The fact that the user was logged into Facebook after giving Facebook credentials to Spotify is not the problem. The login screen communicates that this will occur. Maybe it doesn't communicate it as well as it could, but it does communicate it. The problem is that Spotify added itself to the user's list of apps and granted itself access to the user's data without any communication that this would occur. I guess you…
Here's the tricky part: they do ask for permission to post on your behalf when you open the app. It's pretty muted, at the bottom of a popup, and dwarfed by a larger, more colorful call to action. Here's a screenshot: http://i.imgur.com/oWDstiC.png It's also not entirely obvious to me what happens in every case. If I close the popup, does it still count as my giving consent? If I close the app? My guess is that most…
Spotify and Facebook: Is that phishing?
91–96 of 96 posts
Re: Spotify and Facebook: Is that phishing?
#92Re: Spotify and Facebook: Is that phishing?
#93Earlier quoted context omitted.
No, it's not.
Ok, if we added some text saying 'Login with Facebook' to our login form and then did the above it would be exactly what Spotify are doing. And still illegal.
Re: Spotify and Facebook: Is that phishing?
#94Earlier quoted context omitted.
Irrelevant: the point was that Spotify doesn't have permission or ask permission for what it does.
For Facebook they do. They have a tight partnership. If Spotify did something wrong with their Facebook app, Facebook would have removed their app a long time ago.
Re: Spotify and Facebook: Is that phishing?
#95Earlier quoted context omitted.
It isn't an oversight by Facebook - it is by design. Facebook was a part of the decision to use Facebook login credentials to log into Spotify. Additionally, Facebook does not list access to your friend list (and your friend's email addresses) in their list of permissions. Rather, those details are implicit in using Facebook to authenticate. As an example, using FB to authenticate with Quora does not list access to f…
Facebook does not give implicit permission to access "your friends' email addresses." In fact, they don't grant that permission under any circumstance.
Re: Spotify and Facebook: Is that phishing?
#96Another strong possibility is that he has an existing Spotify account which was created using Facebook Connect. Creating an account with FB Connect would provide Spotify his email, and Spotify would likely have created a user record for that email (this is the recommended behavior from FB).
If either is true, then I think this is what happened:
- Spotify has an old user record in their database, associated with his Facebook account. He might not realize this, especially if his Spotify account was created via FB Connect.
- When he created the new Spotify account, Spotify had a bug/feature which linked the new Spotify account with the old Spotify account.
- Spotify then sent a "logged in via FB Connect" signal to Facebook, which caused his Facebook account to reactivate. This is normal behavior for Facebook - FB interprets any login gesture as a signal that you want to reactivate your account (be it a 3rd party login via FB connect, opening the FB app on your phone, or logging into the FB website)
This seems plausible to me, and wouldn't indicate any malice. Whereas Spotify's engineers writing a screen scraper to login to Facebook and secretly install an app seems exceedingly unlikely.