you are viewing a single comment's thread
view the rest of the comments
[–] 138 points 2 months ago (2 children)

I'm surprised this isn't a bigger part of the story.

Bambu's authentication is just the client saying "I am Bambu Studio". The server completely trusts that with no additional authentication.

It's like setting up a website with a user login, and if someone puts in "admin" in the username field without a password, the system says "sounds good" and lets you in. And then the website owners getting mad that someone hacked their system.

Blatant incompetence. I can't believe they're using their stupidity as an argument.

  • source
  • hideshow 4 child comments
  • [–] 2 points 2 months ago (2 children)

    It’s like setting up a website with a user login, and if someone puts in “admin” in the username field without a password, the system says “sounds good” and lets you in. And then the website owners getting mad that someone hacked their system.

    Blatant incompetence. I can’t believe they’re using their stupidity as an argument.

    You are right, but technically speaking it would be a crime anyway. It is not that if you leave your door open then entering without permissione is not a crime.
    While Bambu Labs obviously is trying to implement some sort of subscribtion model, and they are doing it in a bad faith way, for shitty as the authentication model is it is not an authorization to enter freely.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 6 points 2 months ago

    You are right, but technically speaking it would be a crime anyway. It is not that if you leave your door open then entering without permissione is not a crime.

    Leaving the door open and people walking in isn't a crime, unless explicitly mentioned otherwise (may vary on jurisdiction), but faking a login is a lot less denyable than using the same User-Agent as some software (famously a bad marker for authentication).

  • source
  • parent