Skip to main content

Public petition bring back support of SMBv1 - show your support

  • 26 July 2024
  • 2 replies
  • 55 views

This is the email I’ve sent to the CEO in response to his message from yesterday - please show your support if you agree.

 


 

Dear Mr Spence,

Thank you for this email and public acknowledgment of the incredible challenges SONOS have caused to their loyal customers who usually have several of your products at home. I appreciate the efforts your company is undertaking to fix all the bugs as quickly as possible, nevertheless there is one point that I believe does not receive sufficient attention i.e. your decision to block support for local libraries over SMBv1.

Indeed, it might not be the latest standard and it has some vulnerabilities, but in isolated environments like local home networks of majority of your customers these vulnerabilities do not pose material threat because a) there is no access to internal network from outside and b) the only content that would get potentially compromised is the music library, so really nothing confidential.

My case is as follows - I have my local Sonos library on USB stick connected to the modem provided by my home internet provider. The modems they deliver supports file sharing only over SMBv1 protocol. I checked with them and they confirmed they do not plan to update it in any near future considering it safe enough for local home network.

Therefore I find your decision irrational as it’s forcing me to add additional sophisticated NAS type devices to my network that support more recent SMB protocols, that I don’t really need, not to mention it’s an additional expense on my side.

The best solution would be to bring back support for SMBv1, but keep alerting the user about the vulnerabilities of that protocol and let him/her decide whether residual risk specific to their particular setup is acceptable for them of not.  

I look forward to your consideration of this request.

Best regards

Michael

 

2 replies

If this is a petition,  i do not support it.  
 

Why don’t you petition your ISP to provide more secure and more up-to-date hardware that supports modern protocols ?  This is your ISP’s failing, not a Sonos failing.   Thinking an insecure protocol like SMBv1 is ‘good enough’ is not good enough. 

Userlevel 7
Badge +18

Hi @Michal K. 

Thank you - I've marked this thread as a feature request and it will be seen by the relevant teams for consideration. Keep the ideas coming!

Reply