Live data from Hacker News

Bambu Lab is abusing the open source social contract

jeffgeerling.com

151–160 of 452 posts

Re: Bambu Lab is abusing the open source social contract

#151
post #71

I am an outsider on the details of the Bambu software requiring users to go through their servers in China and the closing of their software. Still I suspect it is about spying in wartime, Bambu printers are at the core of the Ukrainian war effort, the main reason even Ukraine is winning since januari 2026. First China prevented Ukraine from using any of the drones that they sold in millions to Russia while exercisin…

> This firmware replacement will cost a couple of months to write so we all should send that programmer a little money so he/she can release it for free.

> A free Bambu firmware will allow the Ukranians to continue producing another few million drones and save over a hundred thousands lives by ending the war.

If that were true, it seems to me, that Ukraine would have already done it if it was somehow standing in their way.

Re: Bambu Lab is abusing the open source social contract

#152
post #71

I am an outsider on the details of the Bambu software requiring users to go through their servers in China and the closing of their software. Still I suspect it is about spying in wartime, Bambu printers are at the core of the Ukrainian war effort, the main reason even Ukraine is winning since januari 2026. First China prevented Ukraine from using any of the drones that they sold in millions to Russia while exercisin…

Please provide sources to your claims.

I couldn't find a source for China disabling drones it sold to Ukraine, but they did cut off drone exports to Ukraine, while still supplying them to Russia:

https://www.newsweek.com/china-ukraine-russia-war-drone-uav-...

Re: Bambu Lab is abusing the open source social contract

#153

This sentence in Bambu Lab's blog post is wild: > We have documented incidents of service outages caused precisely by spikes in unauthorized traffic - overwhelming the servers, causing service disruptions affecting everyone. The cost was instability felt by all users. So it's a problem that their printers are popular, and they can't be bothered to scale their infra, so let's gate everything based on USER AGENT STRING…

I guess if it's a security issue, it's a security issue: https://github.com/bambulab/BambuStudio/issues/10681

Re: Bambu Lab is abusing the open source social contract

#154
post #30

Full disclosure: I've never owned a Bambu because I've never loved the idea of a "closed" ecosystem 3D printer, however I have used them, and am very familiar with the 3d printing space beyond Bambu. For anyone considering alternatives: You should know that almost all other 3D printers expect you to know a little more about how they actually work than Bambus. Bambus are as close as you can get to a "just works" type…

I think the Bambu social contract is pretty clear:

- they benefit from open source software work

- we benefit from their dirt cheap top performing machines

As long as they remain the lowest priced and the best, they can do whatever they want if you ask me. They provide insane social value through accessibility. Before them, it was Creality with the Ender 3.

My problem with Pruša as an European is that it turns us into the equivalent of being a Chinese citizen who can't afford the Temu product they make at work. Their machines are priced more or less only for US export, and not really something most people here can reasonably buy. They even refuse to use injection moulding out of some self righteous principle, which drives the price per unit up further all the while selling less durable machines cause they're half RepRap. I take it sort of as a personal insult and I will never buy one even though I can afford it, I see it as bad value. Like buying a gold plated watch or something.

Re: Bambu Lab is abusing the open source social contract

#155

"It pretended to be the official client" is not a security argument if the mechanism was client-supplied metadata. That’s not impersonation. That’s Bambu discovering that user agents are not authentication.

Or it's a really blatant security issue that should be reported https://github.com/bambulab/BambuStudio/issues/10681

Re: Bambu Lab is abusing the open source social contract

#156
post #36

Earlier quoted context omitted.

And by using AGPL they grant you the license to use the code however you wish, they cannot say it's "unauthorized access".

Yes you can use the code however you want but equally they are free to bar anyone they wish from accessing their servers. These are completely orthogonal issues in a legal sense.

