Live data from Hacker News

Spotify and Facebook: Is that phishing?

weluse.de

51–60 of 96 posts

Re: Spotify and Facebook: Is that phishing?

#53

I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…

We kind of have a different problem. Clients all want it in the apps we make, but analytics show that very few users use those features. Which sucks because it takes forever to implement all that stuff -_-

Do you know of any 3rd party data on that (perhaps a blog post or published data)? Intuitively I believe what you are saying, but I really want to show someone else.

Re: Spotify and Facebook: Is that phishing?

#54

It says quite clearly: "Log in with Facebook or Spotify". That means you can log in using a Facebook account or a Spotify account. The username field says "Facebook Email or Spotify Username". So when you type an email, you log in using a Facebook account. It's not that hard to understand. By the way, that account you made on the sign up page is still unused: you logged in using a Facebook account, which is a differe…

It says "Log in with Facebook or Spotify," not "Log in with Spotify, or log in with Facebook, reactivating a disabled account if necessary, and then grant us a bunch of permissions." Nobody cares that it attempted a Facebook authentication. We care that it silently reactivated the Facebook account and silently gave itself permissions.

Re: Spotify and Facebook: Is that phishing?

#55

I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…

The issue here isn't with Facebook privacy. If I guess (or you tell me) your bank's online login information, does that give me the right to log-in to your account and start mucking with things? Facebook has an API to access your account through OAuth and Graph; Spotify should never login on your behalf.

Re: Spotify and Facebook: Is that phishing?

#56
post #7

Earlier quoted context omitted.

And yet that in no way gives them the right to use that to log into your facebook (rather than using the API to authenticate) and install the spotify facebook app (giving themselves whatever permissions they like without asking the user). Of course, the lesson here (besides that spotify cannot be trusted) is that you should never use a password for more than one account. Sure makes me glad I switched to using a passw…

Facebook and Spotify are tightly partnered together - at one point they actually REQUIRED the use of Facebook to log in. The option to register without Facebook was only reintroduced recently.

Irrelevant: the point was that Spotify doesn't have permission or ask permission for what it does.

Re: Spotify and Facebook: Is that phishing?

#57
post #27

The fact that the user was logged into Facebook after giving Facebook credentials to Spotify is not the problem. The login screen communicates that this will occur. Maybe it doesn't communicate it as well as it could, but it does communicate it. The problem is that Spotify added itself to the user's list of apps and granted itself access to the user's data without any communication that this would occur. I guess you…

Here's the tricky part: they do ask for permission to post on your behalf when you open the app. It's pretty muted, at the bottom of a popup, and dwarfed by a larger, more colorful call to action.

Here's a screenshot: http://i.imgur.com/oWDstiC.png

It's also not entirely obvious to me what happens in every case. If I close the popup, does it still count as my giving consent? If I close the app? My guess is that most people skim over the copy and click the big blue button, totally disregarding the checkbox down there.

Re: Spotify and Facebook: Is that phishing?

#58
To Summarize:

1. using the same password for spotify and facebook is a dumb thing to do. don't do it.

2. by entering an email address instead of a username means spotify will use facebook auth (it should be made more obvious to users).

3. using facebook api to auth will re-enable your facebook account (apparently restoring photo's and friends lists).

4. facebook adds spotify as an app and gives it access to your facebook account data without explicit permission.

Re: Spotify and Facebook: Is that phishing?

#60
I somehow thought that apps could no longer 'login' to social network accounts using usernames/passwords, so that they would have to use OAuth instead? There should be a way that Facebook and Twitter would prevent an app from using login information in order to bypass the 'app authorization' dialog which is supposed to be shown to users to tell them what the app can do to their account.
Post reply on HN