OrcaSlicer - BambuLab // Legal threats from Bambu Lab?

The whole topic, situation, discussion, statement, everything - in a nutshell:


Quoting the news article here; for the full article, please click the link at the end. Please note that I am simply passing this information. I personally cannot verify its accuracy. Please note: This is not about the original Orca Slicer, but rather a fork - in simple terms, a parallel development.


Independent software developer Pawel Jarczak has voluntarily shuttered his popular “OrcaSlicer-BambuLab” project following legal threats from Bambu Lab, ending one man’s fight to restore direct control to the popular third-party slicer. Jarczak’s fork of OrcaSlicer would have allowed users to bypass Bambu Connect, a middleware application that severely limits OrcaSlicer’s access to remote printer functions in the name of security.

Jarczak said in a note on GitHub that Bambu Lab threatened him with a cease and desist letter and accused him of reverse engineering its software in order to impersonate Bambu Studio. He said he was also accused of violating Bambu’s Terms of Use and bypassing authorization control. He chose to voluntarily remove the software. He insists he did nothing wrong as his fork of Orca only used publicly available source code.



From another topic:

That’s exactly what open-source software and research are for - so that anyone can use them. This often leads to amazing new developments and a constant flow of fresh ideas. The expectation is simply that companies, too, will contribute to this effort - based on trust and a sense of morality.

It’s like a free buffet: as long as everyone takes only what they need and keeps putting something back, it works. But as soon as someone stops contributing and only takes, it stops working.

Remeshing isn’t the problem; in fact, it’s desired and called “fork.”


11 Likes

Jarczak’s fork of OrcaSlicer would have allowed users to bypass Bambu Connect, a middleware application that severely limits OrcaSlicer’s access to remote printer functions in the name of security).

Or said another way… Designed to circumvent the controls BBL places on its systems and services, so that an unapproved piece of software could access those systems and services same as an authentic BBL product.

Access to their servers is something they have a right to zealously protect. Done poorly, the implementation could bring the BBL systems to their knees.

Would this particular project have actually caused any problems for BBL? Not necessarily. But that question is completely dependent on the quality of the implementation, which is completely dependent on who’s doing the implementation. And being an open source project, once proof of concept has been demonstrated, anyone else could write their own version which might not be very good quality at all.

BBL has no way to control that risk except to deny any attempts without regard to the question of the quality of the implementation. Their network is “closed” by design, it’s a component of the BBL “ecosystem”. Part of the “value add” to their customers. They don’t want it open to the world for what should be obvious reasons.

If they wanted people to access it directly, they’d have published an API to enable it. So I have no problem with their aggressively protecting their IP assets. Someone’s project starts messing with server performance, we’ll all throw a fit for BBL allowing such a thing to happen.

6 Likes

I agree with you 100%, but on the other hand, we have to keep in mind that it’s good to draw attention to these topics because:

“Jarczak’s fork of OrcaSlicer would have allowed users to bypass Bambu Connect…”

It’s been known for… good question… many months now how to bypass Bambu Connect. It’s public knowledge and easily accessible. The details are available on GitHub projects. Bambu still hasn’t secured the system. I mean, Bambu Connect is still in beta - it’s been a year.

This raises the question: Is it the fault of the person who walks through the open door - or the person who has left their door open for months?

That aside, I think it’s a bit over the top - if it’s true - that legal action is being taken against the open-source community instead of finally securing their own system.

7 Likes

Its not 100 percent fault on either side.

I think the analogy is more of “is it the fault of the person who shared the code to the door or the person who set the code to 1-2-3-4”.

The developer is using an unintended method to bypass bambu connect, which opens up a security risk. But it is also Bambus fault for not finding that security risk in the first place. It makes sense why they would want to stop it.

I think that Bambu needs to give in and support a safe method to perform these tasks while keeping both sides happy. There will always be faults that are not noticed until someone takes advantage of it.

3 Likes

Everything is a nail to a lawyer who has a hammer, thats why you see thing like these standard C&Ds.

Reverse engineering to do things vendors dont want or intend has been going on for a long time, and this is pretty standard response I see from companies.

1 Like

Say it’s not so…. This is the same way IBM lost to Microsoft back in the day with DOS. Don’t get me wrong, I love the Bambu ecosystem but I’m all for allowing users to control their printer how they see fit. Look at Matt Armstrong and Bugatti debacle. Bugatti has egg on their face after Matt proved that he could rebuild a super car in a garage. People are going to buy the Bambu printers regardless. No need to throttle them because as you know, with competition, someone will come along and start eating the lunch you made… Ask OpenAI.

2 Likes

I’ll continue to buy Bambu printers. For me, one thing doesn’t rule out the other.

Nevertheless, I’d prefer it if Bambu collaborated with the open-source community. This does not mean that they should abandon their closed system. They should, of course, secure their own system, and I fear that will only happen if attention is drawn to such issues from all sides.

I just hope Bambu doesn’t take the same approach as Nintendo. In case anyone isn’t familiar with that: They’d rather sue than fix security vulnerabilities.

