5 ms·
Important Notice to Our Users
- benrapscallion 12y agoIt's surprising how the titles of such posts always never mention the content, just "Important Information".
- benrapscallion 12y agoIt's surprising how the titles of such posts never mention the content, just "Important Information".
- iambateman 12y agoLooks like somebody REALLY wanted to know what their girlfriend had been listening to.
- pestaa 12y agoSpotify is a paid service, and they store user-sensitive data. Don't underestimate the impact of a breach.
- jasonlfunk 12y agoI think the joke was because only one user's data was apparently accessed.
- wwwwwwwwww 12y agoit's also possible a lot more people were compromised and the trail was covered using log injection or something security is really hard to measure
- 0x0 12y agoWhat's the connection with the Android app? Did someone backdoor it, or something?
- hodgesmr 12y agoI received an unauthorized password reset attempt over the weekend. Seems like I probably wasn't the only one.
- spacefight 12y agoWith the size of the spotify users, that might also have been a typo. Or a targeted attack... but to gain what exactly?
- MattJ100 12y agoAnecdotal I know, but interestingly I also received one last week. I've had the account since Spotify was in private beta and this has happened only once before that I recall.
- bowlofpetunias 12y agoThe complete lack of concrete information and the fact that the "incident" applies to only one user suggests something was discovered that triggered the company lawyers to engage cover-your-ass mode. The alternative explanation would be that Spotify has adopted a total transparency policy that includes even the smallest of incidents, but the total lack of information about what the Android update actually changes doesn't support that. Am I missing something here?
- benrapscallion 12y agoIt's surprising how the titles of such posts never mention the content, just "Important Information".
- ronaldx 12y agoYou may have missed: "Hey, this also has the nice benefit that customers will upgrade to our latest version."
- tomp 12y agoGiven that they are only urging Android users to update, it looks like this isn't a new version, but rather a hotfix for some issue that only existed in the Android app.
- eddywebs 12y agosounds like aftermath of heartbleed
- a1a 12y agoPossibly, but why wouldn't they say so? It seems reasonable to me that they would blame the heartbleed bug instead of taking the blow themselves.
- seefoma 12y agoInteresting note at the end about offline playists having to be re-downloaded. That, and the phrase 'internal company data' has me curious if the breach was some kind theft of media, as opposed to user credentials and info.
- atmosx 12y agoIf that was the case I don't think they would bother writing that blog-post. Why on earth would a user 'care' about another user 'stealing his digital media', when it's just 'songs' that are not even owned, by basically 'rented' on a monthly fee.
- elemeno 12y agoIt sounded like that's a result of the upgrade on Android - presumably they've changed something recently about how they store the offline play lists.
- Shank 12y agoOffline playlists are encrypted by Spotify. Presumably this change means that the encryption keys used by Spotify to store offline data were compromised.
- pionar 12y agoActually, it looks like the "upgrade" is actually a new app entirely, so it's probably just that since it's a new app, the offline data has to be regenerated.
- k-mcgrady 12y agoThe makes sense to me as it's unusual to make such a public announcement when just one users data has been compromised and it didn't include and personal or payment information. It sounds like something Spotify are worried about that likely won't harm actual users and media theft seems like a decent conclusion.
- easytiger 12y ago
- Shank 12y agoInteresting note: there are now two apps in the Google Play Store under Spotify Ltd. The first one -- Spotify, is the existing app. https://play.google.com/store/apps/details?id=com.spotify.mobile.android.ui https://play.google.com/store/apps/details?id=com.spotify.mo... It has the package name 'com.spotify.mobile.android.ui'. The new one is 'Spotify Music,' which appears to be brand new. https://play.google.com/store/apps/details?id=com.spotify.music https://play.google.com/store/apps/details?id=com.spotify.mu... It has the package name 'com.spotify.music.' To me, this indicates that the signing keys for the Android app were also stolen during the breach.
- 6thSigma 12y agoThe hackers would also have to have control of Spotify's Google developer account.
- andymcsherry 12y agoNot necessarily, the app could be installed outside of Google Play. A user could click on an malicious web link that would download the application and prompt them to install, much like https://m.spotify.com/us/ https://m.spotify.com/us/ allows the user to do.
- 6thSigma 12y agoThe new app was submitted under Spotify's account though.
- tokenizerrr 12y agoI think if the signing keys had been compromised they could have released an update to the existing app, instead of having to list a new one. Wouldn't it be more likely that just the google play credentials (or api keys) have been compromised?
- dublinben 12y agoYou can't update an app signed with key X to an app (.apk) signed with key Y. The package names must be different, otherwise you get nasty error, and you cannot update. Their users would be forced to uninstall the old app and reinstall the new one.
- general_failure 12y agoI don't understand why they bother announcing such vague information. Just say 'security breach' in two words and stop instead of this word diarrhea.
- worklogin 12y agoAttention: Not everyone is tech-savvy, tech-anything, or security-anything. Saying "Security breach, no biggie" is not a proper way to communicate with the general public about a service for which they pay. -Scope of breach? Check -Actions taken? Kind of (investigating, patching apps) -Actions required by users? Check -Reassurance that everything will be alright, stop cancelling your credit cards? Check
- reledi 12y agoThe most interesting part to me is that the comments rant about the new app instead of discussing the security issue. Their users really want to be heard. Those are dedicated users whose hatred for the app is fueled by love for the product or company. Spotify should at least let them know that they're listening.
- hendzen 12y agoTwo things missing from this statement that should be part of this note and every note like it: 1) How were the passwords stored (hashed? what algorithm? what parameters?) 2) How were the CC #'s stored (encrypted? what cipher/mode/etc?)
- aggronn 12y ago> Our evidence shows that only one Spotify user’s data has been accessed and this did not include any password, financial or payment information.
- johnnyfaehell 12y agoI think the point here is if your data has been breached you should be reassuring people that password and payment details even if accessed aren't easily readable.
- deleted 12y ago[deleted]
- waylandsmithers 12y ago|We take these matters very seriously This phrase seems to appear often in press releases and I feel that it usually indicates the opposite. If you feel the need to SAY that, it's probably because you've done something that implies you don't.
- jasonlfunk 12y agoThat seems like an unreasonable standard. If you take things seriously - you can't SAY that you do otherwise people will think that you don't.
- halflings 12y agoReceived a similar message from eBay (french): "Cher membre eBay, Afin que les utilisateurs d'eBay continuent de bénéficier d'une expérience fiable et sécurisée sur notre site, nous demandons à tous nos membres de modifier leur mot de passe. En voici les raisons : nous avons récemment découvert que notre réseau informatique avait été la cible d’une cyberattaque. Cette attaque a eu pour effet de compromettre une base de données contenant les mots de passe des utilisateurs eBay. Il est important de souligner que rien n'indique qu'il y ait eu accès à vos données financières ou que celles-ci aient été compromises. Par ailleurs, votre mot de passe était crypté. "