Live data from Hacker News

Spotify and Facebook: Is that phishing?

weluse.de

91–96 of 96 posts

Re: Spotify and Facebook: Is that phishing?

#91
post #57
post #27

The fact that the user was logged into Facebook after giving Facebook credentials to Spotify is not the problem. The login screen communicates that this will occur. Maybe it doesn't communicate it as well as it could, but it does communicate it. The problem is that Spotify added itself to the user's list of apps and granted itself access to the user's data without any communication that this would occur. I guess you…

Here's the tricky part: they do ask for permission to post on your behalf when you open the app. It's pretty muted, at the bottom of a popup, and dwarfed by a larger, more colorful call to action. Here's a screenshot: http://i.imgur.com/oWDstiC.png It's also not entirely obvious to me what happens in every case. If I close the popup, does it still count as my giving consent? If I close the app? My guess is that most…

Well spotted. But a user who'd disabled/cancelled/deactivated their FB account would assume that action was moot rather than that Spotify were going to illegally access a secondary service posing as you in order to enable that activity.

Re: Spotify and Facebook: Is that phishing?

#92
This is why no two services know me by exactly the same email address, and different passwords are used everywhere. If I want to share some of my information with your app I will do so deliberately, otherwise you are not getting anything. What's that you say? I can only sign-up via facebook? Well then fine, I guess that means I'll be living without what-ever you are hawking.

Re: Spotify and Facebook: Is that phishing?

#93
post #90

Earlier quoted context omitted.

No, it's not.

Ok, if we added some text saying 'Login with Facebook' to our login form and then did the above it would be exactly what Spotify are doing. And still illegal.

Spotify aren't "logging into the users account" as suggested, the user is signing in with their fb details and by adding an app to their account fb reactivates their account. The issue here is only one of poor communication, not of illegal account access. Saying otherwise is disingenuous.

Re: Spotify and Facebook: Is that phishing?

#94
post #56

Earlier quoted context omitted.

Irrelevant: the point was that Spotify doesn't have permission or ask permission for what it does.

For Facebook they do. They have a tight partnership. If Spotify did something wrong with their Facebook app, Facebook would have removed their app a long time ago.

Permission from the user not from Facebook.

Re: Spotify and Facebook: Is that phishing?

#95

Earlier quoted context omitted.

It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…

Facebook does not give implicit permission to access "your friends' email addresses." In fact, they don't grant that permission under any circumstance.

What I believe the OP was saying is that they grant access to the friends list, and that Quora already has many of their e-mail addresses. Thus, they indirectly get access to your friends' e-mail addresses.

Re: Spotify and Facebook: Is that phishing?

#96
I'd want to know if the OP ever had a Spotify account before, with the same email (m*@gmail.com). I suspect he has, and that Spotify account was previously linked to the FB account.

Another strong possibility is that he has an existing Spotify account which was created using Facebook Connect. Creating an account with FB Connect would provide Spotify his email, and Spotify would likely have created a user record for that email (this is the recommended behavior from FB).

If either is true, then I think this is what happened:

- Spotify has an old user record in their database, associated with his Facebook account. He might not realize this, especially if his Spotify account was created via FB Connect.

- When he created the new Spotify account, Spotify had a bug/feature which linked the new Spotify account with the old Spotify account.

- Spotify then sent a "logged in via FB Connect" signal to Facebook, which caused his Facebook account to reactivate. This is normal behavior for Facebook - FB interprets any login gesture as a signal that you want to reactivate your account (be it a 3rd party login via FB connect, opening the FB app on your phone, or logging into the FB website)

This seems plausible to me, and wouldn't indicate any malice. Whereas Spotify's engineers writing a screen scraper to login to Facebook and secretly install an app seems exceedingly unlikely.

Post reply on HN