2 Likes

Bambu Lab introduced its own optional plugin, which is downloaded during use of the program. That plugin is under a closed license - but introducing it literally violated the free AGPL license that Bambu Studio inherited from PrusaSlicer, and they were obligated to maintain that license.

The developer worked exclusively with AGPL code.

Maybe the ToS of that plugin does not allow using the plugin in other programs.

But the AGPL allows the code to be used freely and modified in literally any direction.

So Bambu Lab literally violated that license.

From what I saw in the developer’s code, he used literally 100% code that is already in Bambu Studio and is licensed under the AGPL! So this is absurd!

How can you support this kind of behavior…

It is like supporting stronger people who beat weaker people - weaker people who, on top of that, are right…

It is as if you were openly saying: “I will defend the stronger one because if someone attacks me, at least they will defend me… and besides, I am not surprised they objected, because they did not like what the weaker one was doing.”

Very shameful behavior.

15 Likes

I mean, of course, that Bambu Lab’s behavior is absurd in this case, and no one should support violating the licenses of open-source programs on which they built their money-making empire.

The strangest thing is that this Linux plugin still works and has not been disabled by Bambu Lab - so it clearly shows that money is more important than user security. And everyone else will simply be threatened with lawsuits…

4 Likes

Dear BBL developers RESPECT THE AGPL LICENSE or develop your own slicer from the scratch.

11 Likes

Who supports that kind of behaviour?


I think comparing it to real violence and bullying is a rather strange approach. In the worst-case scenario, you can’t prevent violence and bullying, but you can choose not to buy a printer.

Actually, your comment was really good and showed real expertise, until you somehow took a strange turn. If you take a look around the forum, you’ll notice that Bambu gets a lot of criticism. Bambu also faces a lot of criticism outside the forum - as seen in the news article - also from the open-source community.


So let me ask again: Who supports this kind of behavior? Who do you mean?

2 Likes

Bambus corporate salarymen sure seem to love it! The hubris of a company built on open source software… a tale as old as … transistors…

4 Likes

I think Bambu’s actions are about IP, not the actual source code.

There are many ways to skin the cat, but Bambu owns the cat and they don’t care how creative a particular skinner is… they just don’t want anyone skinning their cat. :slight_smile:

2 Likes

@RetroSharky

So, still being rather new to the 3D printer aspect of this, I have a blind spot here.

I’m going to ask a noob question.

Can I use a 3d party slicer to connect to my Bambu A1 and have it print? Or is that what this is all about?

That’s a bit off-topic, so please check out this thread instead. Simply because that’s the best place for the question. Because you’ll get a faster help with your question.

In short: Yes. but please hop over to the other thread. Thanks :heart:

2 Likes

After answering to this topic i started wondering that some time ago i had tested it and so i went and search on my server. And yep, there it was. At least i have a copy of the last “release”.

I’ll see if i can test it during the weekend or with some more time, during the week. Will fire up my A1 that is since months in a box and test it there with an account.

in the meantime, i am already preparing some form of contact with the developer. I hope he answers to it :crossed_fingers:

1 Like

by doing this, sooner or later someone from the open source public netiquette will start all the bambulabs at the same time to highlight the bugs :joy:

It’s always been:

Bugtracker


Specifically RFID:


Bambu Connect’s Authentication X.509 Certificate And Private Key Extracted:

[I won’t post the link; just use Google]

As an alternative, I can post the Bambu Reddit thread, which doesn’t explain in detail how to do it, but does inform Bambu Lab - a year ago. He even suggested collaborating with Bambu Lab.

https://www.reddit.com/r/BambuLab/comments/1i4fw74/found_a_way_to_bypass_new_bambu_auth_issue/


By the way, as far as the key is concerned, it was in January 2025 that people figured out how to bypass Bambu Connect - and they still know how to do it today.

Well, it’s always been this way - even now, bugs are made public.

2 Likes

Rossmann just posted a video about it.

No full picture as always but willing to speak to dev so fulu can defend him. Encourages dev get in touch. Lets see where this goes.

5 Likes

I am absolutely appalled by Bambu here, more enshittification for us all to deal with, for no real purpose. If bambu want to continue being successful they will stop locking down their sh*t and make it open source. Internal servers needing protection is one thing, but legal action like this is wholly inappropriate.

I recently heard a great statement in relation to Steam’s monopoly in gaming that is applicable here. “Steam is a monopoly by choice”. Whilst many competitors have risen to fight steam, it has remained the undisputed king of video game sales, because they offer by far the best services and transparency for their customers. They contribute to upstream open source projects and all around keep the consumer at heart. Bambu have made 3d printing accessible, but if they make the choice to limit their product like this, then they are destroying their own business model. The moment the larger tinkerer community move away to competitors platforms, only a few years or so, so will the average user, because bambu’s competitors will have community support, which bambu will have essentially given away. There is no replacing community support or community expertise. I didn’t buy bambu for their software, it’s a nice to have, that’s it. Don’t do this Bambu, this is bad press, and erodes community trust which is essential to your business model.

This makes me seriously consider disconnecting my printer from the internet to prevent this from getting worse, and changing the manufacturer of my next printer.

6 Likes