Skip to main content
CaptainLeonidas_Sonos
Contributor I
November 1, 2016

When will Sonos put additional security measures in place?

  • November 1, 2016
  • 74 replies
  • 5195 views
Today a read an article (https://www.ncsc.nl/actueel/nieuwsberichten/iot-botnets-veroorzakers-nieuwste-ddos-aanvallen.html for those able to read dutch) in which the dutch Nationaal Cyber Security Center (NCSC) is taken steps to track down security issue's of home used Internet of things devices.
So my question is wether Sonos will step up to the plate.

Far as I know the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

74 replies

CaptainLeonidas_Sonos
Contributor I
November 8, 2016
With little effort I already found Sonos systems which willl most likely will reboot accessable on the internet. I therefore question the wisdom of having a webinterface available without a proper credential check In place.
Security is mainly found in a correct mindset and policies applied.
ratty
November 8, 2016
With little effort I already found Sonos systems which willl most likely will reboot accessable on the internet.
Because someone was daft enough to forward public ports to a local SonosIP:1400? Enough said.
jgatie
November 8, 2016
Believe me, there is a lot of questioning about wisdom going on.

CaptainLeonidas_Sonos, I'm going to be blunt because you don't seem to get the subtle message here: Ryan S suggested you take your tin-foil hat paranoia to PM for a reason, and it has nothing to do with the legitimacy of your concerns. Please take his suggestion to heart and spare the rest of us this nonsense.
CaptainLeonidas_Sonos
Contributor I
November 8, 2016
jgatie,
I believe any man/woman can speak for themselves.
So unless you are a telepathic gifted person you might want keep your remarks of what another might think to yourself.

Ratty,
People are daft at times. Then again not all users read through forums to figure out something they could not find in the owners manual.
I may be mistaken but the fact certain webpages are active on an out-of-thebox Sonos product including one to reboot it without some kind of confirmation might be worth a second thought during setup/configuration.
Security is mainly found in a correct mindset and policies applied.
jgatie
November 8, 2016
One does not have to be telepathic to read the posts wishing you would take this to PM:

Thank you, Ryan :)

^^Oh look, there's one now.
CaptainLeonidas_Sonos
Contributor I
November 8, 2016
One does not have to be telepathic to read the posts wishing you would take this to PM:

Thank you, Ryan :)

^^Oh look, there's one now.


Thank you for confirming you are not telepathic.
Security is mainly found in a correct mindset and policies applied.
ratty
November 8, 2016
People are daft at times. Then again not all users read through forums to figure out something they could not find in the owners manual.
I may be mistaken but the fact certain webpages are active on an out-of-thebox Sonos product including one to reboot it without some kind of confirmation might be worth a second thought during setup/configuration.

This is ridiculous. No-one is going to 'accidentally' create a forwarding rule in a home router to port 1400 on a specific IP, especially not for an arcane function that only the technically literate would know how to find on forum pages.

As for 'certain webpages [being] active on an out-of-the-box Sonos product' it might perhaps be an idea to get at least a passing understanding of how UPnP AV works.
CaptainLeonidas_Sonos
Contributor I
November 15, 2016
I did get an answer btw. Again I leave it to Ryan S to elaborate.

I will continue to monitor progress made in this regard.
Security is mainly found in a correct mindset and policies applied.
Lyricist I
December 4, 2016
Hello, I am concerned by security too, because is seems at this moment more than 3000 are opened to the internet (port 1400, cf. shodan.io).
It seems to me that is is a really huge number to have been manually configured to do so (with port translation on routers / DMZ).

And regardless of what can be found with this: phone names (like "John Doe's iPhone"), wifi access point name, even emails used for music services accounts..., it is a serious flaw it term of personal data security.

And also, we can do some mess by playing unwanted music at unwanted times, rebooting, changing parameters, participate in some kind of DDoS...

And it may also have some vulnerabilities in the differents components (API calls, mp3 decoder, ...) that may be used to turn sonos components into some botnet, so reducing the attack surface will improve this.


So in my opinion it is up to sonos to add some security layers (like at least authentication to their equipments), because most of their customers don't understand how networks works and even don't know anything about securing it.
Or maybe you can contact the customers to tell them to secure their installation (if you can use the customer ID to find their email).

I know that security it a real cost in term of effort/time/customer in-satisfaction (when they are too restricted)... but please don't ignore it.
"It's a long way to the top if you wanna Rock'n'Roll"
ratty
December 4, 2016
most of their customers don't understand how networks works and even don't know anything about securing it.
Yet we're to believe that, despite that ignorance, customers will deliberately configure port forwarding to 1400 on one or more of their Sonos devices, or even put a Sonos unit into their DMZ?