8 ms·
Everything I own, owned
https://web.archive.org/web/20260823225933/https://schlarp.com/posts/everything-i-own-owned/ https://web.archive.org/web/20260823225933/https://schlarp.c...
- SchemaLoad 1mo agoI'm hopeful that in the future we can end planned obsolescence from devices that require companion apps which eventually get shut down. Just vibe reverse engineering replacements.
- nulltrace 1mo agoA replacement app could just send the vendor-signed image and leave the signature check to the device. Plenty useful once the official app disappears.
- diabllicseagull 1mo agowe could have ended planned obsolescence decades ago if we put strong policies in place. I would really like a systemic solution instead of every-man-for-himself vibe coding. I've been following the "stop killing games" movement for that reason. fingers crossed.
- kelvinjps10 1mo agoThere was a video on YouTube about a girl basically did this built her own replacements software for these kinda of devices, didn't use ai though
- arn3n 1mo agoThis a fascinating security write up. I had no idea the models were this capable for reverse engineering. I heard CISA is getting defunded. I wonder if it'll become a common assumption for Americans that all their devices are just perpetually compromised.
- tptacek 1mo agoI'm not sure CISA ever did anything material about this problem, or was likely to in the future.
- micromacrofoot 1mo agowe haven't even seen the peak yet, as the author says > Network-connected devices seem near universally fucked at this point?
- philips 1mo agoI just reverse engineered the Supernote note file format with an agent a few weeks ago. For years the community had been asking for a document on the format. And in a few hours the agent, with 20 something file format example fixtures and 30 something prompts, was able to reverse out the format. It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc. https://github.com/philips/supernote-typescript/blob/main/plans/vector-format-spec.md https://github.com/philips/supernote-typescript/blob/main/pl... https://philips.github.io/supernote-typescript/ https://philips.github.io/supernote-typescript/
- zatkin 1mo agoI personally own a Supernote, but I'm not a heavy user of it. For the sake of my own curiosity, what benefits will you get out of having reverse engineered the Supernote note file format? It would be super rad to be able to move my notes between other devices, which is one big plus that comes to my mind.
- philips 1mo agoI built a management website and plugin for Obsidian. https://supernote.ifup.org/ https://supernote.ifup.org/ https://youtu.be/ihRh_F43-iQ https://youtu.be/ihRh_F43-iQ
- frio 1mo agoWhile it’s impressive work from the LLM and a TS implementation is novel, there’s at least a couple of pre-existing Python REs eg. https://github.com/jya-dev/supernote-tool https://github.com/jya-dev/supernote-tool :)
- fwip 1mo agoIt seems like most of these "an LLM solved this in only X hours! " could have been "I found an open source solution that did what I needed with X minutes of web search." Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
- wewewedxfgdf 1mo agoAll this ownage will get shut down when manufacturers start whining to politicians and the AI companies will ask how high to jump.
- SchemaLoad 1mo agoThe best models for reverse engineering right now are the Chinese ones. You can download them and run them unrestricted right now.
- sixtyj 1mo agoOpen hardware being reverse engineered with LLM is cool. I’d say John Deer will be among first ones requesting a halt. It was similar with Napster vs recording companies… and then Spotify bulldozed everything with its attitude. With LLM it could be much faster.
- bloaf 1mo agoWhat's that? A law that all manufacturers need to have had a security review from one of the major AI player's AI models?
- nemothekid 1mo agoIf Opus 5 can do it, there will probably be a Chinese OSS model that can do it before the end of the year.
- Retr0id 1mo agoUsing LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic. The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
- stackghost 1mo agoI find whenever I do this I run into the bullshit cyber guardrails. What model are you using and how are you prompting it?
- Retr0id 1mo agoOpus 5 with CVP, no special prompting. In this instance just about any larger model from the last 12 months would have done the trick.
- stackghost 1mo ago>with CVP Ah, there's the rub.
- Retr0id 1mo agoAlmost everyone I know who applied for CVP was successful, it's worth a try.
- teddyh 1mo agoKey takeaway: > And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
- SchemaLoad 1mo agoThis is why most of the browsers rejected these specs. They are super useful, but the security risks are incredible. Most USB devices were not designed to hold up to being exposed to the internet.
- AshamedCaptain 1mo agoI kinda remember that the counterargument Google used is that only devices with a special attribute would ever be available through WebHID, ensuring that such older devices would never be exposed. Cue my surprise when it turns out you can use WebHID to program a Minidisc / Net-MD device [1], so.. they never did implement that filter, apparently. I mean, certainly it is useful, but ... What The F., Google? [1] https://web.minidisc.wiki/ https://web.minidisc.wiki/
- qlte 1mo agoThe user has to first specifically pick the device from the list and grant the website access. If a user is confused by a permissions prompt and has no idea what is going on, the default path is to reject the permission.
