Jump to content

Caution: SONOS requires risky SMBv1 to access NAS


Recommended Posts

In case you have not read about the SMSBv1 security risk exploited by ransomware such as WannaCry, here is an article:

https://www.zdnet.com/article/windows-10-tip-stop-using-the-horribly-insecure-smbv1-protocol/

 

I have disabled SMBv1 on my Win10 laptops as well as my NAS.  BUT Sonos still requires it to access the music on NAS.   ? :angry2:? 

 

Not sure why Sonos cannot fix the problem in their Apps (and there are many posts in the Sonos forums).  I contacted Sonos support and their suggested workaround is to install and use Plex!  But doesn't this destroy the Sonos value proposition of plug and play ? :shocked:  

  • Like 2
Link to comment
Share on other sites



This issue has been around for quite some time but Sonos is putting their head in the sand!  They seem not to care that they are leaving open a vulnerability in the NAS. ?

 

In contrast, when I raised the issue with SOtM (SMS-200), they fixed the problem within a week.  ?

Link to comment
Share on other sites

 

It is things like this that make me feel so good that I only use physical media for music. Another plus is that I own the physical copy.

 

However, to the OP, I  wish you well and I hope this situation can be addressed to your satisfaction.

  • Like 2
Link to comment
Share on other sites



Quote

It's limitation that we aren't able to use SMB 2 or 3 on some of our older hardware. It's not as simple as just updating the SMB version. Otherwise we would have done it by now.

From Sonos support.  They know about it but choosing not to do anything because of older hardware !  ?  Meantime they leave their customer's NAS vulnerable.  Not sure why they cannot enable SMBv2 for hardware that supports it and leave older hardware on SMBv1 ???

Link to comment
Share on other sites

5 hours ago, Snoopy8 said:

From Sonos support.  They know about it but choosing not to do anything because of older hardware !  ?  Meantime they leave their customer's NAS vulnerable.  Not sure why they cannot enable SMBv2 for hardware that supports it and leave older hardware on SMBv1 ???

A bit of attitude in their response too. I thought Sonos wasn’t great sound quality anyway.  Bluesound might be better.  

Link to comment
Share on other sites

36 minutes ago, Mike13 said:

A bit of attitude in their response too. I thought Sonos wasn’t great sound quality anyway.  Bluesound might be better.  

Yes, a bit disappointing in their response.  Sonos had been good with their previous support response when I had issues, even when warranty had long lapsed.  Yes, Sonos has average audio quality but when I bought 5 years ago,  Sonos was by far the best wireless sound system.

Link to comment
Share on other sites

1 minute ago, Snoopy8 said:

Sonos was by far the best wireless sound system.

Which begs the question: What is the best wireless system now?

Link to comment
Share on other sites



10 minutes ago, Luc said:

Which begs the question: What is the best wireless system now?

Good question. Sonos has average AQ but compared with many cheap wireless systems is still good. Its ease of use still stands out and I think it is still the market leader.  Maybe Heos, Bose or Bluesound has better AQ??  Guessing here.

13 minutes ago, Raffinator said:

Followed your link to guarantee my Win10 laptop wasn’t using SMBv1 when talking to my NAS.

I presume because my streaming uses Linux and Mac components that this is not an issue?

Check on your NAS whether there is a setting to disable SMBv1.  On Synology DSM : Control Panel,  File Services, SMS Advanced Settings.  Also check your MicroRendu.  On my SMS-200 Ultra, they changed the Library Config setting, at my request (?), to define which SMB version to use.   

 

Sorry, do not know Mac.

Link to comment
Share on other sites

Guest scumbag
On 19/06/2018 at 6:21 PM, rantan said:

 

It is things like this that make me feel so good that I only use physical media for music. Another plus is that I own the physical copy.

 

However, to the OP, I  wish you well and I hope this situation can be addressed to your satisfaction.

So you haven't heard about the redbook backdoor vulnerability that affects CD's? It gets into your player and you can't access any of your music.

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.




×
×
  • Create New...
To Top