Skip to main content
CaptainLeonidas_Sonos
Contributor I
November 1, 2016

When will Sonos put additional security measures in place?

  • November 1, 2016
  • 74 replies
  • 5195 views
Today a read an article (https://www.ncsc.nl/actueel/nieuwsberichten/iot-botnets-veroorzakers-nieuwste-ddos-aanvallen.html for those able to read dutch) in which the dutch Nationaal Cyber Security Center (NCSC) is taken steps to track down security issue's of home used Internet of things devices.
So my question is wether Sonos will step up to the plate.

Far as I know the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

74 replies

jgatie
November 3, 2016
No offense, but much of this seems like tin-foil hat territory. Why would anyone want to break into your Sonos system? What exactly is there to gain that couldn't be gained by breaking into hundreds of other less secure devices? Do you really think a hacker is interested in blasting you with rap music at 5AM?

And by the way, if your network allows a Sonos rep to access your device without your permission, your problem is with your network, not the Sonos device. Nobody should be able to access anything on your network from the outside without your permission, and if it were possible, accessing my Sonos devices would be the very least of my worries. Once again, it seems you are worrying about deadbolts and time locks on your broom closet, while leaving the front door wide open and the jewelry box in plain sight.

By the way, in case you haven't noticed, this is the only thread voicing these concerns. Sonos is used by many, many folks in the tech industry, and you are the only one to voice such grave concerns about security. Now that may serve to give you a hint as to how fringe your concerns are, or it may drive you to think you know something everyone else does not. Either way, this is really fringe stuff to many of us who would be all on board if the concerns you post were actually, you know, concerning.
CaptainLeonidas_Sonos
Contributor I
November 3, 2016
Still awaits a formal response of Sonos itself. However it seems at this time they are being forum-spammed.
Security is mainly found in a correct mindset and policies applied.
Ryan S
Retired Sonos Staff
November 3, 2016
Hey Captain, I just replied back to your private message, so we can continue there if you'd like. I'm not going to go into specific details here in the public eye on player security, but it is something we're always looking at and will continue to improve in the future.
Mark good posts by pressing the like button, and select the best answer on questions you've asked to help others find solutions.
Airgetlam
November 3, 2016
Thank you, Ryan 🙂
Bruce
CaptainLeonidas_Sonos
Contributor I
November 4, 2016
Removed this entry.
Security is mainly found in a correct mindset and policies applied.
MikeV
November 4, 2016
Just wanted to note that while my earlier post indicated that I don't feel Sonos should be considered a "weak link" in a network's security at this time, I do share the same interest in knowing details about any accounts - root or otherwise - that may exist on our Sonos devices, and how they are protected.

Since Sonos devices are running some form of Linux OS, and usually have broad access to the internet available to them, they would be prime candidates for being used to launch DDoS attacks just as internet connected cameras and DVRs are. Yes, they may not be as easy to access as internet-accessible devices are, since they don't usually have port forwards and/or firewall rules allowing them to be accessed from the internet. But as Captain mentions, if malware finds its way onto your network through other means, it doesn't matter if it can be accessed from the internet as it can just be accessed from the local network!
The S in IOT stands for Security.
CaptainLeonidas_Sonos
Contributor I
November 4, 2016
MikeV,

I have PMed Ryan S. What you wrote was one of my statements too (and a bit more).
I will not go into details of what I wrote though. If additionel info is made available I will leave it up to him to state this.
Security is mainly found in a correct mindset and policies applied.
CaptainLeonidas_Sonos
Contributor I
November 8, 2016
I stil do not see any reply by Ryan S.

I do wonder: does the hidden reboot work on Sonos system I can find on the internet direct (aka I can window shop stuff like topology hidden page etc)?

If so one could have them reboot continously.
Would be like this article: http://metropolitan.fi/entry/ddos-attack-halts-heating-in-finland-amidst-winter only now the user has a Sonos that keep rebooting itself.
Security is mainly found in a correct mindset and policies applied.
ratty
November 8, 2016
I do wonder: does the hidden reboot work on Sonos system I can find on the internet direct (aka I can window shop stuff like topology hidden page etc)?

If so one could have them reboot continously.

http://IP:1400/reboot works but, again, one would require access to the local subnet. If you're sufficiently paranoid, put Sonos on its own subnet -- along with trusted control devices -- and your IoT toys in their own subnet sandbox.
jgatie
November 8, 2016
I stil do not see any reply by Ryan S.

I do wonder: does the hidden reboot work on Sonos system I can find on the internet direct (aka I can window shop stuff like topology hidden page etc)?

If so one could have them reboot continously.
Would be like this article: http://metropolitan.fi/entry/ddos-attack-halts-heating-in-finland-amidst-winter only now the user has a Sonos that keep rebooting itself.


Once again, if people have access to your local LAN, it is your fault, not Sonos'. It's pretty silly to worry about the lock on the broom closet if you are leaving your front door wide open.