- AshamedCaptain 1mo agoYou realize that most of the time that you are giving access to an older HID device, you are giving the website permission to convert that device into a persistent backdoor forever? No matter if you later close the browser or revoke the permission -- the damage has already been done? Most devices predating WebHID and the like have almost no protection (why would they?), and you can corrupt or even entirely replace the firmware quite easily. heck, NetMD is one example (the browser can overwrite its firmware with no trouble!), as are the devices listed in TFA . It is basically the same reason most desktops do not give the logged in user access to /dev/hidraw*, even though it makes a shitton of sense and would simplify many things greatly. This is one of the few areas where I think Mozilla did the right thing without question.
- lifeisstillgood 1mo agoI am wondering if there is a list of “things you should learn to do with your LLM” (But not the rubbish ads youtube keeps showing me) Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.
- usernomdeguerre 1mo agoSo is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?
- srcreigh 1mo ago> I haven’t actually been brave enough to write a modified firmware to the thing yet - it’s a pretty expensive monitor - but I’ll get there at some point. Honestly if you don't have working patches, it's really not owned. I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky. Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled... We are NOT there yet but I hope we get there soon.
- Retr0id 1mo agoIf you're prepared to get out a soldering iron and/or chip-clip, you can usually back up and restore whatever IC stores the firmware you're modifying, giving you a recovery path. > we also need good glitching tools There are a lot already, what do you feel is missing?
- srcreigh 1mo agoHow should I learn more about how to do it, what to buy, etc ? I haven't found ChatGPT to be a good teacher about this topic, and in particular re glitching, AI will refuse to discuss specifics I have enough basic soldering to get UART attached, but not sure what to try after that. Equipment-wise, I currently just have a few ESP32-C3s and electronics basics kit and some basic soldering stuff.
- rarisma 1mo ago[flagged]
- compiler-devel 1mo agoWhy? Does it bother you to see people using their own devices in the ways that they want?
- drfloyd51 1mo agoThat’s what they said when ASM was created. It’s what they said when C was created. Java. SQL. Powershell. Programming has always been about putting more power into the tools. Sadly, there doesn’t seem to be as much need for hardcore engineers.
- rgovostes 1mo agoTechnically this is Schlarpcoding.
- 0cf8612b2e1e 1mo agoThe pixel cleaning warning turns out to have no native way to disable it, and it’ll always show up after 8 hours of runtime. Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
- chubot 1mo agoI have an LG TV with a similar problem. I think it’s supposed to pixel clean when you turn it off, and I do every night. Yet for some reason I can’t escape these annoying pixel cleaning interruptions. Seems like a bug in the firmware.
- 0cf8612b2e1e 1mo agoThat feels like it should only require a single person working on the product to experience and demand an immediate fix.
- harry8 1mo agoThat feels like every review of LG should mention their quality is garbage to me, impacting their sales dramatically. Why hasn't that happened?
- SoftTalker 1mo agoYou are making a subsistence living in China writing TV firmware on contract to LG. Why do you do anything other than exactly what they ask for?
- 0cf8612b2e1e 1mo agoSure, someone at the bottom of the totem pole may not have autonomy to make decisions. There are others who can dictate policy. Is there no LG salesman who wants to take home this unit and becomes embarrassed about the behavior? A LG VP who might have this very unit on the desk? The second day of owning this monitor and seeing the same message should be a wake up call to everyone in the LG product line to fix the annoyance.
- compiler-devel 1mo agoIt's amazing to see LLMs give us software and hardware freedoms that the open source movement has only ever dreamed about.
- AshamedCaptain 1mo agoI think that this is not true -- the achievements mentioned here are hardly ground breaking and mostly build on work that was already done years before LLMs were a thing. There are things that the "open source movement" dreams about, and one just has to search around... E.g. like codecs, Qualcomm's aptX lossless, adaptative, and other more recent variations.
- SchemaLoad 1mo agoIt's not new capabilities, it's new levels of access. Reverse engineering this stuff used to be a very tedious process which required a lot of specialised skill. Which is why most devices haven't been reverse engineered or hacked despite being full of low hanging fruit.
- layer8 1mo agoThe flip side is that this might become a thing of the past for future hardware/firmware, if AI hardening becomes standard practice. There’s no substitute for having open systems that aren’t cryptographically locked down by the manufacturer.
- spaqin 1mo agoWe were already there. For most people, we are still there. For most devices (especially popular ones, with enough manufacturing volume) there's just enough hardening, downgrade prevention, encrypted or signed firmware blobs, on top of already rare reverse engineering skills and patience, to make it infeasible for most people to give it a crack. Using an LLM for that also isn't a mainstream idea either (plus you're unlikely to have a Claude subscription if you're not a software developer in the first place). Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
- throwyawayyyy 1mo agoI initially thought, but why would you want a "webcam whose activity LED I can switch off while it records"? But then I think I got the point: why would one want a webcam which _could be hacked_ so that its activity LED didn't go on.
