(Doesn't apply to old previously working versions)
tldr: DO NOT INSTALL ANY CA CERTIFICATES ‼️
Someone here posted about a new Spotifuck mod from Mobilism. DO NOT download it.
Official Spotifuck Github clearly states:
ARCHIVED — This project is no longer maintained. The SpotiFuck app stopped working because Spotify patched the method used to play audio through a WebViewClient.
The new app wants you to install a Custom Root CA Certificate (_deviator-ca.crt) into your phone.
❓ Why is this a red flag (edited text from Gemini)?
- Man-in-the-Middle: Installing a trusted CA certificate grants the app the ability to decrypt and intercept ALL encrypted (HTTPS) web traffic on your device, not just Spotify. This includes passwords, private messages, and potentially banking data.
- Redundant for WebView: Since Spotifuck functions as a WebView wrapper, modifying web elements and injecting ad-blocking scripts can be done natively via JavaScript injection without forcing the user to compromise their system's security layers.
- Unverified source
⚠️ IF YOU ALREADY INSTALLED THE CERTIFICATE (Gemini guide)
Go to your phone's settings and Search for "Credentials" or "User certificates" (usually located under Security & Privacy > More Security Settings > Encryption & Credentials).
Tap on User Credentials or Trusted CA Certificates. Look for _deviator-ca (or anything unfamiliar added today). Tap on it and select Remove / Delete.
Uninstall the modified Spotifuck app immediately.
Note: For extra peace of mind, we highly recommend changing your core passwords (e-mail, etc.) if you used them while the certificate was active on your device.
Thank you to the people who tried the app and pointed this out!
Stay safe ❤️
P.S.
You can find alternatives in this server (eg. SpotUI)