4 ms·
Interesting note at the end about offline playists having to be re-downloaded. That, and the phrase 'internal company data' has me curious if the breach was so
by seefoma 12y ago
Interesting note at the end about offline playists having to be re-downloaded. That, and the phrase 'internal company data' has me curious if the breach was some kind theft of media, as opposed to user credentials and info.
- atmosx 12y agoIf that was the case I don't think they would bother writing that blog-post. Why on earth would a user 'care' about another user 'stealing his digital media', when it's just 'songs' that are not even owned, by basically 'rented' on a monthly fee.
- elemeno 12y agoIt sounded like that's a result of the upgrade on Android - presumably they've changed something recently about how they store the offline play lists.
- Shank 12y agoOffline playlists are encrypted by Spotify. Presumably this change means that the encryption keys used by Spotify to store offline data were compromised.
- pionar 12y agoActually, it looks like the "upgrade" is actually a new app entirely, so it's probably just that since it's a new app, the offline data has to be regenerated.
- k-mcgrady 12y agoThe makes sense to me as it's unusual to make such a public announcement when just one users data has been compromised and it didn't include and personal or payment information. It sounds like something Spotify are worried about that likely won't harm actual users and media theft seems like a decent conclusion.
- easytiger 12y agoOr someone got hold of the crypto keys they use to sign all comms to the dl server and they embed the key in the apk
- Rudism 12y agoI don't think the playlist thing is related to the breach at all. This is likely just a side effect of the new version being an entirely new Android app instead of an upgrade to the existing one. If the local playlist data and/or offline settings were sandboxed to the old app, a new app wouldn't be able to access it.