- drfloyd51 1mo agoI am certain if it can be “tricked” into using it with the LED off, there is certainly a feature being sold to “enterprises” where it happens on purpose.
- trebligdivad 1mo agoThe i2c over USB with no auth is just way way too common; I've also seen that on a device.
- markzuckerberhh 1mo agoholy crap how ! i'd love to jailbreak my old quest 2. its such a good device too bad about all the facebook spyware!
- SlightlyLeftPad 1mo agoI had used codex to reverse engineer an electric skateboard to unbrick it. It was a bit more involved because it required soldering wires directly to the UART headers in a very awkward location. Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
- darknavi 1mo agoThis is giving me the confidence to RE my cat feeder. The company (Petlibro) has an outage and now my chilled wet feeder that should be a dumb, offline feeder is basically bricked now. The device reports fine wifi but the backing services are totally busted.
- prescriptivist 1mo agoI have one of their dry food ones and no longer need it. Sad story, but it happens. My cat scarfed and barfed periodically, and I always wanted the Petlibro (the simple one) to slow feed by incrementally turning the auger, just to see if it helped. I might dig it out and try my hand at this.
- SoftTalker 1mo agoWhy do you have a cat when you can't be bothered to feed it yourself?
- recursive 1mo agoYou're making some assumptions. Weird question anyway. Why eat food at all if you can't be bothered to farm it yourself.
- NegativeLatency 1mo agoTry getting a cat sitter around Christmas or a holiday weekend and then ask this again.
- mschuster91 1mo ago
- tuckerpo 1mo agoAh, I remember when reversing hardware took weeks / months, an oscilloscope, logic analyzer, Ghidra/IDA, Wireshark, breakout boards, wireless sniffers... back in the olden days of... 2019.
- fwipsy 1mo agoif an AI could do it without an oscilloscope, probably a human could too.
- drivers99 1mo agoIt's kind of funny, but AI can also use an oscilloscope. My friend vibe coded a software synth on a Raspberry Pi Pico. When he realized his oscilloscope had a network interface, he had Claude figure out how to connect to it over the network and analyze the actual audio output.
- nabilt 1mo agoI had claude write an mcp server to talk to my scope since most are connected over Ethernet. It was pretty fun. https://netliststudio.com/articles/2026/02/23/claude-oscilloscope/ https://netliststudio.com/articles/2026/02/23/claude-oscillo...
- ndiddy 1mo ago> My ASUS ROG Swift PG42UQ monitor was actually where I started, because I got annoyed at the pop-up overlay that comes up every once in a while that tells me to run “pixel cleaning”. I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever. Maybe there’s a debug menu or something that can turn it off, or worst case we patch a branch in the firmware? Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
- Rohansi 1mo agoI don't think learning more about what it does is going to make them change their mind here.
- baby_souffle 1mo ago> You could probably ask the AI to look at the firmware and describe what it does. Or ask for a patch so it runs after the monitor has been powered off for a while... I use an LG OLED 42inch TV as a monitor and it has a setting to do just this.
- ndiddy 1mo agoI looked it up, his monitor does do it automatically after it's been powered off for a few minutes. He's getting the nag message because the monitor has been on and displaying a picture for over 8 hours.
- Aurornis 1mo agoYeah, you actually want to do this with monitors of that generation to make them last. You could argue that there should be an option to disable it for people who don’t care. Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
- californical 1mo ago
- deleted 1mo ago[deleted]
- kachhalimbu 1mo agoSidenote to the technical discussion. The article read like a Martha Wells murderbot novel to me. Fascinating.
- Shocka1 1mo agoYep, Claude did well here. From the experiment, to the website design, to more than likely all the writing/summaries. What is truly fascinating is not that long ago people were doing hard experiments regularly like this without any LLMs. Like Dublin, in the rare ould times.
- soulofmischief 1mo agoI have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do. I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc. It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode. It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.
- rspeele 1mo agoI remember that name from NCSSM! Cool to see you on the front page of HN.
- schlarpc 1mo agoWe should catch up some time, it’s been ages!
- NavinF 1mo ago>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying! Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
- kestrel-robotic 1mo ago> the LED can't be controlled from software If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat. You can say a lot about Apple but the engineering is clever at the hardware level.
- Barbing 1mo agoAlso the Hall effect sensor disabling the mic when a MacBook lid is closed, apparently just about impossible to bypass. https://en.wikipedia.org/wiki/Hall_effect https://en.wikipedia.org/wiki/Hall_effect
- dncornholio 1mo agoIt's not. I can place my iPhone next to my trackpad and the MacBook thinks I closed the lid.
- BYazfVCcq 1mo agoThat's not what people mean by 'bypassing', turning it off is obviously easy. The point is that activating the microphone while the lid is closed is pretty much impossible.