They're essentially saying "yes, the code is open source, but you're not allowed to modify it or we'll ban you and threaten you with legal action", which is completely antithetical to the whole idea behind open source (especially the GPL which literally says in the license text itself that it was created to protect your right to run modified software). "Violation of the open source social contract" is a good way to describe it.

You're correct of course that this is an entirely distinct argument from what Bambu's legally allowed to do under existing law.

Re: Bambu Lab is abusing the open source social contract

#157
post #36

Earlier quoted context omitted.

And by using AGPL they grant you the license to use the code however you wish, they cannot say it's "unauthorized access".

Yes you can use the code however you want but equally they are free to bar anyone they wish from accessing their servers. These are completely orthogonal issues in a legal sense.

Yes, but not bully the people sharing AGPL code. I would like to see how they do it.

Re: Bambu Lab is abusing the open source social contract

#158
post #30

Full disclosure: I've never owned a Bambu because I've never loved the idea of a "closed" ecosystem 3D printer, however I have used them, and am very familiar with the 3d printing space beyond Bambu. For anyone considering alternatives: You should know that almost all other 3D printers expect you to know a little more about how they actually work than Bambus. Bambus are as close as you can get to a "just works" type…

Prusa is still the most 'open source-ish' choice, but they're no longer a polar opposite to Bambu, in 2023 they started making efforts to stop commercialization of their designs, stopped sharing source/design material for their PCBs, etc. Then in 2025 they changed their 'open community license' to say users may not: “Sell complete machines or remixes based on these files, unless you have a separate agreement…” and “T…

They were so deeply undercut by Chinese clone vendors that buying Prusa made little sense to consumers. They couldn't survive without banning them. The situation was similar to IBM PC, but Prusa Research was no IBM.

Re: Bambu Lab is abusing the open source social contract

#159
post #67

Earlier quoted context omitted.

Yes you can use the code however you want but equally they are free to bar anyone they wish from accessing their servers. These are completely orthogonal issues in a legal sense.

Any instance anywhere that a court has considered an UA sufficient for access control? Especially one published under a copyleft license?

Techies like us get caught up in mechanism all the time in discussions like this.

But, though there are some explicit laws where that’s how it works, that’s not generally how the legal system works. If I have a private server, and I don’t give you permission to access it - or, even better, tell you not to, it doesn’t really matter how I secure it. If you access it, you’re in the wrong.

To give a physical analogy, it doesn’t matter how I’ve secured my house. Even if the door is open, you’re not allowed to just waltz in (or, to take it a bit further, come in and start using my stuff).

Re: Bambu Lab is abusing the open source social contract

#160

Earlier quoted context omitted.

Closer to 200C. But the gantry constraints movement, the 200C nozzle can only really touch its holder, the print bed, the filament and some metal or silicon cleaning surfaces. None of those are flamable at those temps. Maybe if it knocks itself down to the ground? But I worry much more about faulty wiring or stuff like that. And that's more a function of the brand and model

All of the fires I've heard about 3d printing involved sketchy power supplies in some of the printers or DIY builds out there. Thermal runaway protection is really easy code to write and very common in firmware and the thermal design of the heated parts makes it hard to get there. Not saying fires don't happen that way but let's say it's a failure mode that is a challenge to achieve intentionally much less accidental…

Thermal runaway protection does not help in certain failure modes.

Failed FET for instance. They tend to fail "on". Unless you have a highside FET shutting off the power (and that may fail too).

On my printer I have software watchdogs but I also have an entire "dumb" (no MCU) circuit that will shut off a large relay that goes to my heaters if any of it's failsafes are triggered. I have a smoke detector, secondary thermistors, etc.

There are a bit more things in the way of thermal fuses and heaters that are less likely to runaway on the newer commercial printers but I still think people need to take the risk more serious.

I have been building printers and printing since 2011 and I still prefer to not have my printer in my house where the family sleeps, even with the failsafes. It lives out in the shop with plenty of room around/above it in case of a fire.

Post reply on HN