Jump to content

Spotify Car Thing: Difference between revisions

From Consumer_Action_Taskforce
Emanuele (talk | contribs)
Undo revision 9921 by Emanuele (talk)
Tag: Undo
Mr Pollo (talk | contribs)
why was everything duplicated?
 
Line 34: Line 34:
|incidents_6_date=December 9, 2024
|incidents_6_date=December 9, 2024
|incidents_6_text=The removal of the Spotify Car Thing API completely bricked all Car Things in distribution.
|incidents_6_text=The removal of the Spotify Car Thing API completely bricked all Car Things in distribution.
}}On May 28, 2024 Spotify was served a [[Class-action lawsuit|class-action lawsuit]] in the U.S. District Court for the Southern District of New York. The lawsuit claimed "Spotify misled consumers by selling them a soon-to-be obsolete product and then not offering refunds", reports Billboard.<ref name=":3" /><blockquote>All of the claims herein arise out of Spotify’s decision to unilaterally and without recourse cut off its support of the Car Thing and announce its plan to terminate its functionality on December 9, 2024.</blockquote>Many owners of the Car Thing have complained in public forums and to Spotify about the discontinuance of the product and have requested that Spotify address and remedy the problem by providing a refund, equivalent replacement, or allow the Car Thing to be open sourced for use outside of Spotify’s control. Spotify has stated that it will not refund, or replace, the Car Thing, instead recommending that Consumers “reset your Car Thing to factory settings and safely dispose of your device following local electronic waste guidelines.”<ref>https://www.digitalmusicnews.com/wp-content/uploads/2024/05/spotify-car-thing-lawsuit-class-action-mazumder-may-2024.pdf</ref>
}}


