This new auth system will make me sell my printers

Said the CEO of any billion dollar company

Please enlighten us on the “proper interpretation” instead of slinging insults.
People will be more likely to listen :wink:

  • EULA (End User License Agreements): Companies can include clauses in their licensing agreements that grant them the right to modify or remove features, particularly if safety concerns are cited. Such agreements must be clear and fair to be enforceable.
  • Magnuson-Moss Warranty Act: This law governs warranties and can provide protection against claims from customers, as long as the company operates within the terms of the warranty and takes actions in the consumer’s best interest.
  • Product Liability Protection: If a feature presents a safety risk that could cause harm, companies can rely on safety standards and regulations from agencies such as the Consumer Product Safety Commission (CPSC) to justify the removal and mitigate legal risks.
  • DMCA (Digital Millennium Copyright Act): Under Section 1201, companies may sometimes claim that changes are necessary to ensure the product’s safety and to protect intellectual property rights, particularly for digital products.
  • Common Law Principles: General legal principles can support companies taking action to prevent harm or safety issues. Courts tend to protect companies acting in good faith to reduce risks to consumers.

The first sale doctrine, as outlined in 17 U.S. Code § 109, safeguards consumers’ rights to use, resell, or transfer legally purchased products without interference from the manufacturer. However, this protection pertains specifically to ownership rights and does not explicitly regulate a manufacturer’s ability to modify or disable product features after sale.

In cases where a company removes a feature due to safety concerns, 17 U.S. Code § 109 remains applicable in ensuring that the customer retains ownership of the product despite any changes. While the company cannot reclaim the product or impose restrictions on its general use without the owner’s consent, modifications—such as the removal of unsafe features—are not necessarily in violation of this law if such actions are justified under other legal frameworks, including liability laws, public safety regulations, or provisions outlined in End User License Agreements (EULAs).

In summary, while 17 U.S. Code § 109 limits manufacturers’ control over how a product is used after it has been sold, it does not preclude them from implementing necessary changes to address safety concerns or ensure legal compliance, provided these modifications are supported by applicable laws or contractual agreements.

Bambu doesn’t care – they already have your money.

Do you avoid 2FA on your bank account? If so, then you aren’t as smart as you think you are. What Bambu is doing for the MakerWorld web site is no different from what your bank is doing. The only reason they do email instead of with SMS is because they don’t have your phone number.

As for “stealing cookies,” you clearly don’t know how the authentication with cookies works, but you do you, ok?

My kid’s high school robotics team has two X1C, two P1S and an A1 mini. The team funding source bought one of the Ps, and parents bought the others. (Obviously the parents are on the higher end of the income scale.)

And these kids really know how to operate the machines. They’re aces with Fusion360.

I see other teams with 3D printers at the First Tech Challenge robotics competitions, and all of the machines are Bambu.

Same here.

If they force me i’ll start with other brands of printers.

But the kids didn’t, which was my point. It’s great to see children using 3D printers, as it provides an amazing opportunity for them to explore their creativity and sometimes even go beyond what they imagined possible. My daughter often sketches her ideas on paper, and I transfer them into 3D models. From there, we decide whether to use a CNC machine or a 3D printer, depending on what’s most suitable for the project.

I hope those who purchased the printers took the time to carefully read all the fine print beforehand to avoid any unpleasant surprises later. It’s always a good idea to fully understand the terms and conditions to ensure there are no unexpected limitations or issues down the line.

Let’s say, in theory, that “safety” applies here (it doesn’t btw), how would you explain this answer bambu spokes person gave:

There are industry-strandard secure authentication methods that ensure security without the need of any proprietary middleman authentication app. Bambu rejected such methods.

This reasoning is invalid. It’s a consumer trap: There’s shady stuff in the TOS? “Oh don’t worry, that’s just legal bs for future, company won’t go evil!” Company does stupid stuff like this? “Oh, you didn’t read TOS, did you? It’s on you!”

Once again, you were aware that you purchased a printer that is not open source. If you’re not satisfied with closed-source printers, it’s best to avoid buying them, regardless of how good the hardware may be.

Making threats to blow up, burn, or otherwise destroy your printer is so counterproductive to the issue at hand—especially when the function hasn’t even been implemented yet—that it’s frankly laughable.

But playing gatekeeper for no reason, all day long, is super productive.

OK, so… any sane calls, by people who passed Network Security 101, for bambu to go with industry-standard practices, that are MORE SECURE and results in no downside to end users, are what? “proprietary stuff, you get no say”?

I posted this on another similar thread, but it applies here too…

Just let us be…

I acknowledge that I’ve contributed to the tone of aggression in this discussion, but my reaction was influenced by how many of you responded when I pointed out that LAN mode isn’t entirely safe either.

Instead of resorting to threats about burning, destroying, or otherwise discarding your printer, let’s recognize the truth: the hardware is undeniably good—better than just good, in fact—and I’m sure many of you would like to continue using it in the future.

As some have already done, provide Bambu Lab with constructive proof of better ways to secure the connection to the printer, Bambu Lab Studio, and MakerWorld. Complaining alone won’t lead to change, at least not in a meaningful or productive way.

This entire debate started with me trying to highlight that a 32-bit access key with unlimited login attempts is equivalent to having virtually no security at all.

So, let’s move past the whining and threats and focus on being constructive. Send well-thought-out suggestions to their support team and keep those tickets active until your points are heard.

Normally, this forum is a fantastic space for discussion, but this topic has turned it unnecessarily toxic—and we don’t need that, do we?

Someone else as clueless about security as Bamabu labs.

And so the irritation game continues—how about we set that aside and move on to something more productive?

OK. Something more productive: There are hundreds if not thousands cloud security experts, that can be hired to fix their stated cloud issues. I highly recommend bambu to pay consultation fees (or make that a team and hire them full time) and have cloud problem solved by experts. This solves all stated cloud issues. Phisical printer safety, if they are worried about that, is solved via firmware controlls making sure motors and heaters do not go outside of the specified ranges. I dunno about them, but my moving projects despite being very craptacular, have endstop switches in case I forget to code range the range (that happened ONCE). If I made anything that heat up, I’d made sure that it had thermal fuse, so it didn’t catch on fire in case of thermal problems… Also - as stated in the article, there exists already industry standard more secure ways to secure printer<->slicer communications, so make sure to use them.

Constructive and productive feedback. TADA!

I’m not a security expert, but the guy in the youtube video I linked to above impressed me as someone who probably knew what he was talking about when he said that 1. Bambu’s security patch wasn’t delivering much, if any, actual security and 2. that if it had been done properly, the shortfalls people are complaining about would never have happened. And he doesn’t just say this, he explains why and essentially proves it. Well, is he wrong? I’ve not heard anyone here say that he is.

So, assuming he’s right, I don’t know why anyone would find the need to defend or excuse what he alleges is incompetent software engineering by saying you have the option not to use it. I’d rather use it, and so I’d rather it be done right.

He gives the analogy of “Gee, we couldn’t make the seatbelts that are designed to protect you work, so we’re going to remove the requirement for you to use seatbelts. Just don’t use them. Problem solved. Now move along, nothing to see here.”

Let me see if I understand your main points.

1-People who think differently than you do are “militant complainers” and engaged in an “aggressive war.”

2-Hey, let’s all be friends!

So this is your response? A personal attack on Americans? No wonder you’re amassing some much good will in this community.