Skip to main content
CaptainLeonidas_Sonos
Contributor I
November 1, 2016

When will Sonos put additional security measures in place?

  • November 1, 2016
  • 74 replies
  • 5195 views
Today a read an article (https://www.ncsc.nl/actueel/nieuwsberichten/iot-botnets-veroorzakers-nieuwste-ddos-aanvallen.html for those able to read dutch) in which the dutch Nationaal Cyber Security Center (NCSC) is taken steps to track down security issue's of home used Internet of things devices.
So my question is wether Sonos will step up to the plate.

Far as I know the only counter-measure in getting access to any Sonos product is the locally used WiFi SSID-name / password.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

74 replies

jgatie
December 12, 2016
As I thought, he's posting here to be a complete pain in the butt. Time for an ignore feature, for both users and threads. Too bad InSided is so bad.
Airgetlam
December 12, 2016
+1 for an ignore feature.
Bruce
CaptainLeonidas_Sonos
Contributor I
December 13, 2016
As I thought, he's posting here to be a complete pain in the butt. Time for an ignore feature, for both users and threads. Too bad InSider is so bad.

I would love a feature for ignoring certain posters. It would be a good suggestion and you have my vote for having it added to the forum as an added feature as soon as possible.

Frankly though IF I were Sonos I would not implement it unless it is an already free feature which was part of the forumpackage but one that had not been tagged yet for functionality. Remember anything not free is an impact on profits made.
A commercial company will most likely only support services when they do not come at a negative cost in general.

I again IF I were Sonos would just advice posters in general to ignore unwanted threads and just not post in those threads. Even more so if you would want to ignore the poster in question. I also would ask the moderators to step in if threads go south.

Up till now I have made concerns I have public which I believe should be improved.
I also asked about their future plans on supporting their hardware/firmware/software.
Security is mainly found in a correct mindset and policies applied.
jgatie
December 13, 2016
I think everyone is quite aware of your self-styled purpose here. Trust me, there's no need to clarify.
airforceteacher
Headliner I
December 19, 2016
They're not especially accurate either. The ports mentioned are not open, for TCP at least. And UDP port scans are notorious for yielding false positives.

Besides, why are we even discussing it? These are ports on a private network.


Speaking as a security professional, private networks are not a security failsafe, they are merely a layer. There's a reason why most successful attacks nowadays are against clients - because we've spent many years hammering at firewalls, routers, IDSs and WAFs, and consequently most of the easy attacks from the outside have been found and accounted for. Attackers have moved to the softer, weaker, client machines, especially residential and consumer systems, because these are often less protected.

If your browser is susceptible to cross-site scripting, it's entirely possible for you to browse a site, download a script that runs in your browser to attack internal systems from a trusted internal network. This attack is not a theory or PoC, it's been effectively used in the real world already to modify routers to allow remote WAN access to the management pages, so it could certainly be used to access SONOS devices' internally accessible ports.

So, say it works - I shoot you a script, you view it your browser and it connects to your player's reboot URL and reboots your speaker. Hmm, cool, DoS! But just getting access to the page means I can try sending other things - buffer overflows, format string attacks, etc. Maybe right now all I've got is an annoying DoS - can I create something else?

Now, OTOH, also speaking as a security professional: security for anything, cyber, personnel, physical, is a risk management exercise. What could happen, what is the likelihood, what is the potential impact? Am I a target of opportunity (commodity) or a specific person of value? If I'm just a normal home user (or device commonly used at home), there are likely many, many, many more devices that are less secure and easier to craft an exploit for than SONOS. In that case, SONOS doesn't have to outrun the bear, just every other IoT device. If I'm a specific entity of value to a certain attacker, then I have to up my game, so to speak. So, for the average SONOS users, how high is their risk - pretty low in my estimation. But SONOS in a corporate environment? I wouldn't connect it to the same LAN as my database server or credit card readers, KWIM?

/ now feel like going home today and experimenting with the various pages and ports and XSS
CaptainLeonidas_Sonos
Contributor I
December 22, 2016
As mentioned earlier in this thread I was able to download the *.upd file without any issue's from Sonos update server (global server?) ... over http. I just had to read out the info already available within the "Status-pages".
Think I did read an article a bit back where Microsoft was told to to up their update policies by making sure their updates should only be available over https.

Guess Sonos might want to follow if their want to be a "responsible" manufacture.
(Granted Sonos is no Microsoft but still.)

Time will tell?
Security is mainly found in a correct mindset and policies applied.
inopinatus
Prominent Collaborator I
December 27, 2016
[quote=jgatie]You would have to duplicate the entire functionality of the Sonos firmware, add in your own mic monitoring functions, break into the individual Sonos units in the home (or substitute your firmware for the version at the Sonos servers, highly unlikely), somehow initiate an update of your own firmware, then you would be able to access the microphones. Compare this with simply breaking into laptop via telnet/ftp and loading a background app and you see why a hacker is going to pick an easier target.

This is a typical head-in-the-sand fallacy. "I can't imagine how it would be easy, so it must be hard and/or unlikely". Guess what though, all hackers love a challenge.

But they wouldn't even have to reimplement the firmware, just hijack it, and then package the hijack as a product for sale to security agencies and/or hacking teams. There are clusters of firms specialising in this stuff, it's a big industry.

Bear in mind, Sonos use off-the-shelf integrated circuits for many components; the underlying OS is clearly a Linux derivative and they won't be reinventing the kernel drivers except possibly for special-sauce elements like their DSPs.

This isn't rocket science, it's just computer programming, and there are hundreds of thousands of people already capable of what you described. For some of them, developing and selling pre-packaged hacking tools is simply the day job.
uncooked meat prior to state vector collapse
CaptainLeonidas_Sonos
Contributor I
January 3, 2018
Well, in the end Sonos is mentioned in this very article basically confirming my findings/concerns.

http://blog.trendmicro.com/trendlabs-security-intelligence/iot-devices-need-better-builtin-security/

Good job, Sonos.
Security is mainly found in a correct mindset and policies applied.
Stanley_4
Grand Maestro
January 3, 2018
Making a personal Sonos clone might be a fun project and I can see several ways to go there.

Making a commercial Sonos clone, I believe is not just an engineering issue but also a patent law problem.
MikeV
January 3, 2018
Well, in the end Sonos is mentioned in this very article basically confirming my findings/concerns.

Good job, Sonos.

That article is mistaking a tiny number of Sonos users (around 5,000 worldwide, out of millions of Sonos customers) who have horribly misconfigured networks for a security issue of the device manufacturer. These are people that are either forwarding a port on their router to one or more of their Sonos devices, or have firewall rules that are allowing traffic from the internet directly into their network, with the result being that the Sonos device is able to be accessed from the internet.

Sonos' resulting software update has removed lots of technical and otherwise useful information that advanced Sonos users relied on for information about their systems because a small fraction of users screwed up and left their devices accessible to the internet.

Maybe there's something Sonos could do to prevent devices that aren't connected to the local network from being able to control the speakers... but now you're making changes that are affecting legitimate users who maintain multiple networks and want to be able to control their Sonos devices on one network from their phone or computer on another network.
The S in IOT stands for Security.