Skip to main content
Trending Lyricist I
August 12, 2018

Speaker password feature needed ASAP!

  • August 12, 2018
  • 85 replies
  • 3004 views
Sonos please task one of your engineers with adding a password option to the Sonos system just like Apple has done with their Homepods!

Airplay2 is a game changer when it comes to an open system like Sonos because any device with Airplay2 capability can take control of a sonos system without intentionally installing the Sonos app. While this is convenient on some networks it is a royal pain in the arse for others.

Take my home network as an example. I have two wireless networks - one for the family and one for guests. The guest network has no access to Sonos which is great. But everyone on the family network can control any speaker in the Sonos system because there is no way to secure them. Unfortunately I can't put them on a separate subnet due to the shared media and backup servers. Sure, I ask them not to connect to certain speaker and groups, but they don't see the harm in having the house filled with their cool tunes while I'm at work. Can't really blame them but it causes problems with the neighbors and even me (sucks to ask Alexa to play CNN on a speaker and have it blaring close to full volume because someone forgot to turn it down).

BTW, this wasn't much of a problem before the Airplay2 update because none of the kids had the Sonos app installed on their devices but now they connect without a 2nd thought.

Please give us the option to protect speakers and groups of speakers.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

85 replies

airforceteacher
Headliner I
August 16, 2018

You keep on saying open port 1400 to the outside world, and are missing the fact that the bulk of exploitation nowadays doesn’t work that way. Cross site scripting, infected documents, phishing messages and other client side exploits are the rule rather than the exception these days. If a malicious actor infects a legitimate site you connect to, say this one, and your browser downloads JavaScript, it could be used to access internal systems. OP is presenting a legitimate, verified and documented real world attack, and you keep dismissing him with the port 1400 argument.


None of which has anything whatsoever to do with Sonos app or hardware, lol.


Lol - yes it does. Anything installed on a modern network should be designed to protect itself against internal and external issues. That’s a basic standard of security today, and I agree with OP that Sonos should provide that capability to require authentication locally. Make it an option, so those who want it can turn it on, but leave it off for others.

However, security is primarily about risk management, and the risk of some attacker randomly choosing you to attack and then choosing your Sonos speaker instead of a poorly configured windows, Mac or android device in your network is quite low. Sonos probably does not have high enough market penetration to make that a major risk for home users. I would not allow Sonos on my main network in a workplace - it would be on a protected vlan that required authentication to access, and limit control of the speakers to authorized parties. And would still have some concerns.
chicks
August 16, 2018


Lol - yes it does. Anything installed on a modern network should be designed to protect itself against internal and external issues. That’s a basic standard of security today, and I agree with OP that Sonos should provide that capability to require authentication locally. Make it an option, so those who want it can turn it on, but leave it off for others.


Sigh. These exploits have nothing whatsoever to do with any Sonos vulnerability. The bad guys are entering your network via other gateways, not via Sonos. You’ve missed the entire point.

Besides, what attacker, once inside your network, is going to go after your Sonos speakers? What would be the point? He’s going to go through your email, your banking and investing software, looking for ways to get to your online accounts. Sonos speakers are the very last thing of interest, lol.
melvimbe
August 16, 2018

Lol - yes it does. Anything installed on a modern network should be designed to protect itself against internal and external issues. That’s a basic standard of security today, and I agree with OP that Sonos should provide that capability to require authentication locally. Make it an option, so those who want it can turn it on, but leave it off for others.


So your reasoning is based on the principle of the matter instead of an actual way that scripting, phishing, etc could infect a Sonos device?
Danny
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
Sigh. These exploits have nothing whatsoever to do with any Sonos vulnerability. The bad guys are entering your network via other gateways, not via Sonos. You’ve missed the entire point.
Those exploits are absolutely related to IoT security. Once inside your network hackers will attempt to gain access to any device on your network. Preventing that access is the point of device level authentication on IoT devices.

So your reasoning is based on the principle of the matter instead of an actual way that scripting, phishing, etc could infect a Sonos device?
Those exploits allow a hacker to gain access to your network. Once they are in your network they can gain access to any unprotected network resource such as Sonos devices.
jgatie
August 16, 2018
And just how is the nefarious hacker going to "access" your Sonos? He can't load the Sonos app, it is required to be on the same subnet. He could load his Spotify account and then control your Sonos via Spotify, except . . . Whoops! Sonos requires authentication for that. Well what if he decides to add his own Sonos device and then control through that, except . . . Whoops! Sonos requires authentication for that. Well, what if he gets into port 1400 from the outside and starts rebooting devices or anything else from the diagnostic menus except . . . Whoops! Sonos removed any nefarious items from the diagnostics.

So exactly what are they going to do, look at your Sonos devices? I imagine they could try to send UPnP messages to a unit to start it playing, but there isn't anything authentication at the app level is going to do about that.
Smilja
August 16, 2018
Those exploits allow a hacker to gain access to your network. Once they are in your network they can gain access to any unprotected network resource such as Sonos devices.
And what's the point of gaining access to a music system? Try and blackmail you because of your bad taste in music?
»And the world is like an apple whirling silently in space, Like the circles that you find in the windmills of your mind.« (›Windmills Of Your Mind‹ [1967]. Music by Michel Legrand ; English lyrics written by Alan & Marilyn Bergman)
chicks
August 16, 2018
Those exploits allow a hacker to gain access to your network. Once they are in your network they can gain access to any unprotected network resource such as Sonos devices.
And what's the point of gaining access to a music system? Try and blackmail you because of your bad taste in music?


Too funny!
jgatie
August 16, 2018

And what's the point of gaining access to a music system? Try and blackmail you because of your bad taste in music?


There is no point. The OP wants passwords to keep his kids from messing with the system. He piggybacked this request onto a "sky is falling" security scare, thinking it would lend more weight.
airforceteacher
Headliner I
August 16, 2018
Wow. There are any number of things that could be done, but apparently you guys don’t want to think about them. The Mirai botnet in November 2016 was made up of internet of things devices. Machines on your internal network are exposed when another system is infected.

However, as I said before, the risk is probably low. There are likely just not enough Sonos devices out there for someone to take the effort to find, say, a buffer overflow error, write an exploit, and use that to target other devices or create a backdoor. Home users aren’t a valuable enough target for that level of effort. However, in a professional engagement, if my reconnaissance showed the use of those speakers, I’d sure as heck have someone on my team look at Sonos for vulnerabilities to allow control over the device. My most likely goal would be to launch a reverse direction VPN server on the Sonos device to allow someone to connect to me and gain access to the internal network at will.

Back to the OPs original question: lots of people with families or visitors would probably like to have some control preventing access to the speakers from anyone with the appropriate app. It’s a good suggestion on its own merits.

Addendum: Not every suggestion should be refuted nastily as an attack on Sonos.
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
The brain of each Sonos device is a network connected computer. Not a good thing to leave unsecured because we can't be sure our networks are secure, in fact it is better to assume the network is not secure and therefore secure each device connected to the network.