Prior to the lawsuit's filing Spotify had setup a refund page for buyers through email which directs customers to [https://support.spotify.com/us/contact-spotify-support/ this link], customers can receive refund with proof of purchase.<ref name=":3" /> The lawsuit was dismissed by the plaintiffs after Spotify began issuing refunds<ref>[https://archive.is/pwsVe "‘Car Thing’ Class Action Lawsuit Voluntarily Dismissed After Spotify Begins Issuing Refunds"] - archive.is - archived 2025-01-28</ref>. The Spotify website for Car Thing now reads "Contact customer service by no later than January 14, 2025 to discuss your refund options." <ref>https://carthing.spotify.com/</ref> The Spotify support web page for Car Thing states that they are discontinuing the hardware product as part of ongoing efforts to streamline their product offerings.<ref name=":02">https://x.com/mypussyfarts/status/1793679258105348378?mx=2</ref><h4>SCT API is shut down and removed from the Spotify App<ref name=":0" /> (December 9, 2024)</h4>The removal of the Spotify Car Thing API completely bricked all Car Things in distribution.
<span></span>
==References==
<span></span><references />
==Consumer Impact Summary==
<span></span>
====User Freedom====
<span></span>
*'''Revocation of control''' - the [[Self-destructive design|discontinuation bricking]] of the device ultimately took away user control for thousands of people. Control was only regained after [[Security|security vulnerabilities]] in the device were exploited.
*'''Dependence on a phone app for basic functions''' - the Car Thing dependence on the Spotify app required that a phone authorized with the Spotify app always be present and connected to the Car Thing. The car thing's lack of offline support [[Forced app download|forced]] the user to use an app possibly unnecessarily.
*'''Retroactive resale falsification''' - the discontinuation bricking incident has created some potential risk for reseller false advertising which has been documented [[False advertising|here]].<br />
<span></span>
====User Privacy====
<span></span>
*'''Data collection''' - Spotify openly admitted that the Car Thing had been developed to collect data on "how people listen to music and podcasts".<ref>[https://web.archive.org/web/20250129004743/https://newsroom.spotify.com/2019-05-17/5-things-to-know-about-spotifys-latest-test/ "5 Things to Know about Spotify’s Latest Test"] - archive.org - archived 2025-01-28</ref> How the data collected through the SCT is useful for this purpose is unclear, in addition it is also unclear what the data is.
*'''Security Concerns''' - The root access exploit<ref name=":1" /> while beneficial to user freedom, allowing them to [[jailbreak]] their device also raises some concerns for future buyers of jailbroken Car Things -- a malicious seller could upload malware onto the device -- resold SCTs may be a potential security risk.<br />
<span></span>
==Consumer Protection Incidents==
<span></span><h4>Production discontinued<ref name=":0">[https://archive.is/9F9Jk "Spotify’s Sordid Car Thing History—Here’s a Timeline of the Disastrous Hardware Release"] - archive.is - archived 2025-01-28</ref> (July 27, 2022)</h4>Production of the Car Thing is quietly halted due to poor sales.<ref>[https://archive.is/Lodo1 "What Happened to Spotify’s Car Thing? Spotify Exits Hardware"] - archive.is - archived 2025-01-28</ref><h4>Price reduced from $89.99 to $29.99<ref name=":0" /> (August 20, 2022)</h4>Spotify reduced the price by $60 in order to clear out their stock. The SCT would eventually sold out exposing more consumers to its discontinuation.<h4>Root access in the SCT is cracked by Security researchers<ref name=":0" /> (October 20, 2022)</h4>Root access was gained on the SCT through local means.<ref name=":1">[https://archive.is/WFjUd "Spotify Car Thing - Root and Custom OS toolkit"] - archive.is - accessed 2025-01-28</ref> While this is damning for the SCT's security it was not significant to consumer security, it merely gave consumers the ability to repurpose the device by uploading their own software. There is a risk that resold jailbroken SCTs could contain malware but this is an unlikely target. Spotify's response to the exploit was "that the product is unsupported, and end-of-life, and therefore no bugs would be accepted pertaining to the product" <ref name=":1" /> which is actually the first time Spotify officially announced the discontinuation. The bypass guide is available [https://github.com/oddsolutions/superbird-bulkcmd here]<h4>Total discontinuation announced<ref name=":2" /> (May 23, 2024)</h4>Spotify official announces the Car Thing's discontinuation on their website warning users that it will cease functioning entirely after December 9th, effectively discontinuation bricking] the device. <ref name=":2">[https://web.archive.org/web/20250128235625/https://support.spotify.com/us/article/car-thing-discontinued/ | "Car Thing discontinued"] - archive.org - archived 2025-01-28</ref> The announcement created a large scale panic with Car Thing owners who had actually enjoyed their product and were disappointed in the future bricking incident.<ref name=":3" /><h4>A now dismissed class action lawsuit is filed against Spotify<ref name=":3">[https://web.archive.org/web/20250129011219/https://techcrunch.com/2024/05/30/spotify-begins-offering-car-thing-refunds-as-it-faces-lawsuit-over-bricking-the-streaming-device/ "Spotify Faces Class Action Lawsuit Over ‘Car Thing’ Deactivation: ‘A Useless Product’"] - archive.org - archived 2025-01-28</ref> (May 28, 2024)</h4>Spotify was served a [[Class-action lawsuit|class-action lawsuit]] in the U.S. District Court for the Southern District of New York. The lawsuit claimed "Spotify misled consumers by selling them a soon-to-be obsolete product and then not offering refunds, reports Billboard".<ref name=":3" /> Prior to the lawsuit's filing Spotify had setup a refund page for buyers through email which directs customers to [https://support.spotify.com/us/contact-spotify-support/ this link], customers can receive refund with proof of purchase.<ref name=":3" /> The lawsuit was dismissed by the plaintiffs after Spotify began issuing refunds<ref>[https://archive.is/pwsVe "‘Car Thing’ Class Action Lawsuit Voluntarily Dismissed After Spotify Begins Issuing Refunds"] - archive.is - archived 2025-01-28</ref>.<h4>SCT API is shut down and removed from the Spotify App<ref name=":0" /> (December 9, 2024)</h4>The removal of the Spotify Car Thing API completely bricked all Car Things in distribution.


==Community Solutions==
<span></span>Spotify had previously posted the code for its uboot and kernel to GitHub, under the very unassuming name "spsgsb" and with no announcement (as discovered by Josh Hendrickson).<ref>https://arstechnica.com/gaming/2024/11/firmware-hacks-are-rejuvenating-spotifys-car-thing-before-the-company-bricks-it/</ref>
There are currently a few solutions on the market to prevent the device from becoming e-waste. This includes software such as [https://deskthing.app/ deskthing], a versatile desktop assistant, [https://github.com/BluDood/GlanceThing GlanceThing], a glanceable action pad, or [https://github.com/usenocturne/nocturne-image Nocturne], a pre-built Debian 12 image for the Spotify Car Thing, that aims to replicate the original function of the Car Thing, still in active development.
==References==
<span></span><references />
[[Category:Products]]
[[Category:Products]]

