Below is an open letter, that is, an answer to the now closed (or reopened) support ticket regarding this issue.
Reply to Bambu Labs ticket US221126800001
I’m not sure if you’re openly dishonest here or just don’t understand the licensing in your reply on . The GPL explicitly says that linking to software licensed under (A)GPL, makes your software a derivated work, meaning that also must be GPL. This is why LGPL (former Library GPL, now Lesser GPL) was created, to allow people to write libraries with a GPL-like license, but still allow them to be used with closed software. AGPL is even stricter than GPL and does not allow linking to anything else and if that is done, that “anything else” is also GPL and you, as a distributor of that software, must give out the source code to whomever you’ve distributed the binaries. The FSF vs Cisco case shows this very well. Linksys, later obtained by Cisco, had taken the Linux kernel and some tools and ported it to their little router, the WRT54G. This became highly popular and people found it was running Linux, which was fun. Then they found the kernel reported “tainted”, meaning it had modules that were closed source. The public asked for the source code for these, which was denied, because that was “company property”. The public replied and said “no, it’s GPL since you’re linking it together, read the license”, but Cisco refused. FSF too them to court and won.
The files used by bambu studio, are (on a mac) libBambuSource.dylib, libbambu_networking.dylib and liblive555.dylib. Files with similar names exist on Windows (.dll) and Linux (.so). These are libraries, not executable programs. You can, on some OSes, make a library executable, but that doesn’t work for these (I tried). I looked through the source code, and it looks like you’re loading the networking module with netwoking_module = dlopen( library.c_str(), RTLD_LAZY); on line src/slic3r/Utils/NetworkAgent.cpp. That is loading and linking to a shared library, effectively breaking AGPL and GPL.
You told me last time that you don’t own the code for this software, and thus cannot distribute it. This is irrelevant, since you are the ones distributing the compiled product and linking to it, so you are responsible for distributing also the code.
So, please, without further ado, please let us have the code this time.
roy
]]>Yes, the log file is encrypted and not open to the public. I can give feedback to relevant guys to see if some part of it can be made public. But I think if there is such a plan, we should announce it, please key an eye on our updates. I will resolve this ticket.
They have not replied to my question on why this was so, but apparently just ignored it.
As one that has worke with linux systems for around 25 years, I prefer open systems and although it is hard sometimes with giants like Dell or the likes, Bambu does its best to keep users like me from purchasing their printers. I hope they realise that one day.
]]>want to comment on some misunderstandings here
“The printer doesn’t have an ethernet port and wifi isn’t secure with PSK”
It is important to point out that this statement is not entirely accurate as the printer supports Wi-Fi security protocols, including WPA/WPA2-PSK.If the WLAN is protected by WPA/WPA2-PSK, which is generally the default security protection nowadays on wireless routers, the WLAN connection should be relatively safe.
What I wrote in the article, was that anyone with the known PSK, that is, anyone connected to the average access point used, will be on the same network. That the network is encrypted with WPA, still means they all have the same key, so once logged into the network, it’s all cleartext between clients on that network. Still – it’s better than nothing, but the best thing is to encrypt everything.
So, they summerise
The security of the LAN mode depends on the security of the WLAN at the moment. It is vulnerable if the LAN is not properly secured. We will work on an improvement for this by January 2023 and we will share an update when that becomes available.
The HTTP connection to the cloud vulnerabilitty has now been fixed.
This is good! Kudos to Bambu lab for fixing this quickly!
The cleartext keyID is a misunderstanding.
My apologies.
So, the WAN connection is a bit safer, and the LAN connection works, ish. All we now need if we want to use this in LAN mode, is a working camera.
roy
]]>The Bambu Lab X1-Carbon with AMS (Automatic Material System) is a very good and very fast 3D printer with all the automatic features you can dream of and a bit more. If you search youtube, you’ll find countless of videos about it and how awesome it is and so on. But as always, there’s the flipside…
– Noise! The printer’s stepper drivers are noisy. That the rest of the printer also makes a lot of noise, is understandable with the speed it’s running, but we’ve had TMC2209 drivers a long time now, which are very silent indeed. Bambu has chosen to use their own drivers, possibly because of price or availability.
– The hotend thermistor is the same glass bead type as used by Creality and a lot more. These work well, but only until they break. When they do, they usually break the thin single filament wires going the last 2cm or so into the glass bead. Since these are aluminium wires, they are practically impossible to fix, so you’ll need to get a new thermistor. This could have been fixed with a barrel-like thermistor. I don’t know what sort of thermistor the bed uses, but it wouldn’t surprise me if it were the same.
