Version 8.7.72.546

Android Galaxy A51

Playstore says the app was updated six days ago; however, I uninstalled/reinstalled it just to be sure, and I'm still getting the popup asking if I want to join or take over the session. I cannot find a way to disable this feature, and in my case it didn't start happening until the latest update.

Suggested posts