Skip to main content
Trending Lyricist I
August 12, 2018

Speaker password feature needed ASAP!

  • August 12, 2018
  • 85 replies
  • 3004 views
Sonos please task one of your engineers with adding a password option to the Sonos system just like Apple has done with their Homepods!

Airplay2 is a game changer when it comes to an open system like Sonos because any device with Airplay2 capability can take control of a sonos system without intentionally installing the Sonos app. While this is convenient on some networks it is a royal pain in the arse for others.

Take my home network as an example. I have two wireless networks - one for the family and one for guests. The guest network has no access to Sonos which is great. But everyone on the family network can control any speaker in the Sonos system because there is no way to secure them. Unfortunately I can't put them on a separate subnet due to the shared media and backup servers. Sure, I ask them not to connect to certain speaker and groups, but they don't see the harm in having the house filled with their cool tunes while I'm at work. Can't really blame them but it causes problems with the neighbors and even me (sucks to ask Alexa to play CNN on a speaker and have it blaring close to full volume because someone forgot to turn it down).

BTW, this wasn't much of a problem before the Airplay2 update because none of the kids had the Sonos app installed on their devices but now they connect without a 2nd thought.

Please give us the option to protect speakers and groups of speakers.
This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

85 replies

TreeGuyAuthor
Trending Lyricist I
August 16, 2018
All you would need to do is gain access to your network and sign on your app and you would have almost full control over the Sonos devices.
What app are you referring to here?
TreeGuyAuthor
Trending Lyricist I
August 16, 2018
Gosh the paranoia is still growing here for one or two.

My home is well protected and locked, but I will never see the point in putting a padlock on my bedroom door that I would then have to open/close everytime I entered/exited that part of the premises. There’s nothing in the bedroom anyway, the good stuff is all in the secure safe downstairs.

I don’t see the point in padlocking the bedroom door at all, as that does absolutely nothing to help keep my safe secure, even if the thief can get into the house in the first place.

And there is the analogy for me.


If you locked your doors and windows then your home may be reasonably secure but as soon as you unlock a window or door that changes. Your network is similar. Even though you may have your router/firewall secured (and there is probably no such thing as a secure router/firewall), the moment one of your devices connects to and receives information from the internet you have opened the door for hackers. By design a home or business network that connects to the internet cannot be locked up tight like a house.

If you want a secure net that is not subject to attack from the outside the only option is to create an air-gapped network. I've been a software developer for 40 years and we've worked on these types of nets from time to time. It is a pain in the rear but it does solve much of the security issue.
jgatie
August 17, 2018
All you would need to do is gain access to your network and sign on your app and you would have almost full control over the Sonos devices.
What app are you referring to here?


You can control Sonos devices directly from the Spotify app, the Pandora app, or Alexa, sometimes even when not on the same subnet. Hence Sonos requires you to authenticate both your Sonos account and your Spotify, Pandora and/or Alexa account before it allows this linking of functionality. If Sonos thought there was any danger of someone being able to control Sonos from outside the network via any other means, they most certainly would require authentication.

But they don't.
TreeGuyAuthor
Trending Lyricist I
August 17, 2018
You can control Sonos devices directly from the Spotify app, the Pandora app, or Alexa, sometimes even when not on the same subnet. Hence Sonos requires you to authenticate both your Sonos account and your Spotify, Pandora and/or Alexa account before it allows this functionality.
Got it, that is a different attack vector and not part of this discussion.

If Sonos thought there was any danger of someone being able to control Sonos from outside the network via any other means, they most certainly would require authentication.

But they don't.

I don't know what Sonos thinks but we aren't really discussing controlling Sonos devices from outside the network (e.g. control from a different subnet) here because the control comes from a compromised device inside a breached network. The point of this thread is that networks are inherently insecure. Therefore hackers can (and do) gain remote access to local devices on what people believe are secure networks. This is an disputable fact.
jgatie
August 17, 2018
Since when are you the arbiter of what is and isn't part of the discussion? Quit dismissing scenarios because they don't fit your narrative.

And I'm still waiting for you to describe one example, just one, of how someone can gain control of your Sonos devices that would be thwarted by an app level password.

Just one. Give me one. No dodging. No links. Give us details. I've actually given you one that they have plugged. Now you give me one they haven't. Heck, we all know your original request needs more diversions.
TreeGuyAuthor
Trending Lyricist I
August 17, 2018
Since when are you the arbiter of what is andisn't part of the discussion? Quit dismissing scenarios because they don't fit your narrative.

I'm dismissing it because it is irrelevant to this discussion as Sonos has already addressed the authentication issue related to it.

And I'm still waiting for you to describe one way, just one, of how someone can gain control of your Sonos devices that would be thwarted by an app level passwod.
The ability to control Sonos would be greatly diminished if those controls required authentication before activation.

Just one. Give me one. No dodging. No links. Give us details.
The last link I provided gives excellent examples. As a software developer I can conceive of others but I'm certainly not going to post them on the web.
chicks
August 17, 2018

Just one. Give me one. No dodging. No links. Give us details.
The last link I provided gives excellent examples. As a software developer I can conceive of others but I'm certainly not going to post them on the web.


Still can't find one single example, I see. Give it up. Your security issues have absolutely nothing to do with your original request.
TreeGuyAuthor
Trending Lyricist I
August 17, 2018
Still can't find one single example, I see. Give it up.
I already provided links to examples.

Your security issues have absolutely nothing to do with your original request.
Never said they did. However, if Sonos devices had the option for authentication this thread wouldn't exist.
Ken_Griffiths
August 17, 2018
If I did leave a window or door open, to my network, the worst thing for me is, that the thief may eventually find the location of the safe. Let’s just say that the safe in this instance is a 'crude' encrypted hidden drive partition that uses 3rd party encryption software, which perhaps has a 16 digit key that is not written down, or stored on the network. It really doesn’t matter if the client application that provides access to the partition is stored locally, or stored on a USB stick. I don’t use this method anymore by the way, but I used to, back in the mid-late 1990’s.

What I really don’t see now, is how password protecting my sonos system, or application, would now make the slightest bit of difference to the thief that has already got this far onto the network. Who really is going to leave important stuff lying around unprotected and even, if they do, why on earth would the thief head for the Sonos system application, when there are probably thousands of other applications that the thief could use or bring with him through the open window or doorway.

I still remain baffled by the argument here, it’s really seems quite irrelevant to the original post in this thread, which was more about stopping the kids using the Sonos application, by installing a password, which I’m sure the kids will probably eventually discover anyway, just by looking over your shoulder.

I still think chicks was right when he said this was more of a discipline matter, rather than a security issue.
TreeGuyAuthor
Trending Lyricist I
August 17, 2018
What I really don’t see now, is how password protecting my sonos system, or application, would now make the slightest bit of difference to the thief that has already got this far onto the network.

There are something like 20 million Sonos devices in the wild and they are part of the IoT universe which is under constant attack. Why would you or anyone else have a problem with protecting those devices with an optional authentication feature?