4 ms·
Reused passwords that appears in breaches maybe?
by aks232 8y ago
Reused passwords that appears in breaches maybe?
- egoisticalgoat 8y agoDoesn't seem to be the case, as people have already tried changing their password. From the article: >On Reddit, Callum Dixon wrote: "The same Bergenulo Five keeps being played on my account and I've tried everything - changed my password, logged out of everywhere. I can't stop it!"
- HelenePhisher 8y agoSounds like he enabled a shady 3rd party app on Spotify. Access tokens do not change when the password is changed.
- kingosticks 8y agoIs that normal? Shouldn't they all be redacted when you change your password or is it a convenience feature that they are not?
- kingosticks 8y agoOne guy quoted in the article claims he changed his password a bunch of times and since he's a 'cybersecurity graduate' I'd expect him not to have reused passwords.
- y04nn 8y agoIt was the case for me last year. I never changed the weak password that I used to create a free account. And the email address was breached in the 2012 LinkedIn hack. The attacker changed the account email to a temporary one and removed all my playlists. Spotify reacted rapidly and restored my account in few days. But it looks suspicions to me that the attacker was able to change my email without Spotify sending me a confirmation first (my email account was not broken). Also Spotify is missing 2FA that would have prevented this.
- Sendotsh 8y agoYup sounds to me like someone got a list of valid Spotify accounts from the recent big breaches, then installed an authorised app to play fake artist songs they generated, to reap in some Spotify profits?