Skip to main content
CaptainLeonidas_Sonos
Contributor I
November 1, 2016

When will Sonos put additional security measures in place?

  • November 1, 2016
  • 74 replies
  • 5195 views
Today a read an article (https://www.ncsc.nl/actueel/nieuwsberichten/iot-botnets-veroorzakers-nieuwste-ddos-aanvallen.html for those able to read dutch) in which the dutch Nationaal Cyber Security Center (NCSC) is taken steps to track down security issue's of home used Internet of things devices.
So my question is wether Sonos will step up to the plate.

Far as I know the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

74 replies

CaptainLeonidas_Sonos
Contributor I
December 7, 2016
Well, Sonos Controller version 7 is out and still the Play:1 Linux v2.6.35 driven Sonos is not updated.

Still able to read out info I should not have to know, open and clearly readable if you know how to find it.
(Why should I be able to readout all WiFi networks near the device with name and security-protocol used. Same for devices used on the Sonos device like phones, tables etc.)
Still not sure why this Sonos needs to have unsecured SMTP, NNTP, POP3 and IMAP ports open, A simple portscan on the device seems to point that out.

The additional feature of Spotify is not even so much impressive.
Would have been more impressed if indeed some additional security had been added.

I also have not seen Sonos on the Z-Wave listing of IoT's with "higher" standards. Is Sonos even considering this?
Security is mainly found in a correct mindset and policies applied.
CaptainLeonidas_Sonos
Contributor I
December 12, 2016
Questions one might want to ask Sonos (like the ones posted by the Internet Storm Center, see URL below) .
https://isc.sans.edu/forums/diary/5+Questions+to+Ask+your+IoT+Vendors+But+Do+Not+Expect+an+Answer/21807/

What can or should we expect?
Security is mainly found in a correct mindset and policies applied.
Stuart_W
World-Class Superstar
December 12, 2016
Questions one might want to ask Sonos (like the ones posted by the Internet Storm Center, see URL below) .
https://isc.sans.edu/forums/diary/5+Questions+to+Ask+your+IoT+Vendors+But+Do+Not+Expect+an+Answer/21807/

What can or should we expect?


I think we can expect no public response from Sonos beyond what we already have and frankly I don't see why we should expect a response. As has been mentioned in this thread there is only a concern if somebody has access to your LAN and if they have that then access to your Sonos devices would surely be very low on your priority list.
Arc + Sub (Gen 1) + 2 x Play 1/ Stereo Play 3s/ Era 100 Stereo in Kitchen, One Stereo in Bedroom, Play 1 stereo pair in Study, Play 1in Bathroom, Sonos Move 2
jgatie
December 12, 2016
What I want to know is why, after repeated requests by Sonos and others to discuss this matter via PM, there are still continuous public posts from the very person who was asked to take it to PM?
ratty
December 12, 2016
They're not especially accurate either. The ports mentioned are not open, for TCP at least. And UDP port scans are notorious for yielding false positives.

Besides, why are we even discussing it? These are ports on a private network.
MikeV
December 12, 2016
The issue they're mentioning is that there are (apparently) thousands of Sonos devices that are visible to the world, rather than being behind a properly configured router/firewall. What would be good for Sonos would be to use Shodan to find those devices, then proactively contact the owners of them and get them properly secured behind a router/firewall, with no port forwards to the Sonos device(s).

On a different note... the fact that Sonos can be rebooted via an unauthenticated URL could be seen as a DoS in some ways. Arris recently ran into the same issue with some of their modems earlier this year (actually it was known about for a while, and had even been raised as an issue in the past; it just got more press this time which caused them to react), which allowed a website to have an image reference to the modem's reboot URL, thus disconnecting the user from their internet service while the modem reboots.

Obviously that IS a DoS, since you're being disconnected from your ISP as a result. Sonos may not be key to your home's internet access, but nonetheless it would be annoying if I were listening to music or watching TV and my Sonos device rebooted for no reason while browsing the web. Arris' fix was to remove the ability to reboot via the modem's web interface once the modem is up and running, though many say they should've added some security to their web interface instead.
The S in IOT stands for Security.
CaptainLeonidas_Sonos
Contributor I
December 12, 2016
What I want to know is why, after repeated requests by Sonos and others to discuss this matter via PM, there are still continuous public posts from the very person who was asked to take it to PM?

I will not elaborate on the PM's I was given but I will say this. I was disappointing at best.
The PM's I got had a high amount of words but little in the form of answers or insurances Sonos is indeed willing to improve itself on what I commited to this forum once again.

Forums are by far the best place to make suggestions as these will most likely not make an impact on the button line and profit of any commercial company. Same for getting quick answers to common user solvable issue's.

Anything else needs to have a certain "demand"-like ring to it. Improving acts like solving security related issue's or concerns are profit-consuming and hence unwanted.
Any good moderator will first act upon this by suggesting PM's. Another is have the issue bleed out and die silently by not responding to inquires.

Only when people become aware of issue's (via a forum like this one) and act upon it with greater numbers a company becomes aware it might need to change policy to keep the costumer happy.

So let me ask this then as I am a reasonable person:
1 - For how long, after I purchase a device, should I expect security updates? Aka the Sonos Play:1 device OS (not referring to the controller software) has till when support? I have not found an answer to that so please feel free to point me in the right direction.

2 - How will I learn about security updates? Sonos Controller itself will give us a notification so no issue there. Also I was informed of the update to version v7 via mail. However I lacked the mail about improved actions of the Sonos device OS itself.

3 - Can you share a pentest report for your device? I have not seen any and I am fairy certain I will never get one. Also I have not seen any indicators where Sonos is willing to join Z-Wave or any other IoT security aware organisation.

4 - How can I report vulnerabilities? I was suggested via PM's. Guess this will have to do.

5 - If you use encryption, then disclose what algorithms you use and how it is implemented? I have yet to find out if indeed this will be disclosed or mentioned anywhere.

34.7-35162-1-8.upd is the latest upd-file available for the device I have.
I would love to know what was improved via this upd file.
Security is mainly found in a correct mindset and policies applied.
Chris
Lead Maestro
December 12, 2016
Well then I guess you just keep asking the questions here then and get no response from Sonos.
Respect the Queue (2)Move (3)Beam (1) Era100 (2)ARC (1)SonosOne (1)Playbar (4)Play5 (4)Play1 (3)Play3 (1)Port (2)Connect (1) Roam (2) Ace (1)Connect:Amp (4)Sonos Amp (1)Sub + (9) Echo + Smartthings; (2)Play)
CaptainLeonidas_Sonos
Contributor I
December 12, 2016
Well then I guess you just keep asking the questions here then and get no response from Sonos.
That's up to Sonos.
Security is mainly found in a correct mindset and policies applied.
ratty
December 12, 2016
34.7-35162-1-8.upd is the latest upd-file available for the device I have.
I would love to know what was improved via this upd file.

http://www.sonos.com/software/release/7-0