Hacker News new | ask | show | jobs
by daguava 1567 days ago
I recently went to pay for a music service and wanted to give spotify a chance, but they have a huge information leak somewhere on when new accounts are created.

On the day of my free trial ending I received the first and only phishing email I've ever had from spotify telling me my trial was ending and it was time to swipe.

Up until then I had been happy with the service, but then noticed I was about to get owned.... Down to the day of expiration...

I emailed their support about how this was sketchy and they needed to do better information masking and got told their team did not consider any of this a vulnerabilty.

With this in tow, it really cast some shade on their serious engineering abilities for me.