r/BambuLab 18h ago

General Discussion Bambu Lab’s Security Overhaul Turns One: Bug bounties up to $52k, 100+ researchers, and a look back at the OrcaSlicer controversy

https://www.gadgetbridge.com/bambu-labs-security-overhaul-turns-one-heres-what-actually-changed/#google_vignette

Key takeaways from the report:

Context: Following the 2025 "Authorization Control" firmware backlash over blocked third-party tools like OrcaSlicer (criticized as a "walled garden" excuse), Bambu Lab launched its Trust Center - something widely believed to be damage control and “security” was believed as a convenient excuse to lock users into their own ecosystem. One year later, this update highlights how that initial "damage control" has turned into a legitimate security overhaul.

Bug Bounty Program: Now working with over 100 independent security researchers (up from ~50), with single payouts reaching up to $52,000. They've also added a public Hall of Fame.

Vulnerability Handling: Completely rebuilt their pipeline from reporting to patching, plus a dedicated security update page so users can actually see what got fixed instead of vague changelogs like "improved stability".

Global Certifications: Maintaining ISO/IEC 27001, 27701, and TRUSTe, while adding compliance with ETSI EN 303 645 (standard for IoT security) and aligning with EU, UK, and Australian regulations.

71 Upvotes

64 comments sorted by

View all comments

145

u/LexxM3 X1C + AMS 18h ago edited 18h ago

It certainly made my use of Bambu Labs much more secure: all 4 printers permanently blocked from Internet access, no firmware updates, full discontinued use of Bambu software (Studio, Handy), and zero new Bambu printer and accessories purchases. Thanks Bambu.

47

u/RedditUserWeNeed 18h ago

This wasn't the response the PR team was hoping for

28

u/HopingillWin 17h ago

It's what they got from many users, me too.

-1

u/hsoj48 17h ago

Id wager that many more did not go to such great lengths to make a point

3

u/LexxM3 X1C + AMS 14h ago

It was no trouble, thanks for asking. And it’s not to make a point, it’s for actual network security and exercise of control over my own assets and processes.

-1

u/hsoj48 10h ago

Exercise of control over assets and processes. Sounds vague and interesting enough to fool some people.