- ryandrake 1mo agoIt's not even that clever, really. The camera power rail must be physically close to the camera, so it's trivial to hang an LED off it. A device manufacturer has to go out of their way to make it so the LED and camera function are independent, and I'm sure many do, for the worst reasons you can possibly think of.
- ks2048 1mo agoI can see the benefit of from-scratch personalized software, but in the spirit of open-source, how about all the world contributes to useful software for everyone else? Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
- ryandrake 1mo agoI'm starting to believe that bespoke, personalized software is the only way to combat feature bloat. Every software (proprietary or open source) I download and use has features I don't want getting in the way and bugs that the developers/maintainers are not prioritizing. I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
- HDBaseT 1mo agoA highly modular plugin system would solve this though. A great base product, with plugins (both community & official) which could expand feature sets.
- deleted 1mo ago[deleted]
- vinay_ys 1mo agoWhy does this feel like arms race where the only real winner is the arms seller?
- Waterluvian 1mo agoTwo weeks ago I told Claude “I have a <wifi outlet relay> on the LAN at <IP>. Assume direct control of it.” And about 8 command approvals later I had a new firmware running on it. Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
- SomeHacker44 1mo agoSurprising. I have hit its BS guardrails a lot lately, working on my vintage computers from the 80s and early 90s. Just about done with Claude.
- Spooky23 1mo agoYou can’t be loyal to these things. I ditched ChatGPT during the peak Claude hype after Christmas. I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
- Gigachad 1mo agoJust sign up with something like openrouter and keep switching models until one completes the task.
- ascorbic 1mo agoPaying by the token is a much more expensive way of doing it than signing up for the various coding plans when you need them.
- luckystarr 1mo agoNot if the models are way cheaper. For many tasks you can do with DeepSeek Flash, and for more gnarly problems you switch to GLM or Kimi. But sure, if you do everything in large models like Kimi K3 or GLM it gets expensive quickly.
- simonw 1mo agoWe have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.
- vunderba 1mo agoNice! I actually built something similar back in early 2023 [1], which used a collection of SDXL models to generate a new random painting every hour upscaled to 4K and then broadcasted to my frame using the Samsung WS API wrapper [2]. [1] - https://mordenstar.com/projects/save-our-screens https://mordenstar.com/projects/save-our-screens [2] - https://github.com/xchwarze/samsung-tv-ws-api https://github.com/xchwarze/samsung-tv-ws-api
- Barbing 1mo agoNeat. What’s the lift from here to get a zero-token spend image upload?
- isoprophlex 1mo agoI desperately want this, but our Frame has never been connected to the Wifi, and I'm really reluctant to do so, as it will probably start snitching and/or delivering ads...
- wingtw 1mo agoNew, ad free, firmware is obv a couple of prompts away...just sayin... ;)
- brusseliz 1mo agoThe tv-ws-api can be used over ethernet. I control my Frame TV from a pi through direct ethernet cable and the pi separately connects to my home LAN over WiFi and serves an app for Frame art control. The TV has never had direct access to the LAN or internet. Check the frame subreddit for several such projects.
- mrheosuper 1mo agoAs FW engineer, I am both horrified and intrigued. The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me. But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices. Sorry community, but it's our job to make the reverse engineer harder.
- webprofusion 1mo agoIf you can use a custom chip yep, if it's commodity hardware probably not. You could use secure boot/secure memory etc but that can be a footgun in itself later.
- mrheosuper 1mo agoWhat do you mean "Custom chip", like ASIC ? Never in my career that i feel the need to make our own ASIC.
- menaerus 1mo agoParent comment was likely about how are you supposed to put LLM into your chip. Commodity ICs are already optimized down to their minimums wrt compute/memory/storage. Ultimately, I think it will prove that RE examples like this are going to become a difficult problem to solve.
- mrheosuper 1mo agoOh no, i mean using LLM in the loop, keep forcing it to break our device, gives it every tool that an average tinker can access.
- menaerus 1mo agoI misunderstood you then, sorry. Yes, that makes complete sense but ultimately I think this will likely not be enough. Implementation will be hardened but new models with better capabilities will be released, and will discover vulnerabilities that would not have been caught or discovered with prior models.
- SubiculumCode 1mo agoI guess there is this dream that AI will help us finally close the Linux driver gap, and maybe even conquer the android phone closed hardware driver conundrum making almost every phone locked down. One can hope.
- cromka 1mo agoI definitely managed to get Linux running in full on my Xiaomi Pad tablet, each and every feature of it! Writing drivers is a breeze now, what remains difficult is upstreaming them.
- SubiculumCode 1mo agoawesome!
