Years ago, a Windows virus slipped on to three family machines I'm the go-to-guy for, due to Spotify using IE to display ads, and not vetting its ads properly.
My answer was two-fold - never use Spotify, and always use an ad-blocker.
Ad blockers are mandatory on my parents computers. They can’t distinguish between what is or isn’t an ad (not speaking specifically of Spotify display ads.)
I feel like I hold an opinion no one else reading hacker news has, I believe website owners should be able to deliver ads and website visitors should be able to block them.
I've pretty much always paid for Spotify, and from what I can remember when they first started all of their ads were "radio" ads. How were they using IE to display their ads? Did they introduce pop-ups?