Cloud load balancer snafu leads to 3D printer user printing on a stranger's kit
- Reference: 1629467230
- News link: https://www.theregister.co.uk/2021/08/20/3d_printer_spaghetti_detectives_cloud_snafu/
- Source link:
Just over 70 of The Spaghetti Detective's users were able to control others' devices as a result – something the service said it doesn't normally allow to happen.
"I made a stupid mistake last night," wrote the founder of the platform, Kenneth Jiang, in an [1]analysis of what went wrong.
[2]
"When I went through the load-balancer reconfiguration, I made a mistake by missing a configuration to let the load balancer pass the public IP address of the connecting client to the backend TSD server. Instead, the load-balancer would just pass its own IP address to the server," he said.
[3]
[4]
"As a result, the server got the same IP address for the users who happened to be connecting their printer to TSD at the same time. The server thought they were on the same local network, and hence allowed them to link each other's printer!"
Jiang added that his team had been "notified of a case in which a user started a print on someone else's printer" – and linked through to a Reddit post where someone had used a stranger's printer to print the words: "TSD is not secure/ I randomly connected /sorry had to inform u."
[5]
Seventy-three users tried to link their printers to The Spaghetti Detective accounts during the lifetime of the config error. The service works through an auto-discovery feature for linking printers to accounts, which Jiang explained as working by detecting printers that have the same IP address as the user. This procedure appears to serve as an authentication measure, a design feature that seems unwise. Spoofing IP addresses is an attack technique as old as the hills.
Affected users were informed by TSD, said Jiang, who added that secure tokens for their printers had been disabled so that "only the people who have physical access to that printer" can start to remotely control it again. An update was pushed within six hours of the load-balancer config snafu first happening, 90 minutes after someone noticed other users' printers were visible in his account.
[6]Another 3D printer? Oh, stop it, you're killing us. Perhaps literally: Fears over ultrafine dust
[7]Buy a household 3D printer, it'll pay for itself in months!
[8]Scottish rocketeers Orbex commission Europe's largest industrial 3D printer to crank out 35 engines a year
[9]Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines
The Spaghetti Detective is a platform that gives 3D printer owners peace of mind by, so it says, using "AI" to "intervene and catch failures early" during the 3D printing process. Its name refers to a side-effect of 3D printing going wrong, where a time-consuming print may result in random strands and tendrils of plastic filament ending up splurged over the project.
A 3D-printing craftsman told The Register the scope for mischief with a 3D printer would be "fairly limited" as the devices "tend to be fairly safe."
"The most dangerous thing is the potential for fire," he said. "There are temperature sensors that built in for regulation, and these will cause the printer's software to shut down the heaters if they overtemp."
[10]
Separately, last year, the appropriately named infosec biz Coalfire discovered a way of tampering with Flashforge 3D printer firmware updates to bypass thermal limits. Among other issues Coalfire pointed out was the [11]apparent lack of signing for firmware updates , meaning anyone could install any binary to the device. ®
Get our [12]Tech Resources
[1] https://www.thespaghettidetective.com/blog/2021/08/19/what-happened-last-night/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YR-Rt3wwlKkJBIhczPYRnwAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR-Rt3wwlKkJBIhczPYRnwAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YR-Rt3wwlKkJBIhczPYRnwAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR-Rt3wwlKkJBIhczPYRnwAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2018/11/13/3d_printer_toxins/
[7] https://www.theregister.com/2013/08/02/household_3d_printer_could_pay_for_itself_in_just_four_months/
[8] https://www.theregister.com/2021/02/24/orbex_3d_printing/
[9] https://www.theregister.com/2020/07/31/3d_printer_fire_firmware_hacks/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YR-Rt3wwlKkJBIhczPYRnwAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2020/07/31/3d_printer_fire_firmware_hacks/
[12] https://whitepapers.theregister.com/
Even with DRM wouldnt be difficult to swap the controller board out for something friendlier, there are only so many ways you can connect stepper motors and thermo-couples...
And given the meta hobby of pissing about with your 3d printer to get it to work as advertised i doubt a board swap would deter many hobbyists
Using the IP address for authentication and authorization like that seems like a slightly hazardous plan to me. Ignoring the idea of deliberately spoofing IP addresses, there's the fact that CGNAT is deployed in the wild. This means we already see public IP addresses shared between different people as a matter of course. We should expect the use of CGNAT will be expanding every year in the future as IPv4 address space gets more expensive.
Its a problem with makers in my opinion, shun whats come before reinvent at every turn and cut corners through ignorance (there are some very good ones, i my self am a self described maker, but some of the dangerous crap wiring, crap design and wilful disregard of safety features has soured my opinion)
Double whammy of that when you combine cloud with makers, relying on IP just reinforces my opinion that they "know enough to be dangerous"
Again if makers used real tools or bothered to understand the 40 odd years of automated Design Rule Checks and CNC and CAD in general 99% of failed 3d prints could be avoided, most of the time it comes down to forgetting to cut the feed to the extruder and moving or just not understanding the tolerances of the machine your using, million and one ways of detecting both with no need to invoke the "give me money" buzzword of AI, but rather than invest in the makers experience the software suppliers instead tries and hides necessary complexity so that people can cling to the 2012 dream of extruded plastic somehow being a startrek replicator and presenting a big pastel coloured print button
Not so much a problem with "Makers" as such, I have a 3d printer churning away quite happily.
However I use a VPN connection back into my home network if I want to check on things when I am away. The issue is more Joe public and "You can do this using the cloud".
Someone brings up TSD as a remote monitoring tool at least once a week on various 3d printing forums & it's about 70% "It's great, I love it" to 30% "Use a vpn, this sh*t isn't secure"
I fully expect this story to return here as a "Who Me?" in a few years time with Kenneth Jiang's name Regomised to Shirley or something equally inappropriate!
OK, at least that "cloud" system in place is there for a reason.
I was half expecting to find out that many 3D printers have strict DRM that connect to the vendors restriction servers before they allow the machine to function. That way when the company goes out of business, they can ensure no-one can benefit from the hardware any longer.
Cautiously going to say, glad that isn't the case :)