- Jhater 1mo ago[dead]
- ryandrake 1mo agoI posted [1] a few days ago my experience using LLM to reverse engineering an entirely undocumented device that was only supported by a (crappy) Windows application, and it was honestly remarkable how good Claude was at decompiling the Windows EXE and reverse engineering the protocol. Very exciting. "The developer refuses to write software for this device" is no longer as scary as it used to be. 1: https://news.ycombinator.com/item?id=49353141 https://news.ycombinator.com/item?id=49353141
- WorldPeas 1mo agoI did this a while back with my Eaton UPS and Opus 4.8, glad I didn't need to install windows 11 just to push a blob. The day when a LLM os can make unique drivers will be one I wait for
- asdfsa32 1mo agoThis looks like an ad for a bunch of products as "hackable". The Authors only other blog post is also about using Claude for similar ideas, without actually showing the end product from a kick skim. Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.
- tired_and_awake 1mo agoI spent a decade in robotics and have built firmware for dozens of devices. And yet I was never able to successfully fix my webcam device driver on linux with Claude. I'm jealous of this person's prompting skills! Or perhaps pwning is easier than fixing the nightmare that is Intel open source device drivers?
- lionkor 1mo agoThere are two nuances here; 1. The author might be exaggerating or lying in regards to the capabilities, ease of use, and result 2. if Claude can do it without hardware access, I struggle to see how it could be anything other than unsigned unencrypted firmware images that you can unpack and mess with
- jaco6 1mo agoAny intelligent powerful person should be going entirely offline now--if I had net worth over $10mm, I wouldn't own a computer--I would have a secretary control my computer for me. We're going to see really horrible, persistent blackmail in the next few years destroying lives and reputations. It will eventually be the end of the consumer internet.
- webprofusion 1mo agoBuilt custom firmware for my Line 6 Pod GO HD guitar multi-fx the other day. Turned into a complete midi controller so it wasn't gathering dust. Fun times!
- lrvick 1mo ago> I can’t help but think about what an AI-equipped automatically-reverse-engineering worm could do today. Everyone should read Daemon and Freedom, like right now.
- sebmellen 1mo agoThis one? https://en.wikipedia.org/wiki/Freedom%E2%84%A2 https://en.wikipedia.org/wiki/Freedom%E2%84%A2
- lrvick 1mo agoThat is the second book, but yes. Read Daemon first.
- schlarpc 1mo agoI didn’t put this in the post, but yeah, I think about Daemon almost every day at this point. Unbelievably prescient novel.
- aetherspawn 1mo agoHow’d you get Opus 5 not to just give up instantly for reverse engineering? Are you sure you’re using Opus 5 and not 4.8 by automatic fallback? I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
- schlarpc 1mo agoI have CVP access, which removes the external refusals for Opus 5. I submitted my LinkedIn and Github and got approved in less than 10 minutes.
- aetherspawn 1mo agoAre you on an enterprise plan? I’m on a personal plan so I never bothered. I assumed they wouldn’t approve. Also is your LinkedIn cyber security adjacent?
- schlarpc 1mo agoPersonal plan, but yes, my day job is being a security engineer for big tech.
- cowboylowrez 1mo agoWhats your thoughts on this being a temporary phenom, that will last until big corp applies AI's to resist this? Reading your article I get the feeling that the only security measures that you ran up against were just the obscurity defeated by disassembly. Plenty of posts here going "enjoy it while it lasts" but since you are actually working in the security field I'm curious about what you think of bigcorp pushback against this sort of thing?
- schlarpc 1mo ago
- cj00 1mo agoThis is timely! I'm trying to take control of my Echo Wall Clock which connects to an Alexa device that I want to get rid of. There's very little info on it but Claude was able to find the FCC filings and now we've got lo-res images of the circuit board. It's inspecting the test pads on the circuit board now to see if it can figure out how to replace the firmware.
- Marsymars 1mo agoI have interest in this. My Echo Wall Clock is the only reason I still have an Alexa device in my home.
- SillyUsername 1mo agoI did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware. I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152. The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine. It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing. The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes. It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour. The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected. I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it. I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
- echelon 1mo agoThis is so neat. This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy. When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead. Everything hardware belongs to us now. This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
- luckystarr 1mo agoUntil the manufacturers enter an arms race and copy a page out of the mobile hardware vendors book. But perhaps they'll do it badly and we've got a few more years.
- jauntywundrkind 1mo agoThis fills me with the sadness of the Jeep hack. Incredible fantastic super amazing work to liberate devices! Finally a peak behind the curtain! But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!" I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
- snowwrestler 1mo agoMaybe this is what Jevon's Paradox looks like for LLMs. Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
- PeterStuer 1mo agoWait,what? Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"? WTF Anthropic? Is the trick not using Python?
- romanovcode 1mo agoMaybe. It wrote C code that override some of my hardware without a single complaints. Try it
- AlfeG 1mo agoYou can request for Cyber Verification Program (CVP) access from Anthropic
- driverdan 1mo agoThis requires submitting a photo ID to Persona, something no one should be comfortable doing. There are very real privacy concerns with Persona, so much so that Discord dropped them as their provider.
