Rendered at 15:52:04 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
SillyUsername 11 hours ago [-]
I did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware.
I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152.
The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine.
It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes.
It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour.
The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected.
I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it.
I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
someothherguyy 26 minutes ago [-]
> It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
That you verified? Seems like 1/3 times when a model says things like this it is way off.
echelon 10 hours ago [-]
This is so neat.
This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy.
When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead.
Everything hardware belongs to us now.
This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
hypfer 10 hours ago [-]
Don't get your hopes up.
What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.
It's of course still huge to be able to do this with all tech up until this cut-off point.
Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.
___
Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.
Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.
We should keep in mind that not everyone wins here. In fact, only a minority does.
jfsebastian 9 hours ago [-]
Generally, I'm with you, but over the past decades I often saw companies being lazy about their software. So I think chances are good that we can make use of this situation. Not long ago, you had to accept certain decisions or servers going down with leaving devices useless. I'm hopeful that more stuff can have a 2nd/better life in our hands.
hypfer 9 hours ago [-]
I like being able to have all this access, of course, but I'm not sure if "we" all truly have the character to be good stewards of this.
Or rather I am sure that we do not.
OTOH, maybe it needs events like these to build character. It just will suck for whoever turns out to be the collateral.
jfsebastian 8 hours ago [-]
That's the downside of the medal, but let's face it. A tool is a tool. You can forge helpful stuff or weapons, but this is not the fault of the tool itself. So we're currently at the stage where we were on the internet 30 years ago. Let's see where this leads too.
hypfer 8 hours ago [-]
[dead]
vlyan 8 hours ago [-]
(in response to the other comment here, whose author forgot to turn off VPN and got automatically flagged despite his account being 10 years old, because @dang would rather hang a hundred innocent men than let a guilty get away.)
do you ponder "unpleasant moral stuff" every time you chop vegetables?
>As an anchor, knives or sharp objects were used in about 97,000 homicides globally in 2017, equivalent to roughly 266 deaths per day.
>There is no reliable single global count, so the best concise answer is about 10,000 people injured by stabbing each day worldwide, not counting deaths separately.
I can guarantee you that 95% of those are done with the humble kitchen knife.
phrotoma 4 hours ago [-]
lol - if hackers hacking devices encouraged device vendors to secure their shit, we wouldn't be in this mess.
pjc50 7 hours ago [-]
My two thoughts are:
- this is great
- this is an incredibly unstable equilibrium, like a lot of things related to the internet, because other actors haven't yet figured out how to do this at scale
yard2010 7 hours ago [-]
I love this comment so much. It really feels like the big tech is losing the grip. In Rick and Morty, the way Rick is using tech to amuse himself always inspires me. I could only dream of doing anything related a few years back when I watched it. Yesterday I was reverse engineering a cheap but good label maker from AliExpress to write my own app printing labels the way I want them with the fonts and graphics I like with no cancer ads like on the official version. Maybe in a few years I could build a portal gun or turn myself into a pickle, who knows. Fun times!
hypfer 7 hours ago [-]
Rick is the smartest man in the universe though.
Using LLMs to do this stuff is more like using a gadget built by the guy - not like being the guy.
Mortyposting on main
Shorel 4 hours ago [-]
So you want to skip family counselling... Hahaha
luckystarr 10 hours ago [-]
Until the manufacturers enter an arms race and copy a page out of the mobile hardware vendors book. But perhaps they'll do it badly and we've got a few more years.
jimmy76615 4 hours ago [-]
I'm sure they will eventually, but for the first time their incompetence is working to our benefit.
shrubby 7 hours ago [-]
When do the locked old apple pads open up for Linux?
quijoteuniv 7 hours ago [-]
Very tempted to keep collecting e-trash! After installing linux on old machines, downloading docs, wikipedia and gutemberg project i just need to make some kind of faraday cage for them.
shrubby 5 hours ago [-]
Or resuscitation of complex electrically faulted cars. Or or.
I have a bunch of iPads stashed for this.
fragmede 5 hours ago [-]
> When the SOTA robots from Unitree get here
I hate to be the bearer of bad news about this, but
> The U.S. Federal Communications Commission (FCC) banned imports of new foreign-made humanoid and quadruped robots, primarily targeting China.
> custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode
While that is cool, why do you need such a thing? More FPS? Less video RAM?
strelok25 6 hours ago [-]
[flagged]
ndiddy 16 hours ago [-]
> My ASUS ROG Swift PG42UQ monitor was actually where I started, because I got annoyed at the pop-up overlay that comes up every once in a while that tells me to run “pixel cleaning”. I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever. Maybe there’s a debug menu or something that can turn it off, or worst case we patch a branch in the firmware?
Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
Aurornis 15 hours ago [-]
Yeah, you actually want to do this with monitors of that generation to make them last.
You could argue that there should be an option to disable it for people who don’t care.
Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
schlarpc 15 hours ago [-]
I understand what it does, I think the alert is annoying. It takes at least five minutes and automatically runs when the monitor is off. I’ve had it for a few years and have no burn in issues despite not doing this every eight hours on command.
discordance 8 hours ago [-]
Agreed.. and it has an incredibly frustrating and hostile UX.
I've been sharing my screen in work in meetings and suddenly screen nagged, and then I'm struggling to find the dumb buttons under the monitor and confused which button does what to make it go away.
I would rather suffer burn in than be nagged. I've had other brand OLEDs that haven't been this annoying, so I'll never buy an Asus monitor again.
richrichardsson 7 hours ago [-]
AOC/Agon OLEDs also have the annoying nag that fires repeatedly to say "Your monitor will go into pixel cleaning mode in 10/5/4/3/2/1 minutes". I still haven't figured out how to easily defer that, and it's super annoying when in the middle of a Rocket League match that the monitor just turns itself off to pixel clean for 10 minutes.
BoxOfRain 5 hours ago [-]
My MSI monitor does it, I don't object to it in principle. What I do object to is a tool, that I own, demanding this is done on its own schedule rather than mine in a way I can't always dismiss. There's no reason it shouldn't be configurable to do it at three in the morning rather than when I'm trying to run the standup for example.
Definitely will be checking more carefully the next time I buy an OLED monitor that it'll let me do this.
eikenberry 14 hours ago [-]
> Yeah, you actually want to do this with monitors of that generation to make them last.
Brand new models still have this popup... what "generation" are you talking about that doesn't need this? Or is it just unnecessary on the newer models but they have it any ways due to lack of firmware updates?
alienbaby 4 hours ago [-]
Reminds me of the degauss button on my old eizo crt...
nyanmatt 2 hours ago [-]
I miss the sound and visuals from a good degaussing
kulahan 13 hours ago [-]
How is it strange that among the 900,000 1-minute tasks you need to complete on a given day, this one is low on the list?
gleenn 12 hours ago [-]
Some people's time is actually worth or even just valued more than others to be bothered doing maintenance tasks such as there. I have a life to live outside preserving every last minute of functionality out of a monitor, I'll buy a new one eventually regardless.
sharken 9 hours ago [-]
I think it's nearly impossible to explain the benefit of not seeing such a popup to most people.
It comes down to the joy of doing things, and if the joy of using said monitor depends on a popup not being shown, then so be it.
I hope that the popup can be removed :)
californical 15 hours ago [-]
Eh I think the monitors should just handle this automatically - mine do. I basically have no idea that they do any cleaning cycles except when I check their “advanced” menu and it says it’s run 1200 times or whatever
DiabloD3 15 hours ago [-]
They can.... which everyone bitched about: they would do their cleaning cycle, no matter if you were busy or not.
kulahan 13 hours ago [-]
Then they should do it at another time...? Obviously?
DiabloD3 5 hours ago [-]
And thats why we have the warning that everyone bitches about: "Hey, the timer is up, but I'm not gonna make you do it, its just gonna wear the display out faster".
Early OLEDs really did need to be pixel cleaned every 8 hours according to manufacturer estimates, the choice isn't have warning or not, its have a lifespan or not.
I don't want to blame early adopters for being early adopters, but they early adopted, and this is the early adoption problem.
radlad 3 hours ago [-]
I have an MSI OLED monitor, and if I accidentally turn it off (trying to find the input switcher), and then back on, it shows this warning.
