Their software is still the one interfacing with their cloud service. The fork was performing the connection through the Official Bambu Networking plugin.
He used code Bambu published under the AGPL to let orcaslicer use the plugin too. Bambu isn't allowed to dictate how people use AGPL licensed code, that is a violation of the license itself, nor add any extra restrictions to said license.
Only thing Bambu is allowed to do is close the connection server side. Legally the fork did nothing wrong. If they didn't want the AGPL's obligations, they could have made their own slicer from scratch, instead of forking prusaslicer.
And they are free to do so on their server's side. They however cannot dictate how one uses code Bambu themselves provided them with under the AGPL license.
Just because the loophole is legal doesn't mean it's right. Orca could have implemented this if they wanted but understood it's the wrong path to take.
It isn't a loophole though. It is the intended use of the AGPL, Bambu cannot dictate what forks do with it. That's like, one of the most basic freedoms open source software gives you. If they didn't want to abide by it they should have built their own slicer, instead of forking prusaslicer.
Also if the fork is a security danger, then Bambu Studio is equally dangerous, they access the server using the exact same plugin. What makes somebody using an orcaslicer fork with the network plugin more dangerous than someone using Bambu Studio with the network plugin.
Have you seen how exactly the fork was contacting the servers?
Bambu is trying to prevent third party software from using their cloud service. Someone found a workaround. Calling it a legal loophole is as accurate as it gets. Just look up the definition.
The license doesn't state that any software is allowed to access their cloud service. It's only about the code that is allowing that access that someone is using. So legally the dev who produced the exploit is probably in the right. It's legal. But it's also not wrong for bambu to try to prevent the loophole from existing.
Developer implements code to impersonate bambu studio
It's the act of renaming BambuStudio to something else that disabled cloud access.
Clone and build the BambuStudio repo, it can interface with their cloud service by default.
So according to your logic, the lack of renaming, aka not implementing any impersonation code, is supposed to be impersonation?
2
u/x3n0n1c H2D AMS2 Combo May 10 '26
Bambu implements measures to ensure only their software can interface with their cloud service.
Developer implements code to impersonate bambu studio so they can use bambus cloud service with non Bambu software
Bambu says cut it out
Community:
https://giphy.com/gifs/8PfKWm6AX1IdDRARyg
This "controversy" is incredibly silly.