Live data from Hacker News

Bambu Lab is abusing the open source social contract

jeffgeerling.com

381–390 of 452 posts

Re: Bambu Lab is abusing the open source social contract

#381

Funny how fast people forget. LAN mode was NOT part of their original plan until outrage like this happened last time. They shifted their course and changed their blog post after. Putting pressure as a customer is how you steer company’s direction.

The only way to put pressure on a company is to buy their competitor's product instead.

The company would prefer that you "put pressure" by getting angry, ranting on social media, and then still buying their product.

Re: Bambu Lab is abusing the open source social contract

#382
post #76

Earlier quoted context omitted.

They can bar people from accessing their servers if they do so by rewriting the entire slicer to be closed source and then implementing some actual security, instead of literally giving you the means of access AND the permission to use and modify it as you wish.

If I give you a template for a postcard, it doesn’t give you the right to send it with “signed, ricardobeat” at the end. These are orthogonal concerns. They could very well enforce login for the entire app, that doesn’t require any closed source code and everyone would be worse off.

It does if you make the card self destruct if you don't write "signed, ricardobeat" on it. Courts have been over this in the 1990s with Nintendo. The Gameboy wouldn't boot any game that didn't start with "signed, Nintendo" so game companies just put that there and it wasn't illegal.

(Later, a trick was found to replace the signature and still boot, but it required extra chips in the game cartridge)

Re: Bambu Lab is abusing the open source social contract

#383
post #71

I am an outsider on the details of the Bambu software requiring users to go through their servers in China and the closing of their software. Still I suspect it is about spying in wartime, Bambu printers are at the core of the Ukrainian war effort, the main reason even Ukraine is winning since januari 2026. First China prevented Ukraine from using any of the drones that they sold in millions to Russia while exercisin…

Lot of conspiracy theory and misinformation in this comment. I'm not up to date with their latest printers, but the Bambu printers used during this timeframe have easy ways to enable LAN only mode. You can leave it disconnected from the network entirely and use an SD card, too. The app lets you enable root access and install firmware mods. There are multiple efforts to reverse engineer the firmware.

[deleted]

Re: Bambu Lab is abusing the open source social contract

#384
post #356
post #346

Earlier quoted context omitted.

The law isn't some autistic computer system, "authentication" is a very broad and amorphous term.

Even if that’s correct, Bambu has a right to then press charges on the users, but can’t really complain about the guy simply copying AGPL software to make it work. He’s not the one doing the illegal part. Bambu clearly didn’t want to press charges on their users, though, so they weaponized the law to try and prevent this, and it’s causing them issues. In any case, we’re not in some “only the laws matter” reality, we’…

"Press charges" - as if this were some Simple Assault. The CFAA isn't something one "chooses" to levy or not, these are crimes against the United States of America and it is solely up to the discretion of a US Attorney to prosecute.

A US Attorney prosecuting anyone on behalf of Chinese business interests isn't a good look politically, though, and that's often a factor.

Re: Bambu Lab is abusing the open source social contract

#386
post #346

Earlier quoted context omitted.

With no authentication it's a "gates down" scenario and it's assumed that if you put your server on the open internet you intend people to connect to it. With authentication it's "gates up" and then "without authorization" from CFAA kicks in. I think it's unlikely that a user agent string creates a "gates up" situation, especially not if it's from code granted under a permissive license.

The law isn't some autistic computer system, "authentication" is a very broad and amorphous term.

If I build their slicer, not modifying any line of code, then accessed using that binary, would that be acceptable? If not, why not, considering it is identical to what is on their website?

If I made any changes prior to building, would it still be acceptable? And if not, where is the line? What is the legal basis, any precedent? How much of the code may I modify before I cross an invisible threshold and somehow "bypass" an "authentication" (neither fit UA anyways, either for law or other purposes unless one can provide any evidence that it ever has).

Re: Bambu Lab is abusing the open source social contract

#387

Earlier quoted context omitted.

Sounds like RC quadcopters society -- everyone knows DJI, but they make fan guards a part of the frame. Guards and props are the most fragile parts, a consumable really. Something an enthusiast often carry spares for, to quickly swap on the field for any other RC quad, but with DJI you need what, send the whole frame to factory?

I have DJI drone, broke prop maybe once, replaced in few minutes. Prop guards work as intended. I did once got it into iron sand which seized the motors. Luckily their insurance covered full replacement. There are much worse things about them like subpar performance or shitty way to access the card slot in Avata, but otherwise they solid.

I mean prop guards -- what do you do when a prop guard breaks?

Re: Bambu Lab is abusing the open source social contract

#388

Earlier quoted context omitted.

I know it's popular to shit on 2D printers, but other than very often being very slow and running out of ink (or rubber rollers hardening after 20 years of use) - I actually didn't have any issues with them? But then I actually didn't really use them for 20 years either.

