Skip to main content
Contributor I
May 14, 2017
Answered

Support for SMB v2 or v3

  • May 14, 2017
  • 108 replies
  • 23234 views
With all the recent reports and issues with the WannaCry ransomware I wanted to restrict use of SMB v1 on my home network. My NAS blocks this to the outside world but I wanted to secure things internally as well. I can configure the NAS to not support SMB v1 but this then prevents the Sonos controller app from seeing the share. When will Sonos support later versions of SMB? I had seen another thread on this somewhere and it sounded like it wasn't going anywhere. Is it possible to get an update on this please.
    This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.
    Best answer by Phil.Coleman
    The problem is that as long as companies produce products that rely on old out of date software other companies have to continue to support them to remain relevant in the market, it's a vicious cycle.

    108 replies

    Enthusiast II
    June 4, 2017
    Sonos has made zero commitment in these forums regarding this feature request, one that is allegedly 3 years old.

    I have no way of verifying whether it's been three years or not but Microsoft has been pretty vocal about dropping SMB1 and NTLM v1 in particular for several years now. Presumably, the folk at Sonos who do the network stack development are aware said stance and the potential consequences of not offering SMB2 support.

    Requiring customers to dumb down the security of their servers to use a product doesn't seem particularly helpful. No server I'm aware of allows customers to selectively enable/disable SMB1 on a per share basis, but I'm happy to be wrong. At least for FreeNAS, it seems to be an all or nothing thing. Forums for Synoloy, QNAP, etc. also document how to revert a server to SMB1 after server software upgrades disable SMB1 support by default.

    I'm not advocating for Sonos to abandon SMB1 and only use SMB2+, as that might impact their users negatively. But giving users the option of using SMB2+ would be great. There was a time when feature requests could be reviewed/logged at ask.sonos.com. Any idea what happened to that since you seem to know so much about the company and its policies?
    June 4, 2017
    There was a time when feature requests could be reviewed/logged at ask.sonos.com. Any idea what happened to that
    I believe it was discontinued because it gave Sonos information overload.
    jgatie
    June 4, 2017
    Sonos makes zero commitment to 99% of the requests on this forum, then they will show up on a release, sometimes years later. Once again, you have no information on what Sonos is or is not working on, and therefore shouldn't be making definitive statements.
    Enthusiast II
    June 4, 2017
    Let's recap: 1) there is a known security risk that the original developer alerted the industry to years ago. 2) Users have allegedly asked Sonos about upgrading the SMB stack for several years now 3) Sonos has made no commitment to fix a known security risk for which there multiple known solutions. You might find this behavior acceptable in your relentless defense of the company, I'm simply puzzled by it.

    To me, requiring customers to dumb down their server security carries enormous reputation risk if something does go wrong and many customers are affected by an exploit. I recognize that users are responsible for their own server settings and have to live with whatever security decisions they made but it would be great if Sonos made a commitment to be part of the solution rather than a potential enabler for the problems associated with SMB1 security.
    jgatie
    June 4, 2017
    You forgot to add:

    1b) Sonos makes no true commitment on 99% of the requests here, and AndyB from Sonos specifically stated in another thread that this issue has not gone unheard and options are being explored at this time:

    Hi th3bigguy - I don't have an update to provide at this time on when we'll be moving away from using SMBv1 for music library sharing. Our customers concerns around the vulnerability of SMBv1 have not gone unheard and we are exploring alternate options. When I do have a bit more to share, I'll come back and update this thread.


    https://en.community.sonos.com/troubleshooting-228999/sonos-smb-implementation-error-900-when-adding-music-library-6765736/index1.html

    Kinda throws a wrench in your little narrative, eh?
    Enthusiast II
    June 4, 2017
    Not particularly. Awareness != commitment to fix the issue. They can explore an issue all day and do nothing about it. Cheerleading will not make the issue go away.
    jgatie
    June 4, 2017
    Yeah, i figured you'd say that. Doesn't change the fact your narrative is nonsense when conronted with the fact they acknowledged the problem and stated they are looking into options. That response alone is more indicative of their intentions than 99% of every other response, which usually says "we will pass this on to the engineers."

    And as an engineer, cheerleading may not help, but obsessed posters who exaggerate the threat and constantly harp on one thing are a definite negative, resulting in placating rather than taking action, and are the very reason the phrase "fire the customer" was invented.
    Enthusiast II
    June 4, 2017
    ... posted by someone with 13000+ posts. LOL. I guess it's OK to be obsessive as long as one only takes the side of the company, eh? 😃

    I'll be happy to pull out my pom-poms and cheerleading uniform when Sonos delivers the goods, not sooner. 🆒
    jgatie
    June 5, 2017
    ... posted by someone with 13000+ posts. LOL. I guess it's OK to be obsessive as long as one only takes the side of the company, eh? 😃

    I'll be happy to pull out my pom-poms and cheerleading uniform when Sonos delivers the goods, not sooner. 🆒


    And there it is, the personal attack.

    For your info, I've been posting for 9 years. That's less than 4 posts a day, the majority of which are helping people. But hey, attacking the messenger instead of the message is always an effective way to argue. :8
    Trending Lyricist I
    June 16, 2017
    OK I understand that Sonos has sadly become one of those companies that will only make changes if it brings in revenue, and hence why they have not bothered to enhance their code to support SMB2.

    However, will a computer hosting *local files* with SMBv1 disabled (as Windows disables SMBv1 by default as it is so exploitable) be totally unusable by Sonos devices? i.e. When I try to add local folders on that machine to my library and it continually fails with the "not responding" message.