- Tepix 1mo agoPrinters are a juicy target, they can have enough CPU/RAM/storage to be a good hiding place for backdoors. Or you just want to patch out rejection of 3rd party ink/toner.
- raybb 1mo agoI posted this on another thread but can someone please run this on some old iPads so we can be able to fully install Linux on them. If AI is so good surely it can do that and save millions of devices from turning into ewaste.
- echelon 1mo agoYou can! Don't be afraid to try. You're limited only by time and imagination now.
- megadragon9 1mo agoI did something similar but with smart home devices. I use the homebridge interface to connect my smart home devices to Apple's homekit protocol. Some homebridge plugins for my devices were outdated and no longer maintained, so I asked Codex/Claude to help me create a patch of it as a local fork, so my smart home devices can still run without problems. It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
- lowbloodsugar 1mo ago> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate. Oh very good! > This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature. Oh that was going so well. Just wow.
- malixp 1mo ago[dead]
- WalterBright 1mo ago> Network-connected devices seem near universally fucked at this point? I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable. And no, not a programmable switch. A hardware switch. They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
- hypfer 1mo agoGive it time. The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes. I like your idea
- pmdr 1mo agoI suspect all this will go away soon, even from Chinese models for, uh, security reasons.
- hypfer 1mo agoMaybe, but also the cat is out of the bag, as open weights models can do it. I suppose you could make having those illegal through on-device scanning and legally mandating usage of operating systems that do that? Not sure. Not sure if this tech can be contained. Dario does it for the wrong reasons, but it's not like there would be no point in his fearmongering. __ I wonder if someone will try something like with printers, in that new and more powerful compute units see signatures of models and just refuse execution in the same way inkjet printers refuse to print euro bills. I'm not sure if that would be a sensible thing to do, but that is a different question from "will someone try that path?"
- hollow-moe 1mo agoDid something like this to play RTMP-over-HTTP from a security camera, no server required. didn't poke for rce yet. And same for a capture card with a HDMI loop out that was dropping audio when the monitor you plugged into it didn't advertise sound support in its edid, now it works.
- utopiah 1mo agoHonestly I do like this trend if it genuinely leads to more interoperability. Im not sure that is the case though and in fact I worry people will start to imagine that anybody can do that in no time and that future devices will remain hackable this way. I have no doubt it was fun for OP to do but I bet most people who try that, people with less understanding, will inevitably end up nowhere or, worst, with bricked device in unrecoverable states. I feel this is one of the best use of AI at the moment, namely gaining agency by having devices do what their own wants and I hope it will lead to manufacturers selling both safer AND more interoperable devices but I'll remain prudently skeptical.
- jfsebastian 1mo agoMy Sony TV also faced some issues in the past, which at least let me start some investigation. Unfortunately it confirmed my assumptions that the hardware is very limited and already runs on full load most of the time. Still thinking about putting some more effort into this, but killing the device was also one of my concerns. A really fun project was extendending the abilities of my reMarkable Pro. I missed a decent Manga Reader on the device, so I created a native one which makes use of my custom server.
- mportela 1mo agoMind sharing it? I would also love a manga reader for remarkable!
- fodkodrasz 1mo agoPeople are praising how this new age of owning our stuff is here, while actually all this will bring is stricter lockdown in every level of the supply chain. Enjoy while it lasts, but I expect even more closed stuff, and less openness from these t.rends
- pjmlp 1mo agoWell, the takeway is that we should keep pushing to write everything in Assembly and C, so that human errors allow such "ownership".
- simpaticoder 1mo agoThe other option is to look for better products that take simplicity, security, ownership and verifiability seriously. I think there's a market. Consider Precusor[0] who's design philosophy could be duplicated. Such a company could become the Anker of computer peripherals: build quality products that decommoditize markets. Now is the time to make such a company, because by the time the peripherapocolypse hits (in a few months) by then it will be too late. [0] https://www.crowdsupply.com/sutajio-kosagi/precursor/updates/introducing https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...
- Cthulhu_ 1mo agoWhile closedness is bad, I assumed peripherals like these were closed anyway; the fact they were hackable implies they were not secure enough. So if closed means they are secure, which 99.99% of end users expect, I'm actually okay with it.
- attila-lendvai 1mo agoclosed is never secure. it's just open only for a smaller circle.
- theshrike79 1mo agoIf I can't hack it with local access and an AI, a random hacker can't do it either. I do lament the loss of control, but the increase in security will be objectively good for humanity as a whole.
- mastermage 1mo agothis is interesting, while i greatly apreciate the ability with claude code to basically customize my own firmware. There are things that I am strictly speaking wondering about the authors choices. The Author removed Pixel Cleaning? As far as I understand Pixel Cleaning is a process to make sure your OLED Monitor lives longer, why would you want to not do that?
