Skip to main content
Enthusiast I
June 14, 2019

SMB2 (or SMB3) support must be supported NOW!

  • June 14, 2019
  • 281 replies
  • 30268 views
We are writing summer 2019 and still Sonos only supports SMB version 1 for the Music Library share.

This is not acceptable.

A file share running SMB1 is extremely vulnerable to all the variants of cryptolocker virus that exists today. File share servers (NAS, Windows, Apple OS) can only support one version of SMB - so you cannot from the same box have one file share (for Sonos) using SMB1 and the other file shares using SMB2 or SMB3. This way Sonos puts each and every file share at serious risc - just because they don’t update their file share protocol to comply with this century.

And for the record - the “solution” through PLEX is not a solution. Unstable at best.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

281 replies

Airgetlam
January 13, 2021

@Simmo1969 has already posted a solution in this thread. 

Synology, to my knowledge, maintains no official presence in these Sonos forums. You may be better off contacting their CS directly, as posting your unhappiness here likely has no impact on them (although will hopefully stoke the fires for Sonos, but we’ll have to see).

Bruce
Lyricist I
January 13, 2021

@Simmo1969 has already posted a solution in this thread. 

Synology, to my knowledge, maintains no official presence in these Sonos forums. You may be better off contacting their CS directly, as posting your unhappiness here likely has no impact on them (although will hopefully stoke the fires for Sonos, but we’ll have to see).

That solution didn’t work for me.

I did have the SMB service installed after DSM 7 upgrade and enabled SMB V1 - but still ended up with invalid username / password error message even though the share can be accessed with the same credentials from a Mac.

Airgetlam
January 13, 2021

The method by which the speakers reach the shared location is via SMB v1, the same can not be said for the controller running on your computer. With SMB v1 now active, I would recommend that you submit a system diagnostic, and call Sonos Support to discuss it, or post the diagnostic number here for a Community Moderator to pick up.

There may be information included in the diagnostic that will help Sonos pinpoint the issue and help you find a solution.

When you speak directly to the phone folks, there are more options available beyond just the diagnostic analysis. 

Bruce
Stanley_4
Grand Maestro
January 13, 2021

My suggestion of using a NAS to SMB v1 gateway keeps looking better and better.

Not saying the issue isn’t real, just that it is a minor aggravation, not a show stopper.

Lyricist I
January 20, 2021

I’ve not read all of it (and I won’t), but I read the sum up of page 6 of Stanley 4.
If not smb2/3 because of explained reasons then why not nfs? As far as I know NFS is smaller, less cpu intensive and more light weight than samba. (Samba/cifs comes from the windows side)
NFS is even linux nativ and most(good) NAS systems provide that as well.


I currently share my music via nfs to a virtual machine which is running nothing else than a samba server providing smbv1 as I don’t want that on my main server. And all that only for sonos.
I did spend some money on sonos, but I’m still missing a lot of devices across the house, I’m currently considering selling them and move to a different product if the situation does not improve.
After all, those devices are far away from cheap. One could expect that they spent some of that money in hardware that is more future proof than “that one kernel version that they build at day 1”.
I know many people that did not buy sonos just because of this situation here and they still laugh at me.

This is pure speculation but I could imagine that the real reason for them still running that same old kernel is because the’ve lost the one person building/maintaining it and now its a “black box” and nobody dares to touch it.

Airgetlam
January 20, 2021

I’d buy in to that pure speculation, if I hadn’t have been in similar situations in the past, where only one person on the team had specific knowledge, and when that team member left, it was a pretty quick decision to have not only a rewrite of the software done, but ensure it was properly annotated, and multiple people were able to maintain it. That has happened to me, exactly once, and will never again. 

My own speculation remains that there isn’t enough available memory in the S1 devices to implement a new, larger, and SMB v x>1 kernel. Which is why I have some hopes that the next version of Sonos S2 that isn’t just bug fixes, will include a new kernel. I have zero expectations that any S1 only device would get it, so those who are running S2 capable devices under S1 would not garner the benefit. 

Bruce
Lyricist I
January 21, 2021

Hi, I have not been able to read the entire thread, but I can see we are still talking about SMB2/3 support vs SMB1. I found all this while trying to set up a music library on a Raspberry PI.

 

About half of my job is pentesting and I think I’ll be mostly preaching to the choir here, but I could probably count on all of our fingers and toes how many Credit Unions and Banks my company has fully compromised due to the use of SMBv1 and/or lack of SMB Signing. (and maybe run out of hands and feet.)

 

SMB Signing could potentially solve the issue as well, however, I read a post explaining that SMB has been deprecated by Sonos in favor of HTTP, which still transmits in clear text, but it isnt the data we are protecting (music) it is the network authentication credentials and identities of computers/users but removing SMBv1 in favor of more secure authentication protocols.

 

The danger as I understand it would be an attacker’s ability to impersonate devices and initiate a Man-in-the-Middle attack. With SMB Signing required for Samba and Windows hosts alike (all compatible systems), the attacker would not be able to utilize this attack vector. Unfortunately, if the network in question had any hosts utilizing NTLMv1 and Broadcast Domain Services such as MDNS, NBT-NS, or LLMNR, an attacker may still be able to capture NTLM hashes, likely resulting in the compromise of the system or network utilizing those credentials.

 

All of this aside, I opened up Wireshark when I heard about the HTTP over SMBv1 situation, and I can confirm that using Sonos S1 with Gen 1 Play 5 and 2-Gen 1 Play 1’s that HTTP and HTTP/XML is in use, and I have yet to see an SMB packet while playing music from a local library on a Windows 10 machine.

 

So my question is, since HTTP is now in use over SMB of any kind, is the conversation about using SMBv2/3 even worth having? If so, could someone please explain this to me?

Stanley_4
Grand Maestro
January 22, 2021

Sonos only offers the HTTP option for Windows and Mac, not NAS devices.

Security flaws in SMB v1 aren’t very scary as long as the SB v1 device contains no sensitive information of any kind. Also for Sonos use there is no reason not to firewall the SMB server away from the Internet completely.

 

NFS might be an option but it would also require some additional storage and memory and the older Sonos have been having features removed, some of which appear to have been removed to open up memory for newer features. Sonos releases little so all is based on speculation, not facts but it sure looks like a low memory situation. 

 

I’ll stick to one of two options, a dedicated SMB v1 Sonos music server, my current option. Second a NAS (any supported Linux protocol) to SMB v1 Gateway. Neither of which require any sensitive data. The Gateway, if using WiFi and not Ethernet will need your WiFi password though.

Lyricist III
February 1, 2021

Sonos, this is ridiculous and thoroughly embarrassing.  You have a premium product for a premium price.  Stop acting like some cheap Chinese knockoff.  I suppose next you’re going to tell me only Internet Explorer and SSL 2.0 are supported on your website.

Airgetlam
February 1, 2021

That would indeed be odd, since both of those run on your local device or the server,and not on the limited memory of the Sonos equipment.

Bruce