Skip to content

Comment on Bambu Lab - Setting the Record Straight About Our Security Updateparent

Comments

Generally speaking, no. Prusa comes close - they're dedicated to community and OSS, and are quality parts... but are almost 2x the price and tend to be missing comparable features.

The other competition doesn't quite have the UX and quality of Bambu Lab. That's changing slowly, but it's reality today IMO.

The challenge is that the 3d Printing community is maturing from a hobbyist/tinker phase into a consumer phase with Bambu Lab leading the way. Bambu Lab has mostly threaded the needle by balancing proprietary UX with practical ability to tinker, swap parts, etc.

But as with most hobby communities, if someone doesn't understand a motivation of a change, they immediately ascribe it to a conspiracy.

Bambu Lab wanting to improve printer security is an obvious thing to anyone who has dealt with corporate network security in the past... today it is effectively an insecure toy that would only be deployed on black holed lab networks. They're trying to make it more modern via Mutual TLS authenticated file transfer rather than a cobbled together mix of FTP and MQTT.

How do normal paper printers work on such networks? From what I gather there is some standardised solution to that, wherein here bambu requires their own "connect" software, correct?

I think that big enterprises are full of old systems that are put on vans, vpns, conditional access rules etc., so it's weird to me that ftp is such a problem?

There is also a point in their tos: 7.4 - boils down to "your printer will block printing until you accept critical security patches" that directly contradicts the linked blog post

Normal paper printers concentrate print services to a Windows or Linux print server that authenticates users before they submit a job. All the direct ports on the printer are firewalled and restricted to the print server.

The main issue is that paper printers are a terrible legacy technology that didn't evolve much and are grandfathered into corporate security, whereas any new technology or new vendors have a much higher bar to pass before they're let on networks. Yes, there are many workarounds like VLANs, firewalls and black hole routes etc but they're usually treated as exceptions these days.

The TOS is meant to cover worst case scenarios, such as, the x509 certificates on the printer expire, or a major vulnerability is found. The printer is a hybrid cloud connected or LAN connected service and thus it's reasonable to warn users they need to update periodically because Bambu doesn't want to be exposed by for unpatched backdoor attacks etc. This is a similar issue with MacOS or Windows where you cant use your web browser securely after a few years of missing updates, or other connected devices where you must consent to automatic updates to use the device (Google Nest or Amazon Ring devices come to mind). Bambu is actually being better than most device companies in that they are just requiring this for crucial security updates and they don't require an internet connection: you can patch it via SD Card.

As a Prusa user who never used a Bambu Lab printer, what features am I missing out?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.