– The hotend and nozzle are integrated, so the amount of nozzles available, is greatly reduced. As far as I know, there is no way to use high-flow nozzles like those from 3dsolex and Bondtech CHT (which are licensed from 3dsolex, who holds the patent for these). They are, however, decently priced, unless you compare them to the dollar-a-dozen-packs from China.
I ran an nmap sweep of the printer, I found it listens to ports 21 and 3000. The former is FTP and the latter is unknown (pptp?). FTP made me wonder. I connected with an FTP client and could verify it was a vsFTP server, a popular FTP server on *nix platforms. BambuStudio uses FTP and MQTT (the latter also cleartext) to communicate to the printer if in LAN mode. An attacker can pick up the username and password easily, log in and download videos and other files and also delete these from the printer. She may also (possibly, not tested) inject MQTT, which is used to control everything, which is worse. The FTP protocol is really outdated and has been for 10+ years. FTPS (that is, FTP with SSL/TLS) is an alternative, but impossible to use over NAT. SFTP (SSHs FTP version) is well proven and secure. The same applies to HTTPS. Sniffing the traffic between BambuStudio and the Bambu printer with wireshark, shows its login and password, which is as expected but indeed not a good idea. Some may argue that it should be secure-ish on a closed LAN, but then, the printer doesn’t have an ethernet port and wifi isn’t secure with PSK. If you have the key, it’s all cleartext unless it’s encrypted at higer leverls. Insecure protocols like FTP or telnet and the likes, are old and obsolete and should not be used in 2022.
The printer is more or less tied to using a cloud service. This is luckily local to the region you’re in, so since I’m in Norway, my printer speaks to a server in Frankfurt am Main, Germany. This is all nice until you look at the traffic, again with wireshark. BambuStudio opens a connection to the server over HTTP, meaning it’s all cleartext. The only authentication is OSSAccessKeyId=xxx in the URL, again, all in cleartext. This is completely insane, since anyone between the client (BambuStudio) and the server (somewhere in the cloud) can read this and the data sent, including opening up new HTTP sessions to the same server. HTTPS would’t have cost bambu anything, perhaps expcept they want a better certificate than those from Letsencrypt, but still, that’s not a lot.
It’s a good printer, by all means, but the total lack of encryption and use of archaic protocols like FTP, is alarming. I have seen a lot of bad equipment with similar issues during my >25 years in IT, but it has mostly been limited to PDUs and similar that can be easily isolated on their own network so that noone can sniff or alter the traffic. This cannot be done with the Bambu system, since it speaks to a cloud service and depends on this. The temporary solution to this, is to disconnect from the cloud completely, by using LAN mode on the printer. That way, you will have to setup the printer in BambuStudio again and you’ll lose all support for the Bambu Handy mobile app. You will also lose video support, which is possibly worse. The printer will still transmit data in cleartext, but only readable for those on the same network. Also, the printer will only be available on the local network to which it is connected, since it relies on mDNS, which is blocked in most routers. I have not found a way to manually add a printer to BambuStudio by its IP address.
Update 2022-11-24
Bambu lab replied to the bug report I sent them, along with the link to this blogpost and they wrote:
We appreciate all the feedback shared, and we want to assure you that our team is already working on improving the security of the printer network connection. At the moment I can’t give you an exact date for when the changes will come, but we are working on it.
At the same time, we will be sharing more information about this in a dedicated post. I will update the ticket when that happens.
Update 2022-11-25
Bambu replied quickly and I have linked to their post and my comments on this blogpost
]]>Så vær så snill – uansett hvor stor kjendisfaktor dere mener Listhaug har, legg bånd på dere.
Takk
]]>Kjøttet i bunnen som hadde fått putre i vannet, var godt – det smakte sånn som det skulle. Det på toppen som blei dampa, var helt ødelagt og smakte omtrent som pinnekjøtt tilberedt av en skotte fra søndre Islay, ikke helt hvordan det skulle være. Så om røkt pinnekjøtt, i hvert fall “eldhusrøkt” eller tilsvarende: Ikke kjøp det – det smaker høgg, er seigt og egner seg mer for ei sulten bikkje, ei skjære eller en måse.
Men – alt håp er ikke ute. Har du eller noen likevel kjøpt det og etter det som skulle ha vært en flott middag, redd deg ut av det ved å følge Hellstrøm: Kok kjøttet eller la det i det minste trekke – gi det væske og liv og smak, så blir nok både du og gjestene litt mer fornøyd. Det hjelper sikkert med en god grønnsaksbuljong, men det er ikke sikkert det er nødvendig. Poenget er jo å få ut røyksmaken og få inn fuktighet. Etter en times tid med koking, kan det bli ganske godt. Har du allerede dampa det, ikke noe problem, men ikke kok det for hardt. Det holder å la det trekke.