My main issues: * one day remote printing no longer works, you need to set it up again or even get into prolonged debugging session * remote printing works one ane device but not other * one color toner cartridge on a color laser printer is empty or near empty, printer refuses to print without all manners of overrides on the local control panel, making it unusable for non-technical users Well, the last point is basic…

I stopped buying cartridge-based inkjets years ago. I'm happy with my Canon G3020, which uses ink tanks (built into the printer, not a third-party addon that the manufacturer will claim voids the warranty).

And it's impressive how long those ink tanks last: I printed out 400 pages of full color and the ink tanks went from 80% full to about 50% full. (There's a clear plastic window in front of the ink tanks, with a "refill when ink reaches this level" line on it — a raised line of plastic, not something inked or painted onto it that could rub off — so you can glance at the printer and see what level the ink is at). The ink bottles cost me about $12 each if I remember right, and each one will fill the ink tank from the "refill here" line to more than 100%: I had to stop filling, then wait until I had printed a few hundred more pages, then refill the rest. Rough back-of-the-envelope math says maybe 1200 pages from a full ink tank. The C, M, and Y bottles will cost $36 total (the K bottle will last a lot longer so I'm not counting it in this math), which means 3 cents a page for full-color, ink covering nearly the whole page, prints. Considering the cheapest print shop I've found would charge me 20 cents per page (and I've seen 50-cents-a-page quotes for full-color printing), the $200 printer will have already paid for itself by the time you run through one ink tank (17 cents saved times 1200 pages is $204).

This is turning into an ad for Canon, but seriously, it's a great printer. The only thing I don't like about it is that it doesn't do automatic duplex printing (I have to pull the pages out, flip them over, and put them back in), and I knew that when I bought it (the model that did automatic duplex was $450, and I chose not to buy that one). Oh, and I am not affiliated with Canon in any way: considering how glowing a review this is, I should probably say that explicitly.

But the best part for me was that it's not an Epson. I previously owned an Epson ink tank printer, and it was great... until the ink sponge filled up. Did you know that ink jet printers, at least the ink-tank variety, have a sponge inside them? When you do a "clean clogged print heads" routine, the printer moves the print head over to the position of the sponge, and pushes ink through the print heads until it's moved enough liquid to hopefully push the clog out. Sometimes it works, sometimes it doesn't. But the sponge can only absorb so much ink before it fills up. And on an Epson, the sponge is not a user-serviceable part. They want you to send it to one of their official repair shops to get it replaced, costing I don't know how much because I refused to do it. I found an unofficial way to wipe the printer's internal counter that kept track of how much ink was in the sponge... and when the printer died about a year later (for unrelated reasons), I went shopping for another brand. I'll never buy an Epson printer again. Canon, on the other hand, will sell you a "maintenance cartridge" (a large sponge mounted in a plastic tray of the right shape to slot into the printer) for about $10 plus shipping. When the sponge gets full you can just swap in a new one. Dead simple.

Enough gushing from me. The point that I spent way too long getting to is, ink-jet printers don't have to use cartridges. Ink-tank printers used to only be available in the Asia/Pacific market, but they're available in the US now. A couple years ago I helped my parents (in the US) buy a Canon G3020 and set it up for them. So far their experience has been positive, too.

Re: Bambu Lab is abusing the open source social contract

#389

Earlier quoted context omitted.

You must put authorization on your server if you don't want others connecting to it. While the right of access is not granted by AGPL - it is not reasonable to run a public service with an AGPL client and say you shouldn't be connecting to it. They are doing a lot of work to create implied consent under CFAA. If you want to control access you must do something to control access - it must reach a threshold, it cannot…

> You must put authorization on your server if you don't want others connecting to it. Unfortunately, the CFAA doesn't necessarily require that authorization is implemented through technical means, and it definitely doesn't require any authorization to be technically robust.

The point is that they distributed AGPL licensed software which legally speaking puts them on very thin ice if they say "actually you're not allowed to modify that software we gave you and explicitly told you you could modify to do whatever you want."

This is a direct quote from the Affero GPL:

> When you convey a covered work, you waive any legal power to forbid circumvention of technological measures to the extent such circumvention is effected by exercising rights under this License with respect to the covered work, and you disclaim any intention to limit operation or modification of the work as a means of enforcing, against the work's users, your or third parties' legal rights to forbid circumvention of technological measures.

The thing Bambu is doing is very much against the spirit of the AGPL, which is the license they chose for the Bambu printer software. And the AGPL has such broadly written language it's hard to believe what they are doing complies with the letter.

Re: Bambu Lab is abusing the open source social contract

#390
post #369

I'll play devil's advocate. What is Bambu Lab's motivation to provide lifetime free cloud services for a onetime revenue transaction? They could demand a subscription. But they probably know for casual users this would be unwelcome. They could seek to monetize via other means like ads or cross and up-sell. Third party clients are a risk to these. I don't see the ground the OSS community are standing on to demand Bamb…

If they don't want to provide free cloud services in perpetuity they could make their 3D printers work offline without restrictions.

They do, its called developer mode.
Post reply on HN