But it automatically runs when it's turned off. The warning is shown because I interrupted it running early.
The warning, for my purposes, is completely useless, and only an annoyance. The automatic feature is more than enough, and I don't need to know if it was aborted early.
troupo 4 hours ago [-]
Because the run a full blown OSes on monitors now, and for some reason it cannot figure out the simple "wait until you're off for at least 10 minutes to do the cycle instead of bothering the user at random intervals"
teekert 11 hours ago [-]
Maybe he should have assigned an agent to it.
userbinator 14 hours ago [-]
The Internet seems rather reluctant to explain what exactly "pixel cleaning" does, but based on the vague useless "explanations" I could find, I suspect it's a sort of "flat-field correction" where it calibrates the pixel drive current to darken the less worn and/or brighten the more worn ones so it eliminates the burn-in effect. This obviously leads to a vicious cycle where more worn pixels are driven harder and hence wear faster...
IMHO OLED is a planned-obsolescence dead-end anyway; LCDs can last literally decades, maybe with a backlight replacement, but OLEDs are designed to fail in a few years. I have a few (rather expensive) pieces of test equipment with OLEDs that became unreadable after only a few years and had to be replaced (fortunately with a regular LCD, and some firmware patching), while others with old-school CSTN/TN LCDs are still fine.
p1necone 13 hours ago [-]
If OLEDs are 'designed to fail' they've certainly gone about it in a very roundabout way - there would be much easier ways to do planned obsolescence if that was actually the goal of display manufacturers.
karim79 12 hours ago [-]
I have a LG wallpaper TV 65" from 2021. I see no burn-in whatsoever. Once in a while it says "we will do the pixel refresher thing when you turn off the TV".
I'm pretty sure there's something to it but I'm no expert. Five years later and my TV is just fine.
realo 7 hours ago [-]
A TV displays constantly changing images.
A monitor displays items that can stay fixed in place a long time, hours or even days.
Not the same at all.
some_random 2 hours ago [-]
Is is possible that some technologies could have longevity trade offs and not be "planned obsolescence"?
UltraSane 9 hours ago [-]
OLEDS have two HUGE advantages over LCDs
Extremely accurate and vivid colors due to their low black level.
And VERY fast pixel response times, 0.01ms to 0.03ms compared to 1ms to 5ms for the fastest LCD gaming monitors.
p0w3n3d 10 hours ago [-]
Pixel cleaning sounds little like blinker fluid to me...
Rohansi 16 hours ago [-]
I don't think learning more about what it does is going to make them change their mind here.
some_random 2 hours ago [-]
That's exactly what it is, and it's pretty important to run
baby_souffle 15 hours ago [-]
> You could probably ask the AI to look at the firmware and describe what it does.
Or ask for a patch so it runs after the monitor has been powered off for a while...
I use an LG OLED 42inch TV as a monitor and it has a setting to do just this.
ndiddy 15 hours ago [-]
I looked it up, his monitor does do it automatically after it's been powered off for a few minutes. He's getting the nag message because the monitor has been on and displaying a picture for over 8 hours.
Sha1rholder 10 hours ago [-]
I have an ASUS PG32UCDM and an ASUS XG27UCDMG, and both can permanently disable the "pixel cleaning reminder." Have you tried update firmware and look in the monitor UI?
NegativeLatency 14 hours ago [-]
Or update the firmware to do it every n hours or screen blanks or something automatic with no nag
winrid 15 hours ago [-]
Every 8 hours is insane, though
2III7 15 hours ago [-]
That is just crap UX. Sonys OLED tv-s for example do this automatically while in standby mode in addition to pixel shift while displaying an image. On the other hand Phillips OLED tv-s also ask the user if they want to do a panel refresh.
moralestapia 15 hours ago [-]
Perhaps you didn't read the text you just copied and pasted, but here it is for you:
"I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever."
No need for ackshually, the guy is clear with what he desires. That is, by the way, the point of TFA. I want my devices to do what I want, not what a product manager wants or what a dude on hacker news wants.
