Amazing. Also, this is yet another privacy threat that I dodged because I use the PwdHash extension ( https://www.pwdhash.com/ ). You type the same password for all sites, but the extension invisibly uniquifies them on a per-site basis.
Doesn't seem like a good fit for the paranoid. If you screw up and your master password leaks, an attacker can access all of your accounts. I greatly prefer KeePass + Dropbox, which also lets you securely store usernames and notes. And the passwords are random and not derived from anything.
Spotify and Facebook: Is that phishing?
71–80 of 96 posts
Re: Spotify and Facebook: Is that phishing?
#72Earlier quoted context omitted.
I don't understand this comment. Many companies share investors, especially at the level of Facebook and Spotify. Are you trying to suggest that a mutual investor somehow has enough product control to strong-arm Facebook and Spotify into this?
I assume the parent post does - and so do I, in at least this particular case. Seeing how closly knit Facebook and Spotify are. There's not just a shared investor group - there's also a partnership between the two companies. And it's pretty strong, as in; yes, it does seem like they have shared product control or at least great influences on each others product management Mark Zuckerberg is listed and quoted as one o…
If the intention was to paint the companies as working closely together, talk about how they actually work closely together, not about how the same VC firms at two different points in time happened to give them some money.
Re: Spotify and Facebook: Is that phishing?
#73This is just Spotify not finding a user with username=[your email address] and looking for that user on Facebook. I did a test by creating an account with the email benjamintesterton@mailinator.com (not linked to a Facebook account) and username benjamintesterton. When I tried logging in with the email, it failed, but with just the username worked. If logging in with the email did work, it would mean that Spotify aut…
That is correct. It says quite clearly "Facebook Email or Spotify Username". It's the user's mistake for using their Facebook account instead of the account they just created.
Regardless of Spotify's intentions here, they're benefitting from users' trust in normal login processes to get Facebook account access. Lots of designs exploit users' automatic behaviors like that; see Dark Patterns [1].
Re: Spotify and Facebook: Is that phishing?
#74Re: Spotify and Facebook: Is that phishing?
#75Earlier quoted context omitted.
Facebook and Spotify are tightly partnered together - at one point they actually REQUIRED the use of Facebook to log in. The option to register without Facebook was only reintroduced recently.
Irrelevant: the point was that Spotify doesn't have permission or ask permission for what it does.
Re: Spotify and Facebook: Is that phishing?
#76This is just Spotify not finding a user with username=[your email address] and looking for that user on Facebook. I did a test by creating an account with the email benjamintesterton@mailinator.com (not linked to a Facebook account) and username benjamintesterton. When I tried logging in with the email, it failed, but with just the username worked. If logging in with the email did work, it would mean that Spotify aut…
Not just finding a user on Facebook with an email address, because they also log into the Facebook account and add their app to it. (Hence the re-activation email as well.) Very shady.
Re: Spotify and Facebook: Is that phishing?
#77If you don't want someone to mess with your Facebook account, then perhaps you shouldn't give them your Facebook login and password...
Spotify are knowingly logging into the OPs Facebook account without OPs permission. Shouldn't this qualify as unauthorised access, as in a Federal offence?
Re: Spotify and Facebook: Is that phishing?
#78I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…
It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…
Re: Spotify and Facebook: Is that phishing?
#79Earlier quoted context omitted.
Not just finding a user on Facebook with an email address, because they also log into the Facebook account and add their app to it. (Hence the re-activation email as well.) Very shady.
I really doubt this is Spotify's fault. Facebook has quite the trigger-finger when it comes to reactivation -- clicking a like button with the right cookies will do it, IIRC.
Re: Spotify and Facebook: Is that phishing?
#80I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…
The issue here isn't with Facebook privacy. If I guess (or you tell me) your bank's online login information, does that give me the right to log-in to your account and start mucking with things? Facebook has an API to access your account through OAuth and Graph; Spotify should never login on your behalf.