Latest revision as of 21:12, 25 February 2025

Article Status Notice: This Article is a stub

Notice: This Article Requires Additional Expansion

This article is underdeveloped, and needs additional work to meet the wiki's Content Guidelines and be in line with our Mission Statement for comprehensive coverage of consumer protection issues. Issues may include:

  • This article needs to be expanded to provide meaningful information
  • This article requires additional verifiable evidence to demonstrate systemic impact
  • More documentation is needed to establish how this reflects broader consumer protection concerns
  • The connection between individual incidents and company-wide practices needs to be better established
  • The article is simply too short, and lacks sufficient content

How You Can Help:

  • Add documented examples with verifiable sources
  • Provide evidence of similar incidents affecting other consumers
  • Include relevant company policies or communications that demonstrate systemic practices
  • Link to credible reporting that covers these issues
  • Flesh out the article with relevant information

This notice will be removed once the article is sufficiently developed. Once you believe the article is ready to have its notice removed, visit the Discord (join here) and post to the #appeals channel, or mention its status on the article's talk page.

Basic Information
Release Year 2022
Product Type Physical application extension
In Production No
Official Website archive.org

The Spotify Car Thing was a physical device that allowed extended control of the Spotify app. When connected to a device running the Spotify app the Car Thing accesses an API for communication with the app, interacting with the Car Thing attempts to make API calls for interaction. Production of the Car Thing stopped July of 2022. The product ceased functioning on December 9th 2024 when the Car Thing API was shutdown, preventing the device from interacting with the Spotify app.

Consumer Impact Summary[edit source]

User Freedom[edit source]

  • Revocation of control - the discontinuation bricking of the device ultimately took away user control for thousands of people. Control was only regained after security vulnerabilities in the device were exploited.
  • Dependence on a phone app for basic functions - the Car Thing dependence on the Spotify app required that a phone authorized with the Spotify app always be present and connected to the Car Thing. The car thing's lack of offline support forced the user to use an app possibly unnecessarily.
  • Retroactive resale falsification - the discontinuation bricking incident has created some potential risk for reseller false advertising which has been documented here.

User Privacy[edit source]

  • Data collection - Spotify openly admitted that the Car Thing had been developed to collect data on "how people listen to music and podcasts".[1] How the data collected through the SCT is useful for this purpose is unclear, in addition it is also unclear what the data is.
  • Security Concerns - The root access exploit[2] while beneficial to user freedom, allowing them to jailbreak their device also raises some concerns for future buyers of jailbroken Car Things -- a malicious seller could upload malware onto the device -- resold SCTs may be a potential security risk.

Consumer Protection Incidents[edit source]

Production discontinued[3] (July 27, 2022)

Production of the Car Thing is quietly halted due to poor sales.[4]

Price reduced from $89.99 to $29.99[3] (August 20, 2022)

Spotify reduced the price by $60 in order to clear out their stock. The SCT would eventually sold out exposing more consumers to its discontinuation.

Root access in the SCT is cracked by Security researchers[3] (October 20, 2022)

Root access was gained on the SCT through local means.[2] While this is damning for the SCT's security it was not significant to consumer security, it merely gave consumers the ability to repurpose the device by uploading their own software. There is a risk that resold jailbroken SCTs could contain malware but this is an unlikely target. Spotify's response to the exploit was "that the product is unsupported, and end-of-life, and therefore no bugs would be accepted pertaining to the product" [2] which is actually the first time Spotify officially announced the discontinuation. The bypass guide is available here

Total discontinuation announced[5] (May 23, 2024)

Spotify official announces the Car Thing's discontinuation on their website warning users that it will cease functioning entirely after December 9th, effectively discontinuation bricking] the device. [5] The announcement created a large scale panic with Car Thing owners who had actually enjoyed their product and were disappointed in the future bricking incident.[6]

A now dismissed class action lawsuit is filed against Spotify[6] (May 28, 2024)

Spotify was served a class-action lawsuit in the U.S. District Court for the Southern District of New York. The lawsuit claimed "Spotify misled consumers by selling them a soon-to-be obsolete product and then not offering refunds, reports Billboard".[6] Prior to the lawsuit's filing Spotify had setup a refund page for buyers through email which directs customers to this link, customers can receive refund with proof of purchase.[6] The lawsuit was dismissed by the plaintiffs after Spotify began issuing refunds[7].

SCT API is shut down and removed from the Spotify App[3] (December 9, 2024)

The removal of the Spotify Car Thing API completely bricked all Car Things in distribution.

References[edit source]