The author even dropped a comment here doubling down on his intent. That is the main problem, when the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
ryandrake 13 hours ago [-]
The user should be the final authority over what his computer does. Not the computer manufacturer. Not the OS developer. Not the 3P app developer. Not some product manager at a software company. The end user.
Even time computer says no, or does something without your permission, or does something counter to your wishes, or alerts you to do something, or urges you to do something, or makes you opt-out, is a failure.
willdr 12 hours ago [-]
The end user disables pixel cleaning because the pop-up annoys them. They then start bitching about burn-in within 6 months, RMA the monitor even though it was their choice to do so, and spread negative sentiment about your brand going forward for being "prone to burn in".
jcelerier 5 hours ago [-]
Yes? Are you a human or a corporation talking? Has Samsung achieved singularity status and is now posting on HN?
Besides, the negative sentiment that OP shares here sis for me much stronger than any burned pixel, annoyances like this are a sure way for me to not buy a product if I read this in reviews
2 hours ago [-]
flavelius 11 hours ago [-]
..which then forces the manufacturers to develop better solutions - people who are annoyed by manual maintenance tasks or disruptions buy them - Not a bad scenario for both sides.
cwillu 11 hours ago [-]
Cool story, bro.
fluoridation 9 hours ago [-]
I think there are actions a user may sometimes wish to take that software should simply refuse, ideally. Some actions are, and can only be, mistakes. I don't think it's a bad idea for software and hardware to defend itself against misinformed, confused, or clumsy users.
harry8 15 hours ago [-]
>...the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
Not just tell, actually nag, coerce and force, often in the teeth of their own total idiocy.
"Your password needs to be between 8 and 15 characters and include an upper case letter, a symbol and a number. (And an actually good, strong password will be rejected).
See that all the time, still, in 2026. So very smaht.
phh 8 hours ago [-]
I definitely love this article and this spirit. I've accumulated a lot of crap/cheap IoT, I'll probably owning them!
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
ghosty141 8 hours ago [-]
The CRA that will be active starting december 2027 will also do similar things like RED. Cant ship with fixed static credentials anymore or manufacturer backdoors (unless the user activates them)
hypfer 8 hours ago [-]
> for anything connected to the internet
Are you sure? iirc that (for now?) only applies to stuff with wireless connectivity, though maybe I'm misinformed or misremembering.
Which would still be "all IoT, basically", of course.
phh 6 hours ago [-]
Hum, I don't really know. I was pretty sure it applies to anything connected to the internet even if it's Ethernet-only, but double checked. And reading the EU directive, it looks pretty obvious to me that you're right, it's only for devices with wireless connectivity... (the wireless connectivity doesn't need to be wifi/internet though. like if you have a 433mhz-to-ethernet gateway it still fits).
(Technically it says "which intentionally emits and/or receives radio waves for the purpose of radio communication", I'll let HN crowd determine if Ethernet emits/receive radio waves in an enclosed channel called Ethernet cable)
trencedamp 8 hours ago [-]
I have a box of ancient Android and Windows phone handsets which I'm now looking at in a new light.
cromka 29 minutes ago [-]
Inspired by this article I started to work on migrating my cat's feeder to ESPHome. Within 2 mere hours I'm am basically done but also wanted to RE their update path to avoid having to connect to UART to flash the new firmware. To my surprise, the stock firmware has some issue with the vendor's server where it downgrades to plain HTTP after 5 retries. It exposes all keys, device id and firmware upgrade path to MITM attacks. Absolutely bonkers and it shows how bad these IoT companies are at security.
Vendor is PetKit btw.
philips 17 hours ago [-]
I just reverse engineered the Supernote note file format with an agent a few weeks ago. For years the community had been asking for a document on the format. And in a few hours the agent, with 20 something file format example fixtures and 30 something prompts, was able to reverse out the format.
It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.
While it’s impressive work from the LLM and a TS implementation is novel, there’s at least a couple of pre-existing Python REs eg. https://github.com/jya-dev/supernote-tool :)
philips 13 hours ago [-]
I know of the project but it doesn’t actually extract the stroke information. It converts the raster into vector.
