Has anyone assessed the risks of Roon servers being hacked as an entry point into residential network? Is Roon aggressively updating their software to reduce/eliminate these risks? Has anyone seen a music server become a stealth residential proxy server? I am not having issues that I know about but a lot of press is coming out on these issues.
Your comment is rather broad for a detailed answer. Are you referring to Roon server, which is software running on a host operating system, i.e., Linux, macOS and Windows? Roon Optimized Core Kit? Or any combination where Roon ARC is enabled?
If Roon isn’t accessible outside the LAN it can’t be used as you suggest unless the host computer is already compromised. Likewise, running ARC can be done securely, either using a VPN, i.e., Tailscale, or port forwarding, which uses certificates (recently updated) to authenticate a remote session.
Roon has no back door, and Roon can’t access the server remotely (logs may be sent, but only if the server is in diagnostic mode.)
Lockdown mode in macOS significantly limits Roon’s networking capabilities.
Could it be that it has similar doubts?
Someone closer to Roon development is probably the only ones that know. From observation, Roon’s server/client software is updated on a continual basis and practices security standards like other software vendors. Just like any other software running on a server, your security is more dependent on whether you have secured your operating system and firewall. The recent announcement that the Aug 20 update will need to meet minimum requirements your operating systems (OpenSSL, glibc, etc) is comforting to me in that Roon is paying attention to what’s needed in the operating system.
It might be a different story on “who is responsible” to maintaining security if you’re using Roon’s own linux-based operating system (provided for ROCK and Nucleus). My understanding is ROCK gets security updates as needed and will only run operating system services required to support Roon Server (thus decreasing attack vectors). I ran ROCK for a couple years and didn’t witness any security issue but I admit I always felt it was a little bit of a black box of what’s getting updated.
I do think there could be some improvements made on who in the household on your LAN can access your Roon Server. But at the end of the day if you don’t trust someone in your own house to access the Roon Server you probably shouldn’t be letting them access anything on your LAN.
Thank you for your reply. My comment was intentionally broad as I wanted to hear the level of concern Roon users have and I wanted to learn what system issues I should pay attention to. I am not that tech savvy. The Wall Street Journal had two articles over the last two weeks that made me think many of us may be more trusting than we should be that someone in the software development side is protecting us. Indeed they may be trying to do that but the threats keeping advancing. One article was about a young man at the university who identified a major cyberthreat brewing that utilizes Residential Proxy Servers which is the ability to use our own network/servers in receiving and sending malicious software (I am oversimplifying the threat description). He catalogued thousands of IP Address that had been collected and being offered for sale to nefarious organizations who could use that capability. In particular one of the servers mentioned was an inexpensive digital picture frame which is apparently easy to hack to get into your network. If that is true then just look at the IP Addresses in your LAN and imagine them being vulnerable as well - network switches, tv and music streamers, etc. Food for thought.
The other article was on the vulnerability of older software that actually has numerous bugs that were never identified nor were they of particular concern, except the latest AI tools can find them easily and quickly exploit them. Keeping software updated is important. And not keeping too much old hardware with firmware that is out of date and not upgradeable should be something to look at.
To your first question I am using a Roon Nucleus as my streamer and a LTA Aero as my DAC. I am contemplating several third party streamer/servers as I seek to upgrade but I am comfortable with the Roon interface and meta-data so will likely build around that.
For this to occur, the network would already be compromised, and a common cause is user behaviour. Examples include responding to phishing, downloading compromised (Windows) programs with malicious payloads, weak passwords or using the same password for everything, using unsupported software, e.g. Windows 10 or earlier and old routers, buying IOT devices of unknown origins etc.
Also, third party services that leak your data is more prevailent than you may imagine since the majority of businesses do not inform the user or data protection authorities (if they operate outside the EU / UK.) This is why it is important to use one password per application / service, 2FA, and plus email addresses.
These are public not private IP addresses that are / were previously compromised. This is similar to sucker lists associated with telephone numbers, or compromised email addresses and passwords previously mentioned.
Chiming in here noting my concern over this is extremely low. Susceptibility to cyber threats is based on the relationship between the complexity/effort required for the attack, and the perceived value of the target. Meaning if perceived value of the target is low, as it is with a residential network, than as long as you have reasonable security standards in place there isn’t a lot to worry about. A “hacker” is not going to spend hours breaching a residential network unless they know there is reason to. Most residential networks are attacked through vulnerabilities in order to be leveraged to launch additional attacks on much higher value targets. Steering traffic through 1000 different home networks in order to attack a high value target, credential stuff a login or perform a dos attack on a server is valuable to an attacker because distributed attacks are much harder to detect and mitigate than if a login is being hit by the same IP 100 times every minute. Plus residential IPs are “clean” and not on widely publsihed deny lists. So even if you have been “breached” it is unlikely the attacker is sifting through your files- they simply want to launch other attacks from your network.
I run an enterprise grade firewall at home (pfsense) and the logs are clear as to 2 things happening;.1 I am constantly under attack. 2 the constant attacks are “dumb” attacks mostly looking for open ports.
Your time and concern are better spent ensuring your password hygiene is excellent on all of your internet based applications/websites. Excellent = relatively complex and UNIQUE passwords for every login.
Thanks all for your replies. I believe that device vendors are not intentionally leaving the doors open but unexpected threats can emerge. [GPS was originally encrypted by DOD to keep bad actors from using the positioning data. And then people figured out how to triangulate off the carrier wave to get fairly accurate positioning data anyway] I plan to pay close attention to ever developing threats as I am sure all of you will as well. I do not want to overreact to conceptual threats but I do want to educate myself on pathways that could be opened either through the technology employed or through my own missteps and remain vigilant in taking prudent actions to limit my exposure.
Thanks
Let’s be honest, you’re more likely to have someone hack your Roon online account than your Roon server.