I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…
It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…
Spotify and Facebook: Is that phishing?
81–90 of 96 posts
Re: Spotify and Facebook: Is that phishing?
#82Earlier quoted context omitted.
The issue here isn't with Facebook privacy. If I guess (or you tell me) your bank's online login information, does that give me the right to log-in to your account and start mucking with things? Facebook has an API to access your account through OAuth and Graph; Spotify should never login on your behalf.
That would be illegal (highly illegal actually). It should also be illegal to do what Spotify is doing, but I'll go out on a limb and say that they won't be held accountable. People have gone to jail for incrementing IDs in GET variables, accessing Facebook accounts without permission and installing apps goes way way beyond that.
We have thousands of usernames and passwords for users on our services. If we then tried using these to log into our users facebook accounts in order to install an app of ours we'd be rightly prosecuted. Yet this is exactly what Spotify are doing.
Re: Spotify and Facebook: Is that phishing?
#83Earlier quoted context omitted.
It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…
Is this true? I hadn't seen this. I've found Facebook specifically don't let you access the emails of a user's friends. Quora could easily receive higher access of course, but this still seems like it shouldn't be possible.
Re: Spotify and Facebook: Is that phishing?
#84Earlier quoted context omitted.
Is this true? I hadn't seen this. I've found Facebook specifically don't let you access the emails of a user's friends. Quora could easily receive higher access of course, but this still seems like it shouldn't be possible.
But Quora gets your email address and your friend list, and then when your friend joins they get your friend's email address, so they can email you both about each other.
Re: Spotify and Facebook: Is that phishing?
#85Earlier quoted context omitted.
Why is everyone jumping to blame Spotify for maliciousness? All I see is that they have a bug where they instantly assume emails = Facebook login. Then they try logging in using that email, and because this user reuses passwords, it works. It takes two to Tango, but I see incompetence on both sides rather than maliciousness.
It's not a "bug" if they specifically ask the user for their "facebook email" or their "spotify username" - which of course they do! So if the user provides their facebook email and the correct password to match, which this user did, the correct behaviour is to log the user in via facebook. Which of course Spotify did. No bug there. I'd say that this is mostly user error - but possibly Spotify could make it more obvi…
Re: Spotify and Facebook: Is that phishing?
#86Earlier quoted context omitted.
It's not a "bug" if they specifically ask the user for their "facebook email" or their "spotify username" - which of course they do! So if the user provides their facebook email and the correct password to match, which this user did, the correct behaviour is to log the user in via facebook. Which of course Spotify did. No bug there. I'd say that this is mostly user error - but possibly Spotify could make it more obvi…
So reactivating the facebook account and adding the app to the facebook account without the user agreeing to either is fine for you?
But, as I said before, Spotify could make this clearer.
Also see this comment: http://news.ycombinator.com/item?id=5267040
Re: Spotify and Facebook: Is that phishing?
#87I'm ashamed that this doesn't surprise me much. This looks like a huge oversight on Facebook's part, but with the countless reports on Facebook failing with privacy here, there and everywhere, it's like I don't care anymore. The thing that numbs me even more is that client work, no matter how good of an argument one gives, will always have some form of third-party social login because it's oh-so-important and users w…
The issue here isn't with Facebook privacy. If I guess (or you tell me) your bank's online login information, does that give me the right to log-in to your account and start mucking with things? Facebook has an API to access your account through OAuth and Graph; Spotify should never login on your behalf.
Re: Spotify and Facebook: Is that phishing?
#88Earlier quoted context omitted.
That would be illegal (highly illegal actually). It should also be illegal to do what Spotify is doing, but I'll go out on a limb and say that they won't be held accountable. People have gone to jail for incrementing IDs in GET variables, accessing Facebook accounts without permission and installing apps goes way way beyond that.
I agree that it seems illegal. We have thousands of usernames and passwords for users on our services. If we then tried using these to log into our users facebook accounts in order to install an app of ours we'd be rightly prosecuted. Yet this is exactly what Spotify are doing.
Re: Spotify and Facebook: Is that phishing?
#89Earlier quoted context omitted.
You can signup with an email address , but the option is hidden quite low in the signup page. Best way to avoid this sort of stuff is just to sign up to spotify with throwaway email. I have found that it's worth buying a domain name and just tying it to a VPS with SMTP installed (or using a third part service that offers unlimited addresses). That way you can just generate throwaway email addresses as you need them.
You can also use Mailinator[0] and their many other domains for throwaway email addresses. In fact, you can point your MX records to mail.mailinator.com for a custom domain without running a VPS.[1] [0] http://www.mailinator.com/ [1] http://mailinator.blogspot.com/2008/01/your-own-private-mail...
I just create lots of alias emails associated with a domain name I used to use and still own. Works like a charm and they are always accepted.
I hear mailinator email addresses don't always get accepted by some services (though I haven't experienced this myself to verify).
Re: Spotify and Facebook: Is that phishing?
#90Earlier quoted context omitted.
I agree that it seems illegal. We have thousands of usernames and passwords for users on our services. If we then tried using these to log into our users facebook accounts in order to install an app of ours we'd be rightly prosecuted. Yet this is exactly what Spotify are doing.
No, it's not.