Skip to main content
Trending Lyricist I
August 12, 2018

Speaker password feature needed ASAP!

  • August 12, 2018
  • 85 replies
  • 3004 views
Sonos please task one of your engineers with adding a password option to the Sonos system just like Apple has done with their Homepods!

Airplay2 is a game changer when it comes to an open system like Sonos because any device with Airplay2 capability can take control of a sonos system without intentionally installing the Sonos app. While this is convenient on some networks it is a royal pain in the arse for others.

Take my home network as an example. I have two wireless networks - one for the family and one for guests. The guest network has no access to Sonos which is great. But everyone on the family network can control any speaker in the Sonos system because there is no way to secure them. Unfortunately I can't put them on a separate subnet due to the shared media and backup servers. Sure, I ask them not to connect to certain speaker and groups, but they don't see the harm in having the house filled with their cool tunes while I'm at work. Can't really blame them but it causes problems with the neighbors and even me (sucks to ask Alexa to play CNN on a speaker and have it blaring close to full volume because someone forgot to turn it down).

BTW, this wasn't much of a problem before the Airplay2 update because none of the kids had the Sonos app installed on their devices but now they connect without a 2nd thought.

Please give us the option to protect speakers and groups of speakers.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

85 replies

TreeGuyAuthor
Trending Lyricist I
August 16, 2018
I worked on a Unix based POS system installed in hundreds of commercial properties once. We had dial-up support, and the system was protected by a randomized root password that changed at a variable time interval. Unless you had the PGP protected password generator installed on your support system and the private key, there was no way to log in, and no way to crack the root password before it switched.

There are always other methods to gain access to a system. Just because we aren't aware of them doesn't mean they don't exist. Although a dial up attack could be significantly more challenging than an attack on an internet connected device.

There are many different ways to poke a device for information. IMO, this article is just the tip of the iceberg.

https://securelist.com/iot-hack-how-to-break-a-smart-home-again/84092/
jgatie
August 16, 2018


There are always other methods to gain access to a system. Just because we aren't aware of them doesn't mean they don't exist. Although a dial up attack could be significantly more challenging than an attack on an internet connected device.

There are many different ways to poke a device for information. IMO, this article is just the tip of the iceberg.

https://securelist.com/iot-hack-how-to-break-a-smart-home-again/84092/


So that would be a "No" on my request for you to tell me exactly one way to log into a Sonos device?

Gotcha.

And the dial-up mention was superfluous. My main point is gaining root access to a device is not easy.

Also, still waiting on how passwords at the app level have anything to do with this security tangent, or how they will help secure the terribly unsecured Sonos devices.
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
My main point is gaining root access to a device is not easy.

Depends on the device. Some are easy, some are challenging, none are bullet proof.

Also, still waiting on how passwords at the app level have anything to do with this security tangent, or how they will help secure the terribly unsecured Sonos devices.

You are making the assumption that app level access is safe. It is not. Exploiting a bug or security weakness in an app to gain root access is a common attack vector. Because the Sonos device is unprotected at the API level that common attack vector readily available.
Enthusiast II
August 16, 2018
I’m a natural worrier about all sorts of things but to be honest I don’t see any to worry about with the security of the Sonos system 🙂 I personally would hate if I had to enter a password to use the system so if it ever come to fruition I’d hope it would be an option rather than compulsory.
airforceteacher
Headliner I
August 16, 2018
I’m a natural worrier about all sorts of things but to be honest I don’t see any to worry about with the security of the Sonos system 🙂 I personally would hate if I had to enter a password to use the system so if it ever come to fruition I’d hope it would be an option rather than compulsory.

I’m in agreement on this. Give the option, but make it something I can turn on and off depending upon my environment. Best bet would be that it requires authentication the first time an instance of the app connects, then remembers that, similar to the way Airplay works.
jgatie
August 16, 2018


You are making the assumption that app level access is safe. It is not. Exploiting a bug or security weakness in an app to gain root access is a common attack vector. Because the Sonos device is unprotected at the API level that common attack vector readily available.


How? The app cannot be used unless you are on the same subnet. And how are passwords in the app supposed to secure the API, assuming it is unsecure?
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
Give the option, but make it something I can turn on and off depending upon my environment. Best bet would be that it requires authentication the first time an instance of the app connects, then remembers that, similar to the way Airplay works.

As implemented on the Sonos Airplay doesn't require a password and I haven't found a way to give it a password.
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
How? The app cannot be used unless you are on the same subnet.

In the scenario presented above the hacker has gained asses to the network via one of the many exploits out there, therefore they have access to all unprotected devices on that network.
jgatie
August 16, 2018
How? The app cannot be used unless you are on the same subnet.

In the scenario presented above the hacker has gained asses to the network via one of the many exploits out there, therefore they have access to all unprotected devices on that network.


But the hacker is still not on the same subnet. Unless you are saying they have gained access to your device's controller app on your network? In that case, you are entering a password every time you enter the controller, an annoying scenario at best.

Look, you painted yourself in a corner here. You tried to piggy back on security, and are now talking silly scenarios to justify it. You want passwords for your kids, a legitimate request, but one which has nothing to do with network security. End it there.
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
But the hacker is still not on the same subnet.

If they have gained access to the network where the Sonos devices reside then they can poke, prod, control and attempt to hack those devices. That is an indisputable fact. How they gained access to the net and what devices they are using to attack the Sonos devices is not important.

Perhaps this article will help: https://blog.sucuri.net/2014/11/most-common-attacks-affecting-todays-websites.html