The list of fake concerns they list are not the real and very valid concerns I have seen. This addresses nothing.
> This addresses nothing. This does in-fact address quite a bit, because they have change their stance with this update. Previously even LAN only mode required to go via their bambu connect system, now you can switch it to developer mode and talk freely via MQTT to the printer.
Bambu Lab - Setting the Record Straight About Our Security Update
31–40 of 122 posts
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#32Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#33Does anyone know or can see an actual concrete security concern with the current implementation of LAN mode? https://github.com/Doridian/OpenBambuAPI/blob/main/mqtt.md Right now, the printer's local MQTT server can only be accessed from the local IP using an 8 digit password obtained through through the physical display. I can't personally see any fundamental issue with this design assuming the implementation is corr…
Look up old results about "BambuLab MQTT" on Google. They use an online MQTT server instead of the local one for the following functions: initiating printing, heating the nozzle, and heating the heatbed. (see https://www.allaboutbambu.com/2024/06/14/p1p-p1s-new-firmwar... ) On https://forum.bambulab.com/t/bambu-lab-mqtt-limitations/8344... you can see their MQTT server got DDOSed by some faulty 3rd party "client". I…
In lan mode it doesn't use anything remote and works just fine completely isolated.
> you can see their MQTT server got DDOSed by some faulty 3rd party "client"
Right, when you use 'cloud mode' then bambu controls the printer, and your own control has to go through them.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#34Earlier quoted context omitted.
You could already talk freely to the MQTT on the printer and it was already secured with a unique password. This feels like making it a second class feature that could disappear at a future point.
That is obviously correct, but this is a meaningful improvement over what their initial plan was.
- Want to introduce x, but we are worried what our userbase thinks.
- Introduce something way more ridiculous y that subsumes x.
- Rollback y but not x because of backlash.
Now they look like a company that listens to their users and they got what they wanted.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#35Re: Bambu Lab - Setting the Record Straight About Our Security Update
#36Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.
I summarise all these replies in my head as "Influencer I've never heard of influences"
I agree with your re: Developer mode though.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#37Meanwhile Jeff Geerling already put a video out on his second channel that he won’t recommend a bambu lab printer anymore although he was happy with his printer. And this update didn’t convince him to change his mind. “Developer mode” isn’t a solution. You buy hardware and it should work 100% without cloud connectivity. Otherwise it’s not your hardware.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#38Uh-huh. So exactly what threat or threats is the "security upgrade" meant to address, what alternatives were considered, and where the heck is the "security" in sticking a barely obfuscated private key in a publicly distributed binary?
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#39Earlier quoted context omitted.
You could already talk freely to the MQTT on the printer and it was already secured with a unique password. This feels like making it a second class feature that could disappear at a future point.
That is obviously correct, but this is a meaningful improvement over what their initial plan was.
Don't get me wrong I'm glad they're responding to feedback but the feedback shouldn't have been required in the first place.
I'm all for better security on products(esp ones that heat up to 300C!) but interoperability with open standards makes it a better product overall and given the direction we've seen in the IoT space I think they've done quite a bit of damage(even if not intentionally) by not taking more care in this area.
Re: Bambu Lab - Setting the Record Straight About Our Security Update
#40Earlier quoted context omitted.
Tellingly, this pull request is coming from a Bambu Lab employee. I think the OrcaSlicer maintainers should tell Bambu Lab to pound sand with this change.
> I think the OrcaSlicer maintainers should tell Bambu Lab to pound sand with this change. Hum, the alternative is OrcaSlicer stops working with Bambu printers...
Which is fine, no? Plenty of other good printers available.