Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Bambu is patching a security issue.

This isn't a security fix. As a security protocol, it wouldn't pass any kind of security audit. A security fix would be something based on a per user credential, not on obscurity.

> Personally I don't want any device or application to send any old G-code to my printer.

Username/password over TLS would do that better than what Bambu Lab is proposing, as an extremely simplistic example.



And LAN-only mode should work without any external connections yet it looks like it'll require it for authentication. That defeats the whole idea of LAN-only!


> Username/password over TLS would do that better than what Bambu Lab is proposing

Already works that way and isn't affected by this update: https://wiki.bambulab.com/en/security-incidents-cloud-traffi..., https://github.com/Doridian/OpenBambuAPI/blob/main/mqtt.md#l...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: