Live data from Hacker News

Spotify and Facebook: Is that phishing?

weluse.de

71–80 of 96 posts

Re: Spotify and Facebook: Is that phishing?

#71
post #26
post #2

Amazing. Also, this is yet another privacy threat that I dodged because I use the PwdHash extension ( https://www.pwdhash.com/ ). You type the same password for all sites, but the extension invisibly uniquifies them on a per-site basis.

Doesn't seem like a good fit for the paranoid. If you screw up and your master password leaks, an attacker can access all of your accounts. I greatly prefer KeePass + Dropbox, which also lets you securely store usernames and notes. And the passwords are random and not derived from anything.

While it's not a perfect solution, most of the time you are not trying to protect yourself from a dedicated, thinking, hacker. Instead you're protecting yourself against automated systems that share passwords. Unless it was commonplace it would avoid a majority of those issues.

Re: Spotify and Facebook: Is that phishing?

#72
post #16

Earlier quoted context omitted.

I don't understand this comment. Many companies share investors, especially at the level of Facebook and Spotify. Are you trying to suggest that a mutual investor somehow has enough product control to strong-arm Facebook and Spotify into this?

I assume the parent post does - and so do I, in at least this particular case. Seeing how closly knit Facebook and Spotify are. There's not just a shared investor group - there's also a partnership between the two companies. And it's pretty strong, as in; yes, it does seem like they have shared product control or at least great influences on each others product management Mark Zuckerberg is listed and quoted as one o…

I would understand if the parent comment had noted everything in your second and third paragraphs about the strong partnership between product teams and Mark Zuckerberg's reference on the sign up page. That stuff seems incredibly relevant in this context.

If the intention was to paint the companies as working closely together, talk about how they actually work closely together, not about how the same VC firms at two different points in time happened to give them some money.

Re: Spotify and Facebook: Is that phishing?

#73

This is just Spotify not finding a user with username=[your email address] and looking for that user on Facebook. I did a test by creating an account with the email benjamintesterton@mailinator.com (not linked to a Facebook account) and username benjamintesterton. When I tried logging in with the email, it failed, but with just the username worked. If logging in with the email did work, it would mean that Spotify aut…

That is correct. It says quite clearly "Facebook Email or Spotify Username". It's the user's mistake for using their Facebook account instead of the account they just created.

I don't think it's fair to blame the user for that. This is a standard-looking login form that users will have seen hundreds or thousands of times before. You don't reinterpret the words on a login form every time you see a new one; you type in the stuff to log you in without really thinking about it.

Regardless of Spotify's intentions here, they're benefitting from users' trust in normal login processes to get Facebook account access. Lots of designs exploit users' automatic behaviors like that; see Dark Patterns [1].

[1]: http://darkpatterns.org/

Re: Spotify and Facebook: Is that phishing?

#74
Spotify is able to do this because they have partnered with Facebook. Facebook has white listed them for a set of API's that allow them to convert a Facebook User/Password into a Facebook auth token. Any time this whitelisted API is called the application that called it is automatically added to the users list of applications. Spotify is then white listed (by Facebook) for a second set of API's that allow them to add any permission available to the Facebook access token they were issued. This is why you see permissions being added to the application that were not clearly communicated. Facebook requires partners that are on these white lists to clearly communicate what is happening, but IMO Spotify does a particularly poor job of this.

Re: Spotify and Facebook: Is that phishing?

#75
post #56

Earlier quoted context omitted.

Facebook and Spotify are tightly partnered together - at one point they actually REQUIRED the use of Facebook to log in. The option to register without Facebook was only reintroduced recently.

Irrelevant: the point was that Spotify doesn't have permission or ask permission for what it does.

For Facebook they do. They have a tight partnership. If Spotify did something wrong with their Facebook app, Facebook would have removed their app a long time ago.

Re: Spotify and Facebook: Is that phishing?

#76
post #48

This is just Spotify not finding a user with username=[your email address] and looking for that user on Facebook. I did a test by creating an account with the email benjamintesterton@mailinator.com (not linked to a Facebook account) and username benjamintesterton. When I tried logging in with the email, it failed, but with just the username worked. If logging in with the email did work, it would mean that Spotify aut…

Not just finding a user on Facebook with an email address, because they also log into the Facebook account and add their app to it. (Hence the re-activation email as well.) Very shady.

I really doubt this is Spotify's fault. Facebook has quite the trigger-finger when it comes to reactivation -- clicking a like button with the right cookies will do it, IIRC.

Re: Spotify and Facebook: Is that phishing?

#77
post #37

If you don't want someone to mess with your Facebook account, then perhaps you shouldn't give them your Facebook login and password...

Well yes of course, you shouldn't use the same user:pass for different sites. But a lot of people do, and that opens them up to being hacked if the password for one site is revealed.

Spotify are knowingly logging into the OPs Facebook account without OPs permission. Shouldn't this qualify as unauthorised access, as in a Federal offence?

Re: Spotify and Facebook: Is that phishing?

#78

I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…

It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…

Facebook does not give implicit permission to access "your friends' email addresses." In fact, they don't grant that permission under any circumstance.

Re: Spotify and Facebook: Is that phishing?

#79
post #76
post #48

Earlier quoted context omitted.

Not just finding a user on Facebook with an email address, because they also log into the Facebook account and add their app to it. (Hence the re-activation email as well.) Very shady.

I really doubt this is Spotify's fault. Facebook has quite the trigger-finger when it comes to reactivation -- clicking a like button with the right cookies will do it, IIRC.

How would the app be installed?

Re: Spotify and Facebook: Is that phishing?

#80
post #55

I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…

The issue here isn't with Facebook privacy. If I guess (or you tell me) your bank's online login information, does that give me the right to log-in to your account and start mucking with things? Facebook has an API to access your account through OAuth and Graph; Spotify should never login on your behalf.

That would be illegal (highly illegal actually). It should also be illegal to do what Spotify is doing, but I'll go out on a limb and say that they won't be held accountable. People have gone to jail for incrementing IDs in GET variables, accessing Facebook accounts without permission and installing apps goes way way beyond that.
Post reply on HN