AVForums

Our philosophy in our forums, reviews, podcasts and feature videos is to promote audio and visual excellence by gathering and sharing the best information and resources available.

Help

To begin please visit our help section »

Not a Member Yet?

It only takes a minute to start enjoying the benefits of AVForums membership, and it's free!

Member Log in

spotify alert

Post Reply
Old 04-03-2009, 6:57 PM   #1
Member
Join Date: Aug 2005
Experience Points:
2,983, Level: 12
Points: 2,983, Level: 12 Points: 2,983, Level: 12 Points: 2,983, Level: 12
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 43, Got 58
Posts: 595
spotify alert

has anyone else had an email alert about a possible account comprimise

Dear Spotify user,

Last week we were alerted to a group that managed to compromise
our protocols. After investigating we concluded that this group
had gained access to information that could allow testing of a
very large number of passwords, possibly finding the right one.
The information was exposed due to a bug that we discovered and
fixed on December 19th, 2008. Until last week we were unaware
that anyone had had access to our protocols to exploit it.

Along with passwords, registration information such as your email
address,birth date, gender, postal code and billing receipt
details were potentially exposed. Credit card numbers are not
stored by us and were not at risk. All payment data is handled
by a secure 3rd party provider.

If you have an account that was created on or before December 19th 2008,
we strongly suggest that you change your password and strongly
encourage you to change your passwords for any other services
where you use the same password.

When choosing your password we provide you with an indicator of
the password strength to help you choose a good one. To change
your password please visit your profile page on our website.

************************
LINK DELETED IN JUST IN CASE
************************
For the technically minded amongst you, the information that may
have been exposed when our protocols were compromised is the
password hashes. As stated, we never store passwords, and they
have never been sent over the Internet unencrypted, but the
combination of the bug and the group's reverse-engineering of
our encrypted streaming protocol may have given outsiders access
to individual hashes.

The hashes are salted, making attacks using rainbow tables unfeasible.
Short or otherwise bad passwords could still be vulnerable to
offline targeted brute-force or dictionary attacks on individual
users, but you could not run attacks in parallel. Also, there
has been no known breach of our internal systems. A complete user
database has not been leaked, but until December 19th, 2008 it was
possible to access the password hashes of individual users had
you reverse-engineered the Spotify protocol and knew the
username.

We are really sorry about this and hope you accept our apologies.
We're doubling our efforts to keep the systems secure in order
to prevent anything like this from happening again.

Regards,
The Spotify Team

OR IS THIS A SCAM
  Quote
Old 04-03-2009, 7:06 PM   #2
Prominent Member
 
sunnybacon's Avatar
Join Date: Mar 2008
Location: Leicester
Experience Points:
11,559, Level: 25
Points: 11,559, Level: 25 Points: 11,559, Level: 25 Points: 11,559, Level: 25
Activity: 0.4%
Activity: 0.4% Activity: 0.4% Activity: 0.4%
Thanks: Gave 386, Got 435
Posts: 3,246
Re: spotify alert

I was just about to post this as well, I just got the email.
I keep trying the Spotify website but it seems to be down.
Not sure what to do now, should I keep trying to change my password or not
  Quote
Old 04-03-2009, 7:48 PM   #3
Moderator
 
Iccz's Avatar
Join Date: Apr 2008
Location: Keystone City
Experience Points:
29,928, Level: 42
Points: 29,928, Level: 42 Points: 29,928, Level: 42 Points: 29,928, Level: 42
Activity: 20.9%
Activity: 20.9% Activity: 20.9% Activity: 20.9%
Thanks: Gave 3,753, Got 4,287
Posts: 19,789
Re: spotify alert

Any chance of a from email address?

I didn't get one.
  Quote
Old 04-03-2009, 8:29 PM   #4
Prominent Member
 
sunnybacon's Avatar
Join Date: Mar 2008
Location: Leicester
Experience Points:
11,559, Level: 25
Points: 11,559, Level: 25 Points: 11,559, Level: 25 Points: 11,559, Level: 25
Activity: 0.4%
Activity: 0.4% Activity: 0.4% Activity: 0.4%
Thanks: Gave 386, Got 435
Posts: 3,246
Re: spotify alert

It was something like spotify@spotify.com
However I know emails can be faked with websites like Free Fake Email - Send Fake Mail Pranks Anonymously for Free (great for pranks )
I can't see the harm in changing my password though, so I'm gonna do it just to be safe.
  Quote
Old 04-03-2009, 8:45 PM   #5
Member
Join Date: Aug 2005
Experience Points:
2,983, Level: 12
Points: 2,983, Level: 12 Points: 2,983, Level: 12 Points: 2,983, Level: 12
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 43, Got 58
Posts: 595
Re: spotify alert

no email address on mine just, spotify and subject spotify security notice
  Quote
Old 04-03-2009, 8:45 PM   #6
Moderator
 
Iccz's Avatar
Join Date: Apr 2008
Location: Keystone City
Experience Points:
29,928, Level: 42
Points: 29,928, Level: 42 Points: 29,928, Level: 42 Points: 29,928, Level: 42
Activity: 20.9%
Activity: 20.9% Activity: 20.9% Activity: 20.9%
Thanks: Gave 3,753, Got 4,287
Posts: 19,789
Re: spotify alert

Quote:
Originally Posted by sunnybacon View Post
It was something like spotify@spotify.com
However I know emails can be faked with websites like Free Fake Email - Send Fake Mail Pranks Anonymously for Free (great for pranks )
I can't see the harm in changing my password though, so I'm gonna do it just to be safe.
Yeah no harm in a password change, strange I never got one though
If the link is to their site, or if you just log in normally and change it there, then you'll be fine.

However fakesend isn't clean when it sends.
If it was from there and you have a proper look into the email and headers etc you'd see:
Quote:
smtp.mail=spotify@spotify.com Received: from localhost ([127.0.0.1] helo=fakesend.com)
  Quote
Old 05-03-2009, 10:08 AM   #7
Member
 
timothyw's Avatar
Join Date: May 2002
Location: London W2
Experience Points:
3,887, Level: 14
Points: 3,887, Level: 14 Points: 3,887, Level: 14 Points: 3,887, Level: 14
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 66, Got 30
Posts: 462
Re: spotify alert

Just noticed this thread, it was a genuine email, you can read about it on the spotify blog which is now up here:
Spotify
  Quote
Old 05-03-2009, 11:56 AM   #8
Member
 
plazmoid's Avatar
Join Date: Jan 2008
Location: Dumfries/Glasgow, Scotland
Experience Points:
1,946, Level: 10
Points: 1,946, Level: 10 Points: 1,946, Level: 10 Points: 1,946, Level: 10
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 67, Got 55
Posts: 560
Re: spotify alert

Also reported on the BBC.
  Quote
Post Reply



Thread information and display options
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off