- 8-prime 1mo agoMy monitor can run a pixel cleaning automatically when it detects that there is no longer a signal coming in. That way it periodically cleans, but has never done so while I was using it. I presume the author uses the same mechanism and just doesn't want to be bothered about it.
- dncornholio 1mo agoNothing owned.. Maybe the webcam a bit but this is mainly, again, just slop.
- phh 1mo agoI definitely love this article and this spirit. I've accumulated a lot of crap/cheap IoT, I'll probably owning them! Two things: - to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does. - When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
- hypfer 1mo ago> for anything connected to the internet Are you sure? iirc that (for now?) only applies to stuff with wireless connectivity, though maybe I'm misinformed or misremembering. Which would still be "all IoT, basically", of course.
- phh 1mo agoHum, I don't really know. I was pretty sure it applies to anything connected to the internet even if it's Ethernet-only, but double checked. And reading the EU directive, it looks pretty obvious to me that you're right, it's only for devices with wireless connectivity... (the wireless connectivity doesn't need to be wifi/internet though. like if you have a 433mhz-to-ethernet gateway it still fits). (Technically it says "which intentionally emits and/or receives radio waves for the purpose of radio communication", I'll let HN crowd determine if Ethernet emits/receive radio waves in an enclosed channel called Ethernet cable)
- 1mo ago
- cromka 1mo agoWhat I wish is that we started reverse-engineering audio receivers, many of which run regular Linux. Manufacturers tend to release the new models with hardly any hardware changes, sometimes only software updates. To be able to backport an Airplay2 to an older, fully functional receiver would be amazing. I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
- Abishek_Muthian 1mo agoAt this point manufacturers should just open-source their firmwares as there's no barrier for entry to reverse engineer it. They will instead gain from army of end-users willing to put their time and tokens into fixing their bugs for free.
- erikkri 1mo agoI hope someone does this for the Sonos speakers
- edwinjm 1mo agohttps://github.com/luckyshot/OpenSound https://github.com/luckyshot/OpenSound
- a_bonobo 1mo agoI've spent SO MUCH TIME in my life trying to get laboratory machinery, usually only ten of them in the world, to spit out their data nicely. They have UIs but usually god-awful, and all data is hidden away somewhere (they're written by biologists, for biologists). I wish I could go void some warranties....
- shrubby 1mo agoWhen will reversing unlock old Apple devices for other OS'es?
- trencedamp 1mo agoThis is the first exciting thing I've seen done with LLMs in quite some time. Turning on or off an LED doesn't seem world shattering, but the idea that we might be able to unlock or add functionality to hardware we own makes me giddy
- bobek 1mo agoTBH this is one of a few things that feels exciting about LLMs. I've recently revived a flip-dot panel from an old bus by reverse engineering and replacing its firmware -- https://www.bobek.cz/buse/ https://www.bobek.cz/buse/
- brammeleman 1mo agoLooks like the video links are broken, would love to see these displays in action.
- e-topy 1mo agooh wow, this is cool! I managed to reverse engineer a BS120 led display[1], we ended up hooking it into our hackerspace's[2] home assistant instance, displaying everything from static messages to when trams are departing. I enjoyed the challenge of REing it by hand, but the ESP32 firmware to connect it was vibed by a fellow member. [1]: https://git.sr.ht/~e-topy/bs120 https://git.sr.ht/~e-topy/bs120 [2]: https://base48.cz https://base48.cz; feel free to come by anytime
- BiteCode_dev 1mo agoThis indeed works very well, most device are not very well locked down because of proje t resources limitation, and this opens a new era of hacking. Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI. This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.
- touchme 1mo agoI bought a Evnia 27M2N8500 and has been having issues too with the Pixel cleaning, sometimes i turn it on and it says its been 4 hours, or simply never show it the whole day... I'm not brave enough to brick the 700 euros monitor :( for the rest of the things i own i pretty much did the same as most of the OG software is just bloat, 1gb to just control pc fans is evil.
- sshagent 1mo agoThis is great stuff. Wouldn't this be lovely to go "fix" misbehaving devices (LG TV)
- konraditurbe 1mo agoI own the Insta360 Link too, will flash this firmware since I also want to turn off the LED ring.
- jeroenhd 1mo agoAnthropic's Claude: own your things, for only 20 dollars per month!
- theshrike79 1mo agoThe difference is that you'll own the hacked solution forever, even if you unsubscribe from Claude. Using AI to build tools you own and operate is the way.
- holofermes 1mo agothis is awesome! I also did something similar with the Orba by Artiphon [1]. Initially I was pretty disappointed by the current state of the Android app, and honestly I just wanted to see what happens if I plug this thing in and ask my Bob bot to take a look around. What I didn't know before starting was that Artiphon went bankrupt last year, which is a bummer cause they made a lot of cool hardware. I have not considered the firmware route, and just relied on decompiling whatever APK/exe, but the idea of controlling a device which is essentially no longer maintained, and all for a few hours of bobbing is quite spectacular. [1] https://github.com/holofermes/orba-protocol https://github.com/holofermes/orba-protocol
- RS-232 1mo agoThanks, I hate it. The camera in particular is exactly why I’ve reverted to using devices without networking capabilities.
