Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password reset by Spotify, and logged out of devices, after suspicious activity #732

Open
bryce-carson opened this issue Nov 22, 2024 · 3 comments
Labels
bug Something isn't working

Comments

@bryce-carson
Copy link

I used this Flatpak today and was unable to log in, depsite using the correct username and password.

Hours later I was logged out of a browser session of the official Spotify web client and Spotify forced me to reset my password.

There could be a chain of custody issue and the Flatpak or this repository could be compromised.

@bryce-carson bryce-carson added the bug Something isn't working label Nov 22, 2024
@ondras12345
Copy link
Contributor

I think the Spotify detector for "suspicious activity" is just too sensitive.
I no longer actively use Spot, but I had the same issue with mopidy-spotify: see e.g. mopidy/mopidy-spotify#394 (comment)
I cannot say for sure, but I'd be surprised if the flatpak build was actually compromised.

@xou816
Copy link
Owner

xou816 commented Nov 22, 2024

Id be surprised too, but Ill have a look at the sources for the latest release, I havent participated in its release

I guess Spotify is trying to phase out password login for its products, and projects such as spot/librespot/etc are affected (password login has been working hit or miss for the last few weeks/months). they probably have stoppedusing password auth on official products, and what remains is flagged as suspcious -- even before that, spot users would often mention receiving a warning email from spotify

anyway, the good news is that thanks to @stevenleadbeater 's last MR we will use oauth for auth so there shouldnt be any more issues! next release should be good

@bryce-carson
Copy link
Author

Id be surprised too, but Ill have a look at the sources for the latest release, I havent participated in its release

I guess Spotify is trying to phase out password login for its products, and projects such as spot/librespot/etc are affected (password login has been working hit or miss for the last few weeks/months). they probably have stoppedusing password auth on official products, and what remains is flagged as suspcious -- even before that, spot users would often mention receiving a warning email from spotify

anyway, the good news is that thanks to @stevenleadbeater 's last MR we will use oauth for auth so there shouldnt be any more issues! next release should be good

Great, sounds good! I've enjoyed using Spot in the past so I was concerned. Spot is a lovely alternative to the bloat of the official application or the Flatpakked form thereof.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants