This new auth system will make me sell my printers

I’m just watching everyone fall apart until the smoke clears and everyone realizes all is going to be fine.

Famous last words…

My life doesn’t revolve around 3D printers, they do what I want them to do. Read through the proposed update, don’t see anything that’s going to keep my printers from printing.

My life doesn’t revolve around my phone either. Yet if Apple tells me that, due to security reasons, I am no longer allowed to choose a provider and therefore must use Apple’s own service and only their service. I get suspicious.

Ok, I lied a bit there. I use my phone more than I care to admit… But you get the point :sweat_smile:

Let me know your price and I’ll pay shipping!!!

If my understanding of the last update is correct with this “developer mode” feature, I might be able to tolerate it (if I some day accidentally upgrade the firmware). Assuming nobody points out something I missed that would be a deal breaker.

Buying another BL printer remains off the table, though. Trust level doesn’t fall back into place so easily. Oh well.

Probably the only thing that’d repair the damage for me is something that would be considered drastic, like making all firmware source-available, and releasing anything else crucial for us to have full control over our hardware.

I won’t hold my breath.

Already happening.

BL seems to be in the gaslighting “don’t believe your lying eyes” and “you didn’t really read what you think you just read” mode.

Stop deflecting, obfuscating, wordsmithing, and BSing, BambuLab.

Until then, and until you reverse course completely on this “security” update, you won’t see another dime from me.

What timing; I just acquired a P1S, A1 Combo, and a bunch of filament last week. Luckily, I’m still within my return window to Micro Center and Bambu (14 days) which gives me time to think about my printer refresh with Prusa CORE One, and maybe a Creality. After reading/watching over a few viewpoints and standpoints from various channels, my biggest takeaway is the “security” reason behind locking out OrcaSlicer. Not to mention the “security” architecture is rudimentary at best…it’s a shame since many peers speak highly about these printers in terms of ease of use and quality.

a man with a beard is wearing a yellow hat and has the words i know right below him

Ooooooooh, the fun had already started before BBL pulled this stun.
Now it just need more people getting involved

I have one of their filament dryers, complete junk.
In the end repurposed a food dehydrator at 1/4 the cost and 200% the power.

I was just thinking of buy a A1 until I saw this stunt. I am very grateful I saw this before I purchased. I am big on open-source, people owning the things they bought, and as such freedom to do whatever you want with what you bought. If I bought this printer and saw that I would immediately have refunded.

You’re a bit late to the party, there were a couple of things that BambuLab backtracked on from the original announcement that started this whole debacle:

  • They announced upcoming changes to the X1 firmware (and P/A series to follow) which introduce an additional middleware that one must use to talk with their printers regardless of mode they’re running - this effectively breaks every 3rd party tool commonly used with their printers including Orca Slicer which is, arguably, used more than their own Bambu Studio (and for a good reason).
  • They said that they are working with 3rd party tool developers to address this, where we got back from Orca Slicer devs that they were downright denied to implement the new protocol (allegedly, BL did create a PR which embeds their Connector in Orca but that wasn’t available at the time)
  • BL TOS explicitly said (and still says) that your printing requests might be denied until a firmware update is applied - where BL in their follow-up tried to gaslight everybody that this is not the case
  • BL edited the original announcement to add that you don’t have to update your firmware (which kind-of contradicts the aforementioned TOS) - but then say goodbye to the promised 5 years of updates
  • The middleware itself wasn’t explained well leading to people wondering what all this ‘authorization’ means and leading to a very valid conclusion that their printers alongside with the said Connector will need to, at least occasionally, speak with BL servers to establish this authorization - this effectively means no real LAN-only mode
  • It was cleared up later (in posting the authorization pathway diagram and post-factum adding a so-called Developer Mode) that in LAN-only mode the printer will not have to speak with BL servers - but then this raises a valid question - how does then this new middleware improve security? (which it doesn’t)

This all happened in the span of 5 days so sure, the situation is a bit clearer now, but there are still many, many unanswered questions. All BL got out of this is a severely broken trust.

No matter how you slice it [ha!], this is both a PR and technological disaster - PR because they even to this day cannot come up with coherent message and seem to only do reactive damage control using gaslighting, vague promises and assurances (which do not work all that well when the trust is lost), and technological because everything we found out both from BambuLab’s own posts and disassembling of their new Connector screams: amateur hour. They’re literally attempting to pull security-through-obscurity, a very badly implemented one at that, and are alienating their loyal user base in the process without increasing their security whatsoever.

This whole disaster could’ve been easily mitigated with a ~$20k cybersec consultant fee. Of course, I’m still coming from the good-will argument that their goal here was to actually increase security, not to further tighten down control over the pathways to talk with their printers in the hope of putting everything through one funnel - and then figuring out how to monetize their control over that funnel.

Or even a much cheaper dinner with a couple of security expert / open source software friends… :face_with_hand_over_mouth: I mean, c’mon… even I could figure out a static private/public key pair you are gonna distribute with every copy of the middleware was a very bad idea … ffs… it should be no different to SSH keys … generate locally , transfer to printer, done. No central copy, no bambu servers, nada. Not that I’m saying the middleware was a good idea either… but still… another episode of “what were they thinking” :rofl: :man_facepalming:

I just bought a P1S and Panda Touch and have been very happy with both … until now. I definitely will NOT update the P1S firmware. If they try to force the update I will disconnect the printer from the internet. I can’t believe that Bambu Lab would do this with a new printer soon to drop. With so many good Bambu alternatives (often cheaper) why in the hell would you alienate the market? Hopefully they will see sense and reverse some of this. The next Bambu printer better be bloody good and reasonably priced or they will lose the market.

If by cheaper you mean Creality :face_vomiting:.
It’s a solid printer in terms or hardware, performance and cost.
Keep in LAN mode with no internet if you so wish or Prusa.

Bambulab has already pushed the earlier version to my printer. It seems that they did listen. Is my printer the only one that has been updated to the previous none Beta version?

See my post above This new auth system will make me sell my printers - #774 by GrahamGo

@AndiS @Olias @Unique_Letterhead Thanks!, but last night Bambulab pushed the option to “upgrade” from 01.08.03.00 to 01.08.02.00 I did it, and now everything (orcaslicer etc) works as before. So I am good again. Thanks Bambulab.

I love the security statement around LAN mode, that enabling this in LAN mode protects your printer from Malware that may be on other hosts the LAN already.

Because you know it wouldn’t be impossible for malware on your PC to open the new connect app and then use the unauthenticated API that provides to send “prints” that contain the gcode to do all the things that they are blocking. In this way if you think about it this method actually lowers security. (Currently only things with the LAN access code can talk to the printer, now there will be an unauthenticated proxy running on your PC that can)

Get a cheap Tapo_C100 IP camera like I did, works great.