- wartywhoa23 1mo agoAI PR department at it again: sell to hackers what they ostensibly used to love doing themselves babbling about the ideals of freedom and openness. So much for the "hackers", I guess.
- hn1rig3rak 1mo agoYep. Every single time.
- soundworlds 1mo agoAn Agent helped me get a Windows XP Korean MMORPG private server running on my Steam Deck last week. The community obviously got us most of the way there (huge props to them) but setting it up on Linux seemed like a brick wall. Now it works. Amazing for keeping old tech open and running: https://github.com/P0nk/Cosmic/discussions/350 https://github.com/P0nk/Cosmic/discussions/350
- hajimuz 1mo ago- Kindle Book decryption - Game Console(XBOX especially) Jailbreak Let’s go!
- ozereray1 1mo ago[dead]
- jimmy76615 1mo agoWhich model does one use for this? I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis. I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.
- lennart-rth 1mo agoI did this just yesterday with a smart light. Used Deepseek-v4-flash. In about 2h I had a custom firmware on the smart light running that I could control from its api endpoints. Also now Im hosting a small web-server on there that lets me set schedules and sleep timers. No im not relying on their proprietary cloud anymore to toggle my lights. Which is insane to start with. Why should my phone that is in my home network need to send the "light on" command ot some cloud in a different country, only to then send the command back into my home network and turn the light on. Im definitly very exited to try this our with more devices in my live.
- ziofill 1mo agoPerhaps I’m daydreaming, but maybe some vendors will accept this new reality and begin just selling the hardware without locking users in. Perhaps they’ll even make it easier for users to truly own their products.
- seanclayton 1mo agoDIY kits have been a thing... forever? There's lots of open source hardware out there, and some you can even buy if you demand commercial access.
- neop1x 1mo agoNo, they will just encrypt firmware, add more signature verifications and lock devices to accounts in order to complicate reuse, increase sales and produce more ewaste.
- ziofill 1mo agoI agree, but like many others I'm willing to pay a fair price for that freedom and ownership, and I believe there is a customer base to be captured. And in the end there's a cost for a company to put all of those locks in place, which they could simply avoid.
- wg0 1mo agoBut seriously - is software industry over? Where the next talent would come from?
- fenestella 1mo ago[flagged]
- cromka 1mo agoInspired by this article I started to work on migrating my cat's feeder to ESPHome. Within 2 mere hours I'm am basically done but also wanted to RE their update path to avoid having to connect to UART to flash the new firmware. To my surprise, the stock firmware has some issue with the vendor's server where it downgrades to plain HTTP after 5 retries. It exposes all keys, device id and firmware upgrade path to MITM attacks. Absolutely bonkers and it shows how bad these IoT companies are at security. Vendor is PetKit btw.
- sergioramos 1mo agoI would be interested in your ESPHome version if you release it
- cromka 1mo agoTomorrow most likely. I'll let you know.
- tonymet 1mo agoAbout 1.5 years ago I reported a vulnerability with my router’s ipv6. The firewall was wide open, and router management SSH was listening externally, among a few other vulnerabilities. After pulling teeth, the router fixed ssh, but not the firewall. A couple months ago I used AI to find a novel shell injection exploit and obtain root creds in the router, so I could print out the firewall configuration , init script flaws , and write up a vulnerability report. AI found the bug and wrote the patch to fix it for the vendor, without having the original code ( the bug was in shell script, thankfully). The vendor had commented out the IPv6 firewall init, probably to pass QA , knowing consumers don’t usually use or test IPv6. Upon getting the report, the vendor fixed the issue.
- hmartin 1mo agoI've been on a similar (if less ambitious) jam. I found that ping-ponging between Fable and Sol if one of them get stuck or refuse has been wildly succesful. Firmware for Onyx Boox apps: https://github.com/hbmartin/onyx-android-sdk https://github.com/hbmartin/onyx-android-sdk Mac / Metal drivers for Kinect 360: https://github.com/hbmartin/libfreenect2-metal https://github.com/hbmartin/libfreenect2-metal Mac driver and control app for Razer's cooling pad: https://github.com/hbmartin/razer-cooling-pad-mac https://github.com/hbmartin/razer-cooling-pad-mac
- schrijver 1mo agoSo any interesting alternative use for the Camlink ? All I can think of is dropping framerate (some of my cameras output 50p but are 25p). Or maybe adding a LUT ?
- 1vuio0pswjnm7 1mo ago[dead]
- vagab0nd 27d agoCC extracted the private keys from the AT&T modem and moved the decryption to my UCG. No more slowdown when scraping the internet. This is a pretty well-documented hack but without CC it'd probably take much longer.