'Stupid mistake' caused 3D printers to take on a life of their own

3D printer
(Image credit: Shutterstock / asharkyu)

The Spaghetti Detective (TSD), a company that monitors 3D printers remotely to catch potential errors, has issued an apology after a configuration mistake allowed prints to be sent to the wrong devices.

The error, described by founder Kenneth Jiang as ‘a stupid mistake’, let roughly 70 customers access and control each other’s 3D printers. In at least one instance, a user triggered a print on another person’s device.

In a blog post, an apologetic Jiang explained the security incident had come about as a result of attempted optimizations, which were supposed to improve the speed and efficiency of the company’s service.

3D printers go rogue

The problem was made possible by a feature called auto-discovery, which gives customers an easy way to synchronize their printers with their TSD accounts. As Jiang explains, the feature makes use of the fact that devices share the same public IP address when on the same local network.

“When I went through the load-balancer reconfiguration, I made a mistake by missing a configuration to let the load balancer pass the public IP address of the connecting client to the backend TSD server. Instead, the load-balancer would just pass its own IP address to the server,” he wrote.

“As a result, the server got the same IP address of the users who happened to be connecting their printer to TSD at the same time. The server thought they were on the same local network, and hence allowed them to link each other’s printers!”

Jiang says the security hole was live for about eight hours, but has since been closed off. All 73 affected users have also been notified.

Although the likelihood that all 73 were attempting to link their 3D printers at the same time is low, The Spaghetti Detective also took additional precautionary steps, including turning off auto-discovery and disabling remote access for affected customers.

“I don’t want to sugar-coat this. This is a serious security vulnerability,” said Jiang. “My sincere apologies to our community for this horrible mistake.”

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Digital image of a lock.
Xerox printer security risk could let hackers sneak into your systems
HP LaserJet Pro 3000 on modern office desk
Now HP printers are being bricked following firmware update
Printer
No, your printer isn't possessed: a Windows 11 23H2 bug could be making it print random characters when connected via USB
A person with a laptop using a credit card online.
Avery label maker confirms attack on its site, customer credit card info stolen
Brother HL-L2865DW during our review process
Brother denies claims it locked down third-party printer ink cartridges via forced firmware updates
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale