Bambu why is your networking so terrible?

Right because there’s absolutely no other way to ping for time ?

and for the rest (Microsoft, Amazon, Adobe, e-Bambu, etc) how does that work out (and justifies), in your opinion? Doesn’t really hold water the time sync argument does it?

Actually, no. NTP protocol is basically the one and only solution.

@drakko apple, amazon, microsoft, google run NTP servers. it’s probably trying to hit their NTP servers. I don’t see adobe on that list. and e.bambulab.com is clearly it trying to connect to bambu cloud.

though amazon or microsoft could be bambu cloud activity as well, hosted on Azure and AWS.

It 100% does not need to get out to check the time… nor should it be trying to connect to Bambu in LAN ONLY mode, hence the setting name “LAN Only Mode.”

There is also no good excuse for the printer to need NTP, or, for that matter, for you not to be able to manually enter the NTP information.

So, basically, this is exactly what the OP was complaining about…

…and let’s not kid ourselves. If the printer is still trying to occasionally hit e.bambulab.com, it’s probably not for NTP, but telemetry: case in point, it does not try to hit e.bambulab.com with the same frequency it attempts to hit the others. This implies that it’s attempting to do something else.

I haven’t taken it apart to figure that out, as I really don’t want to mess my printer up, and the H2D IS a really great printer.

I have it on LAN Only mode because it does NOT like have a Palo Alto Networks firewall scrubbing it’s traffic and preventing it from going ANYWHERE but the US/EU/JPN. The Bambu Slicer will not connect to the printer if it’s allowed to get out to the internet, but ports are blocked except 443 and the traffic is being actively scanned by an industrial network security appliance.

Put it on LAN Only mode, and then it fails to work as well; you can’t connect to the printer from Bambu Slicer if the printer can’t get out to the internet. (As per my post above…) …and it’s clear that the issue is not only NTP but that the printer in LAN Only is STILL trying to get to the Bambu cloud…

I totally get why Bambu doesn’t want you messing with the Laser version of the printer software stack, and so on. …but the network stuff is a a security issue.

You’re right it doesn’t need to use ntp to keep time, but it really should. Pool.ntp.org and it’s participants can be mostly trusted. This specific thing is benign.

You’re not wrong… however, if you had the ability to configure all of that in the printer interface, then you can give it your local NTP server. (Firewall IP address, etc.)

Bambu has even the IP settings locked down so that DHCP is your only option. With no options related to the network stack… such a gateway IP, subnet mask, NTP server, system name, DNS, etc.

Not to mention the ability to set the time manually…

Which again, you’d only do if you were trying to force someone to let a printer connect to the internet. Aside from laziness (and no one that created the H2D printer is lazy…), the only other explanation is attempting to get telemetry.

hey, genius I’M OP.

second: actually, there is good reason to use NTP. so users don’t have to whine about using their clock. NTP isn’t a security risk. also windows uses NTP, but you can manually configure time if you want to hate yourself.

you could bother to read everything i said too. hitting e.bambulab.com is probably trying to connect to cloud or to look for updated firmware.

just because I think they did a crappy job on their networking hardware doesn’t mean i’m going to validate your paranoia over basic pretty innocent network access patterns. i pulled up the stats on my mine from my network monitoring software and it looks like Bambu Cloud is being hosted on AWS btw.

Their cloud backend for their slicer/printer binding is like this:

Every printer serial number gets a message queue
Every user gets an auth token to S3 storage
You upload gcode to S3 in BambuSlicer
Events queue up to let the printer know its got a job and for bambu’s data warehouse to steal your model for AI training
Your printer downloads the gcode next time it polls it’s queue
S3 entry is deleted

Two decades ago we woulda called that an FTP service, but yknow

List of vulnerabilities exploited via NTP:

  • Code Execution Bypass
  • Privilege Escalation
  • Denial of Service
  • Information Leak

I’m sure there are other non-disclosed vulnerabilities.

Usually, it’s with the implementation of the NTP stack on a specific device that hasn’t been patched or updated in a significant amount of time.

Convenience is not an excuse for failure to take security seriously… some of us don’t want any of our intellectual property touching the Internet.

As your original post implies, not having any insight into how their networking stack works, or it being more modern in general… is part of this problem.

I also never said that the printer wasn’t absolutely fantastic… It’s just that it seems that they’re giving lip service to LAN Only. If they were truly owning that the things I said previously would be options.

Yup: it appears that the attempts to connect to AWS in Canada… At least for where I am in the United States… or so the packet trace seems to indicate.

Oh, and in so far as NTP is concerned… I have an NTP server in my home. So when I say the ability to put in NTP manually, I mean, pointed to my local on-premise NTP server. That server gets NTP from NIST.

lol imagine just blindly listing NTP vulnerabilities without actually understanding them and expecting someone who is a computer security and networking expert to agree with you

mkkaaaay. if you wanted to tear tinfoil hats you should go buy a prusa.

PS: if you want to redirect it to your local NTP just use firewall rules to force redirection

all I’m sayin’ is that if pool.ntp.org becomes comprimised as a wild attack vector, I am in good hands for remediation, because that includes about every damn computer on the planet and we all will be talking
/and talking with slightly skew clocks
//or was that slew
///ntp joke

It would look to be doing standard “is there an working internet connection or not” tests… hence why it is checking if some websites which are 99.9% guaranteed to be alive and up are responding.

Agreed.

Potentially incorrect. Security certificates have both a “valid from” and expiry date and time, thus the printer may need to know the current time in order to determine if the certificate is valid. If they are not needing it for that, then sure, it probably has no valid reason to not get it synced from Bambu Studio directly (for use in logging and timestamping time-lapses, etc).

Blaming the use of ntp is wild. I hate everything about bambu network, but NTP???

One reason for better wifi chip just fast… even if only 5-30seconds…if paying $2000 for printer insure 90% not going to mind extra $5-10 for better connection and future proof.

edit: nevermind misread. my bad

So you are saying that adding a $20 ethernet port in a $2000 dollar machine is going to raise the price so much it is gonna make a difference in a buyers decision? I doubt that seriously.Even with a markup the price might go up $30 bucks which at the $2K level is trivial.