Announcement

Collapse
No announcement yet.

"Important Upgrade Information"

Collapse
This is a sticky topic.
X
X
 
  • Time
  • Show
Clear All
new posts

  • "Important Upgrade Information"

    Some of you might have seen this menu item, talking about improving MySB:
    Click image for larger version  Name:	Screenshot 2022-12-07 at 13.48.40.png Views:	270 Size:	72.6 KB ID:	1635610
    The background for this forced upgrade is that we want to bring the way in which your passwords are stored on MySB up to date. The service has been up for about 15 years now. In this time the internet and technology in general has come a long way. What used to be the perfect way to store passwords back then no longer suffices to withstand today's hacking techniques.

    Using a better algorithm on the server side would be relatively easy - we've already done that change for UE SmartRadio. But the LMS integration needs an upgrade too: up to LMS 8.3 we were storing your MySB credentials (with the password hashed) in LMS' prefs file. That's not best practice. Therefore we changed the way how we sign LMS in to MySB in LMS 8.3. Later this year, when we turn on the improved password storing on MySB, older LMS versions will no longer be able connect to MySB.

    Please note that this is a measure taken proactively. There's no sign of a successful hack on MySqueezebox.com or UESmartRadio.com.
    Last edited by mherger; 2023-04-22, 06:41.
    Michael

    "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
    (LMS: Settings/Information)

  • #2
    Hi Michael, I understand the need for this upgrade and unfortunately I think it will mean I will have to change the platform I use to run LMS but I wanted to check that this is really the case. I am currently running LMS v 8.0.0 on a Synology DS216j with an out of date version of Perl. I don't directly use the MySqueezebox website but I do use the Tidal plugin which I believe requires use of the MySqueezebox site. I know this platform is not supported and as far as I am aware there isnt v8.3.0 available. Consequently I have been anticipating a move to Raspberry Pi at some point. I wanted to check with you that:
    1) my current setup will cease to work when the upgrade happens
    2) You are not aware of some other work around I could use
    In summary is it time to change my platform?

    Best wishes and thank you for all your work on behalf of the community
    Simon

    Comment


    • #3
      Oops... I'm sorry for the delay: I forgot to actually send off my response... So here's what I wanted to send weeks ago:

      If you can get a hold of a Pi then this would be the best option IMHO. Yes, TIDAL would no longer work with your existing installation. And no, I'm not aware of another work around for your setup. If you hunt for a Pi you could look into getting one 2nd hand. I believe that even a Pi2 might be on par with your NAS' performance.
      Michael

      "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
      (LMS: Settings/Information)

      Comment


      • #4
        In case I do not use any of the apps offered on MySB.com - are there any other reasons to use this service at all?
        LMS 8.3.1 on Raspbian GNU/Linux 10 (buster); 3 Radios

        Comment


        • #5
          Originally posted by xrad
          In case I do not use any of the apps offered on MySB.com - are there any other reasons to use this service at all?
          If you haven't added MySB credentials in Settings/MySqueezebox.com, then you wouldn't see any impact anyway. You should be good.
          Michael

          "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
          (LMS: Settings/Information)

          Comment


          • #6
            Originally posted by mherger

            If you haven't added MySB credentials in Settings/MySqueezebox.com, then you wouldn't see any impact anyway. You should be good.
            Actually I have those credentials, I set this up a long time ago and never really touched it. I've been using Deezer for a long time and figured this was needed for the app on MySB.com. I have not switched to Spotify (I really like Spotty!) and I want to know if I can cut the cord or not. Can I?
            LMS 8.3.1 on Raspbian GNU/Linux 10 (buster); 3 Radios

            Comment


            • #7
              Head to mysqueezebox.com to see what "apps" you've installed. Remove those you don't use any more. If nothing but Radio or Podcast is left, then you don't really need MySB integration.
              Michael

              "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
              (LMS: Settings/Information)

              Comment


              • #8
                Having trouble logging in to MySB from one of my radios after a firmware reset, the radio says wrong email or password.
                Using the same credentials I can successfully login from a web browser although I now see an extra level of security (selecting pictures).
                Would any of this be why I can't login from the Squeezebox Radio?
                Any help much appreciated.

                Comment


                • #9
                  Originally posted by gegen
                  Having trouble logging in to MySB from one of my radios after a firmware reset, the radio says wrong email or password.
                  Using the same credentials I can successfully login from a web browser although I now see an extra level of security (selecting pictures).
                  Would any of this be why I can't login from the Squeezebox Radio?
                  Any help much appreciated.
                  so, when you say logging into mysb.com, you mean after you go through a factory reset->choose language->choose network->connect->register or continue?

