Live data from Hacker News

Bambu Lab - Setting the Record Straight About Our Security Update

blog.bambulab.com

31–40 of 122 posts

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#31
post #3

The list of fake concerns they list are not the real and very valid concerns I have seen. This addresses nothing.

> This addresses nothing. This does in-fact address quite a bit, because they have change their stance with this update. Previously even LAN only mode required to go via their bambu connect system, now you can switch it to developer mode and talk freely via MQTT to the printer.

Why should I switch to "developer mode" to talk to a computer I own on my own network?

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#32

Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.

Neither LAN mode nor Developer mode requires cloud connectivity. Keep spreading the FUD though.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#33
post #16

Does anyone know or can see an actual concrete security concern with the current implementation of LAN mode? https://github.com/Doridian/OpenBambuAPI/blob/main/mqtt.md Right now, the printer's local MQTT server can only be accessed from the local IP using an 8 digit password obtained through through the physical display. I can't personally see any fundamental issue with this design assuming the implementation is corr…

Look up old results about "BambuLab MQTT" on Google. They use an online MQTT server instead of the local one for the following functions: initiating printing, heating the nozzle, and heating the heatbed. (see https://www.allaboutbambu.com/2024/06/14/p1p-p1s-new-firmwar... ) On https://forum.bambulab.com/t/bambu-lab-mqtt-limitations/8344... you can see their MQTT server got DDOSed by some faulty 3rd party "client". I…

That article is referring to conflicting controls when using their cloud stuff.

In lan mode it doesn't use anything remote and works just fine completely isolated.

> you can see their MQTT server got DDOSed by some faulty 3rd party "client"

Right, when you use 'cloud mode' then bambu controls the printer, and your own control has to go through them.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#34

Earlier quoted context omitted.

You could already talk freely to the MQTT on the printer and it was already secured with a unique password. This feels like making it a second class feature that could disappear at a future point.

That is obviously correct, but this is a meaningful improvement over what their initial plan was.

That doesn't seem obvious to me. It's not unthinkable their plan is:

- Want to introduce x, but we are worried what our userbase thinks.

- Introduce something way more ridiculous y that subsumes x.

- Rollback y but not x because of backlash.

Now they look like a company that listens to their users and they got what they wanted.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#36

Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.

There is little I find more hilarious than the " has put out a video on their that says " comment reply.

I summarise all these replies in my head as "Influencer I've never heard of influences"

I agree with your re: Developer mode though.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#37

Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.

Yeah, what is the point of developer mode for a device you’re not “allowed” to develop for anyway?

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#38

Uh-huh. So exactly what threat or threats is the "security upgrade" meant to address, what alternatives were considered, and where the heck is the "security" in sticking a barely obfuscated private key in a publicly distributed binary?

The security threat is real, they got ddos attempt to their mqtt service last year from 3rd party apps. The fix is not good though, distributing private key.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#39

Earlier quoted context omitted.

You could already talk freely to the MQTT on the printer and it was already secured with a unique password. This feels like making it a second class feature that could disappear at a future point.

That is obviously correct, but this is a meaningful improvement over what their initial plan was.

I don't really see what having a "developer mode" offers here beyond the existing solution. The current mqtt is already locked down with a unique password and AFAIK the endpoint was read-only anyway.

Don't get me wrong I'm glad they're responding to feedback but the feedback shouldn't have been required in the first place.

I'm all for better security on products(esp ones that heat up to 300C!) but interoperability with open standards makes it a better product overall and given the direction we've seen in the IoT space I think they've done quite a bit of damage(even if not intentionally) by not taking more care in this area.

Re: Bambu Lab - Setting the Record Straight About Our Security Update

#40

Earlier quoted context omitted.

Tellingly, this pull request is coming from a Bambu Lab employee. I think the OrcaSlicer maintainers should tell Bambu Lab to pound sand with this change.

> I think the OrcaSlicer maintainers should tell Bambu Lab to pound sand with this change. Hum, the alternative is OrcaSlicer stops working with Bambu printers...

> Hum, the alternative is OrcaSlicer stops working with Bambu printers...

Which is fine, no? Plenty of other good printers available.

Post reply on HN