Skip to main content
CaptainLeonidas_Sonos
Contributor I
November 1, 2016

When will Sonos put additional security measures in place?

  • November 1, 2016
  • 74 replies
  • 5195 views
Today a read an article (https://www.ncsc.nl/actueel/nieuwsberichten/iot-botnets-veroorzakers-nieuwste-ddos-aanvallen.html for those able to read dutch) in which the dutch Nationaal Cyber Security Center (NCSC) is taken steps to track down security issue's of home used Internet of things devices.
So my question is wether Sonos will step up to the plate.

Far as I know the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

74 replies

Chris
Lead Maestro
November 1, 2016
Someone getting access to my speakers is the least of my worries when it comes to cyber security.
Respect the Queue (2)Move (3)Beam (1) Era100 (2)ARC (1)SonosOne (1)Playbar (4)Play5 (4)Play1 (3)Play3 (1)Port (2)Connect (1) Roam (2) Ace (1)Connect:Amp (4)Sonos Amp (1)Sub + (9) Echo + Smartthings; (2)Play)
CaptainLeonidas_Sonos
Contributor I
November 1, 2016
Someone getting access to my speakers is the least of my worries when it comes to cyber security.

Are you a Sonos employee?
If no -> Thank for your response but I am asking Sonos.
If yes -> Good to know the stance of Sonos in this. Handy to report this to those that do care.
Security is mainly found in a correct mindset and policies applied.
Stuart_W
World-Class Superstar
November 1, 2016
Sonos Staff are indicated as such under their username.

So Chris isn't and nor am I.

Your question isn't particularly clear. You say "are Sonos going to step up to the plate". What do you mean? What is it that you believe Sonos do or don't do that you want them to do/not do in the future?
Arc + Sub (Gen 1) + 2 x Play 1/ Stereo Play 3s/ Era 100 Stereo in Kitchen, One Stereo in Bedroom, Play 1 stereo pair in Study, Play 1in Bathroom, Sonos Move 2
jgatie
November 1, 2016
Sonos employees are noted as such. This is a site where postings by Sonos users and employees alike are encouraged. Put a question out there in public and you will get responses from both, regardless of intent.

My 2 cents:

Your analysis that "the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password" is incorrect. They also have the local to each machine embedded OS and firmware, which is protected by hidden security measures and by the very fact it is embedded firmware that is designed for purpose. Given this, a hacker would have dozens of easier targets if looking to infiltrate your network, and would most definitely choose those over one which, without some pretty sophisticated hacking, would only give them the ability to remotely play music in your home. On the oft chance they did target Sonos, even with the sophisticated hacking, it wouldn't give them much more than this. In short; It is truly the case of worrying about doubling the locks on the 2nd story windows when the front door is wide open.
Chris
Lead Maestro
November 1, 2016
He doesn't want any of our cents .... .so I'd just let him hunker down in his shelter on his own.
Respect the Queue (2)Move (3)Beam (1) Era100 (2)ARC (1)SonosOne (1)Playbar (4)Play5 (4)Play1 (3)Play3 (1)Port (2)Connect (1) Roam (2) Ace (1)Connect:Amp (4)Sonos Amp (1)Sub + (9) Echo + Smartthings; (2)Play)
jgatie
November 1, 2016
He doesn't want any of our cents .... .so I'd just let him hunker down in his shelter on his own.

He may not want it, but he will get it when his assumptions are incorrect. Besides, I love the embarrassed silence that often (but not always, alas) happens when a Sonos rep eventually confirms our posts. 😃
CaptainLeonidas_Sonos
Contributor I
November 1, 2016
If anyone can already point me to additional info available I am more then happy to see it. So sure any 2 cents is welcome.
If I am too concerned on this matter I rather be told that to have to find out I had an IoT bot running havoc on the internet.

Like the DDos Dyn had to endure and thus having website like spotify, netflix being harder to find/access.

If anyone of Sonos would set me straight: all the better. I am then atleast told I have a secured device running.

https://www.shodan.io/ is a site where you dont have to look for certain devices yourself.
Note: have not taken the time to query that site att.
Security is mainly found in a correct mindset and policies applied.
Paulw123
Virtuoso
November 1, 2016
What about getting access to the play5 microphones as well?
jgatie
November 1, 2016
If anyone can already point me to additional info available I am more then happy to see it. So sure any 2 cents is welcome.
If I am too converned in this matter I rather be told that to have to find out I had an IoT bot running havoc on the internet.

Like the DDos Dyn had to endure and thpus having website like spotify, netflix being harder to find/access.

If anyone of Sonos would set me thread: all the better. I am thn atleast told I have a secured device running.


I'm not sure what you are asking. Are you doubting the fact that Sonos uses embedded OS and firmware? If so, then I really don't know what answer is going to satisfy you.

In any case, here is a recent reply from a Sonos rep in regards to the Dyn DDOS incident (not that it is going to satisfy you):

https://en.community.sonos.com/ask-a-question-228987/how-secure-our-registration-information-mirai-a-possibility-for-sonos-speakers-6751742
CaptainLeonidas_Sonos
Contributor I
November 1, 2016
Thanks jgatie.

Not a link that tells me more about the current state of Sonos stance on IoT security but informative.
However still good to know about anyway.
Security is mainly found in a correct mindset and policies applied.