                  I ask because IIRC when you get to this step you are registering your device, you are not actually entering credentials for accessing LMS. It used to be that the registration would survive a factory reset (and you could choose it or register to another account). But with recent security changes to mysb.com, this has changed.

                  I'll reset a radio I have here and check it out as I am a little fuzzy on it.

                  <edit - I just reset a radio - select language-continue-select network-> then the screen that asks you if you want to register or continue. If you look at the smaller text at the top, it does indicate that the radio is registered to my email, so I choose "continue" and setup is done.>

                  Jim
                  Last edited by Redrum; 2023-04-28, 13:10. Reason: tried a radio reset

                  Comment


                  • #10
                    Originally posted by Redrum

                    so, when you say logging into mysb.com, you mean after you go through a factory reset->choose language->choose network->connect->register or continue?

                    I ask because IIRC when you get to this step you are registering your device, you are not actually entering credentials for accessing LMS. It used to be that the registration would survive a factory reset (and you could choose it or register to another account). But with recent security changes to mysb.com, this has changed.

                    I'll reset a radio I have here and check it out as I am a little fuzzy on it.

                    <edit - I just reset a radio - select language-continue-select network-> then the screen that asks you if you want to register or continue. If you look at the smaller text at the top, it does indicate that the radio is registered to my email, so I choose "continue" and setup is done.>

                    Jim
                    Thanks very much for spending the time to reset a radio to investigate.
                    It was after a factory reset as you asked and I was entering credentials for mysb.com.
                    The fact that you got an acknowledgement indicating that the radio is registered to your email (which I don't get)
                    made me think that now that the reset radio had a network connection then maybe just a reboot would do the trick.....and it did!
                    Thanks again for getting me going in the right direction.

                    Comment


                    • #11
                      Originally posted by gegen
                      Having trouble logging in to MySB from one of my radios after a firmware reset, the radio says wrong email or password.
                      Using the same credentials I can successfully login from a web browser although I now see an extra level of security (selecting pictures).
                      Would any of this be why I can't login from the Squeezebox Radio?
                      Any help much appreciated.
                      Are you in EU rather than US? I just saw there's an issue with the deployment pipeline. This might have blocked the latest updates.

                      That said: if you run LMS, you should be able to connect the device to LMS, which would register it on MySB automatically.

                      Feel free to PM me the MAC address and your account email. I can check what's wrong there.
                      Michael

                      "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
                      (LMS: Settings/Information)

                      Comment


                      • #12
                        Thanks for replying, I am in EU rather than US. I rebooted the radio at the point where it was connected to my wifi and before entering credentials which weren't working and that did the trick.

                        Comment


                        • #13
                          Originally posted by mherger

                          That said: if you run LMS, you should be able to connect the device to LMS, which would register it on MySB automatically.
                          This is good to know, thanks. So, if someone were to buy say a used radio, registered to someone else, and they just connected to the network, then connected to LMS, the lms credentials (in settings->mysb.com tab) would be assigned to the radio, replacing the registration of the previous owner? Or, does it only work if there is no registration?

                          Jim

                          Comment


                          • #14
                            Originally posted by Redrum

                            This is good to know, thanks. So, if someone were to buy say a used radio, registered to someone else, and they just connected to the network, then connected to LMS, the lms credentials (in settings->mysb.com tab) would be assigned to the radio, replacing the registration of the previous owner? Or, does it only work if there is no registration?

                            Jim
                            No, it's not that easy to hijack a stolen device . In that case this wouldn't work. But for an unregistered device it should. Or, as you showed, in the case of your own, already registered but factory reset device you should be able to skip the registration step.
                            Michael

                            "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
                            (LMS: Settings/Information)

                            Comment


                            • #15
                              Originally posted by mherger

                              No, it's not that easy to hijack a stolen device .
                              Right, thanks for the clarification. It helps to understand for the next time we try to help out someone.

                              I should probably stop thinking, but can a device ever be unregistered if it has been registered at one time? I ask because when I buy devices on ebay, they may be factory reset, but they are always registered. That exposes the sellers email address to the buyer. Not a problem, but if one wanted the device to be unregistered, is that possible without bugging you?

                              Jim

                              Comment

                              Working...
                              X
                              😀
                              🥰
                              🤢
                              😎
                              😡
                              👍
                              👎