@fever_soft@real_OrcaSlicer Can you guys look into this? :) Would like to be sure bambu cant inject stuff into orcaslicer. Also a good reason to prioritize integrating that open source bambu networking plugin project https://t.co/7PcPTvOIdE
I looked at those slicers too...
CWE-494 isn't just a Creality issue. It is inherited directly from OrcaSlicer, and all the other vendor forks have it too. This means Bambu can inject its own code into all of these slicers. That might be a good reason to submit a PR to @real_OrcaSlicer adding integrity checks, but someone would have to maintain it...
What is unfortunate is that all these vendors forked OrcaSlicer, yet apparently none of them contributed anything back.
At the same time, they all modified the cloud opt-out / libbambu_networking behavior. Creality completely removed Stealth Mode from the UI. Elegoo commented out the control toggles. FlashForge left the option in the UI, but commented out and disabled the backend!!!, so the setting does nothing. Anycubic added its own networking stack, and the setting does not apply there.
Another interesting detail is that the official Anycubic package does not fully match the GitHub source code. It contains 13 additional binaries, and they also removed the Orca-branded models. 🙂
CrealityPrint has very aggressive telemetry. It sends more than 70 different events to a Chinese SaaS platform, Sensors Analytics / 神策, (IMHO) without clear consent. They claim the data is anonymous, but it includes permanent identifiers such as device_id and user_id, along with information about printed models, other printers, and much more. On top of that, the privacy dialog seems to almost never appear.
As for libbambu_networking (used by all vendors), the slicers expose the user's public IP address, the slicer itself, and its usage frequency to Bambu. Once a user logs into MakerWorld (I am not sure all users realize this is Bambu) it can link that to their identity, full printer information, what they print, and their slicer settings (amazing marketing source). Bambu can also silently push arbitrary code to your computer via the libbambu_networking update and execute it when the slicer launches.
@GrinnelliDesign Does 100% of the purchase go to your company through your store or is there some kind of revsplit with ED? Also is it not possible to get a steam key through this method in the future? Still salty about my experience with the f15e and how ED refused to help.
It's incredibly shocking the lengths people will go to defend corporations like they're a friend or care about you. When a user has a bad experience or wants better, its too common for people to put up a shield for the company rather than advocate for a fellow user. disappointing
@Cypherous@BambulabGlobal Shane please consider this. What does it cost you to stand up for my desire for a better experience? I am asking a company raking in millions of dollars to upload a zip file once every bunch of months to their website. It's not some insurmountable task or unreal expectation.
@BambulabGlobal Now lets imagine if someone kept up with the firmware page by posting the latest and historical firmware files for download. Like the X2D would be a nice add! :D https://t.co/qdYwWIBpBi
@BambulabGlobal how about getting on top of the firmware downloads pages and providing the most up to date firmware along with historical firmware for downloading for people who don't want to use the bambu app? Thanks
@Cypherous@BambulabGlobal I do not want to install nor use the app. If they're serious about not forcing people to use the ecosystem then they need to make some changes. I should be able to access historical firmware and the most up to date via firmware page.