spotify - loads of ports being opened, constantly

I downloaded spotify yesterday http://www.spotify.com/en/ It was featured on, amongst other places, bbc news so i assumed that it was relatively legitimate. I run little snitch (packet sniffer) so once the program was up and running it intercepted a udp connection, which I kind of expected, and then required me to allow connections through the firewall via spotify - ok but now a little nervous. However then little snitch went absolutely balistic trying to connect to dozens of addresses on various tcp ports. I googled little snitch + spotify and this looks like a common experience - the connections are apparently other spotify users and are something to do with bandwidth. How worried should I be about these connections? In the past I've stayed away from peer to peer networks but this wasn't advertisied as such - yet, by my limited knowledge of these things it seems the program is quiet similar. What sort of security risk am I undertaking by allowing an outgoing tcp connection? ( incidently I have emailed the program makers but they have not emailed me back as yet). I ran portscan on the IP of my mac on the LAN and there was a port way up to the 50000s open yet I amrunning it now and in spite of allowing outgoing connection they are not showing up on portscan (is scanning my own ip this wasy legitimate - it appears to be kerboros and sfp are showing as should). Is there a way i can double check what is going on here for my own sense of security?

mac pro, Mac OS X (10.5.6)

Posted on Mar 16, 2009 9:19 AM

Reply
10 replies

Mar 16, 2009 2:24 PM in response to tmx3

Took this quote from spotify's help pages

Why does Spotify use so many internet connections?
Spotify uses a peer-to-peer network along with streaming servers to stream music. This is why you see multiple connections to other Spotify users.


This product is new so who knows if there are any security vulnerabilities yet.

Sounds to me that you are becoming a streaming server yourself when you use spotify. This means that spotify dont have to pay for bandwidth you are paying for it.

I think I will stick with normal internet radio streams.

Mar 17, 2009 9:47 AM in response to tmx3

Hers is what I did. I delete all the spotify rules from little snitch.

Then relaunched spotify the first server snitch reports is spotifies server so allow a connection to that port and server for ever.

then the next server that snitch reports select deny everything for ever.

Spotify will now continue to work only through their servers and none of the peer to peer connections.

i find musics loads quicker in this way as you are not relying on p2p connection only the main spotify server.

Mar 17, 2009 2:43 PM in response to Tim Haigh

great solution - appears to be working fine. Thank you. While they haven't exactly kept the p2p and bandwidth use secret its not particulalry prominent in their promotional material either is it? I've found myself listening to my i tunes a fair bit still anyway - while there is a reasonably broad selection of music there are some large gaps. Anyway, happy listening.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

spotify - loads of ports being opened, constantly

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.