God apetitt og god etterjul!
]]>Jotta funker nå også på Linux, med Duplicati som klient. Denne fungerer på de fleste plattformer, ikke bare Linux. Hastigheten er ikke forbløffende høy, men jeg får 10-30Mbps opp dit. Hvor mye som er begrenset i klienten eller fra jotta sin del, veit jeg ikke, men jeg gjetter at mye ligger hos jotta. Uansett en god løsning for mange.
Har du ikke lurt på hvorfor ting heter det det heter? Hva er Rødtvet, eller Makrellbekken? Jeg plukka opp denne boka i dag på biblioteket, og den begynner med et flott utgangspunkt – dog ikke i Oslo, men Nesoddtangen. Resten av boka er en fornøyelig reise mellom diverse stedsnavn og deres etymologi dvs språklig opprinnelse. Flott bok!
Tidlig i oslohistoriens morgen stir du og jeg oppe på det som en gang skal bli kalt Ekeberg.Vi ser over på det lange landet som har kommet til syne bak de store øyene. «ET NES!» sier du og peker. «Ja,» sier jeg, «det er NES!» og derved har vi navngitt det nye landet NES, slik mange steder i landet blir kalt.
Etter noen hundre år stir vi der igjen og skuer ut på NES. Ingen av oss husker lenger hva navnet betyr. «Se!» sier jeg, «NES er jo en odde, en NESODDE!» Og ganske snart begynner vi å kalle landet for NESODDEN.
Atter noen hundre år går, og på en stopp oppe på Eikaberget står vi og beundrer Nesodden, et navn vi for lengst har glemt hva egentlig betyr. Derfor peke r du ivrig: «Se! Nesodden er jo en tange! En NESODDENTANGE!». Uten tanke for at de tre ordene betyr det samme, har et nytt navn blitt til: NESODDTANGEN.
Men hva tenker vi neste gang vi står der,når det tredobbelte navnet har festnet seg som et skikkelig egennavn? Kanskje at landet der ute former en spiss? Vil vi da stå og se på NESODDTANGSPISSEN?
]]>Vi mennesker er som kjent oppbygd av naturlige, kjemiske midler, slik man finner i naturen. Disse fungerer sammen i en symbiose ikke ulikt det vi finner i planteriket. Vi består av proteiner og fett, vi har hjelpebakterier og hjelpesopp, og andre hjelpere som støtter vårt livs vei framover. Vi ble til slik siden det var det beste. Darwin beskrev det godt i sine skriverier om hvordan det dårlige skilles fra det gode, på naturlig vis. Her fungerer altså naturen perfekt, som beskrevet.
Autisme er, som mange vet, en genetisk sinnslidelse. Den fører til at man føres bort fra det sosiale og inn i det teknokratiske univers, der bare matematikk, fysikk og biologi gir leveevne. Slike lidelser ble tidligere behandlet av fagfolk, men regnes i dag for å være nærmest normale. Noen forfekter dem til og med med superlativer. De gener som ble forstyrret for at noe slikt skulle kunne skje, vet jeg ikke ord om, men her må det være utenforstående makter som må være årsaken.
Tilbake til nevnte artikkel, det er altså 18 gener som er koblet til autismens styggedom og dermed er det altså ikke vår feil. Vi ble bare født sånn. Likevel vet vi at tilførsel av farlige kjemikalier via vaksiner og tilsvarende, utgjøre en trussel mot det edle og rene mennesket. Skolevitenskapen gjør som den pleier, de finner noen kjemikalier som ser ut til å virke, og prøver dem ut på intetanende skolebarn for best mulig å prøve å holde styggedom i sjakk.
Vi vet at vaksiner fører til autisme og vi nyere forskning peker også mot at grunnen til dette, er vannets hukommelse. Vi vet fra homøopatien at vann husker sine tidligere stadier, fra det blir drukket til det finner veien til elven. I løpet av denne veien, må det gjennom deg, og i løpet av den ferden både tar det og gir det kunnskap. Vannet husker en tilstand om dårlige gener, men glemmer det. Det er bare traumen av kjemien fra vaksinen som får det til å huske dette igjen, det vi kaller vann-traume, som får vannet til å bringe dette tilbake til kroppene våre og dermed ta med seg det genetiske om autisme og gjenintrodusere det.
Vi må ikke tillate denne form for vanntraume. Vi må ikke det! Det handler om våre barn og barnebarn!
PS: Hvis du ikke fikk med deg ironien/sarkasmen i innlegget, les det én gang til, denne gangen i visshet på at jeg, artikkelforfatter, har god tiltro til skolemedisinen og vaksiner.
]]>