My reverse engineering extracts each pen stroke directly into a svg vector.
psolidgold 11 hours ago [-]
This sounds awesome if it works as you say. Will give it a shot tomorrow! Thank you for the tokens to solve this.
philips 11 hours ago [-]
Checkout this "handwriting demo" I made. It uses the stroke information to animate each individual stroke.
It seems like most of these "an LLM solved this in only X hours! " could have been "I found an open source solution that did what I needed with X minutes of web search."
Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
Klonoar 1 hours ago [-]
Per the author, that open source project is not doing the same things as what they cobbled together.
analog_daddy 11 hours ago [-]
Ohh, sadly I relate with this feeling too much.
For all the agentic loops people seem to have come up with, the research loop or as I call it the “Desperate 10th page on Github’s crappy search results” is still not up to the mark.
Either it might be genuine rate limiting these LLM’s face or just that, they are trained to focus on implementing a solution which would be faster and user acceptable solution. (which seems to be a true looking at people pushing LLM generated code as is).
At least in my personal experience with niche projects and heck even with well documented and famous libraries, along with fancy mcp’s, llms.txt and skills; RTFM has been more relevant than usual for code that I have asked an agent to generate, since it is too eager to reimplement functionality which already exists, only if it RTFM!!
ShinyLeftPad 13 hours ago [-]
> Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art
It is definitely the case that people know less and less how to do research themselves though...
fragmede 13 hours ago [-]
If give an AI the full set of files it needs to RE a file format, and it's running xxd in tool calls in order to document the file format, I don't think it's cheating by copying it off the Internet.
fwip 2 hours ago [-]
It might be reverse-engineering it, but it also might be kayfabe. (Kayfabe is what professional wrestlers do - the storyline and matches are scripted, but it's presented as real. LLMs excel at doing this.) Similar to how Anthropic showed that their LLMs appear to "think ahead" when writing poetry to come up with a rhyme[1], so too might the knowledge of a file's structure influence how the LLM approaches analysis.
As a simplistic example, suppose one section of the file is known by the model to be bzip2 compressed - the LLM may use xxd to scan for common magic numbers that "just so happens" to include 42 5A (Bz). Every step of analysis is like this - what threads to look for, and which ones to pull on. Somebody or something who mostly-remembers the answer is going to find the answer quicker than if they'd gone in blind.
I personally own a Supernote, but I'm not a heavy user of it. For the sake of my own curiosity, what benefits will you get out of having reverse engineered the Supernote note file format? It would be super rad to be able to move my notes between other devices, which is one big plus that comes to my mind.
philips 13 hours ago [-]
I built a management website and plugin for Obsidian.
Two weeks ago I told Claude “I have a <wifi outlet relay> on the LAN at <IP>. Assume direct control of it.” And about 8 command approvals later I had a new firmware running on it.
Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
SomeHacker44 14 hours ago [-]
Surprising. I have hit its BS guardrails a lot lately, working on my vintage computers from the 80s and early 90s. Just about done with Claude.
marinhero 12 hours ago [-]
I’ve been doing this with Qwen 3.8 27B with success. Kindle, Android Tablet, and Raspberry Pi all working better and fully owned thanks to agentic help. No issues with hitting the guardrails here ofc.
Gormo 10 minutes ago [-]
What tools/skills are you using to do this with Qwen 3.8?
trencedamp 7 hours ago [-]
What did you do with the Kindle?
npodbielski 11 hours ago [-]
What about Raspberry Pi is not open?
oynqr 10 hours ago [-]
The boot firmware.
LargoLasskhyfv 10 hours ago [-]
The hypervisor running on the VideoCore, booting up the ARMs, and the OSes that run on them:
Initially at least. Had some changes of ownership and rebrands meanwhile.
Now playing: "Hot Chocolate - It's just an illusion"
Spooky23 13 hours ago [-]
You can’t be loyal to these things. I ditched ChatGPT during the peak Claude hype after Christmas.
I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
Gigachad 12 hours ago [-]
Just sign up with something like openrouter and keep switching models until one completes the task.
ascorbic 10 hours ago [-]
Paying by the token is a much more expensive way of doing it than signing up for the various coding plans when you need them.
luckystarr 10 hours ago [-]
Not if the models are way cheaper. For many tasks you can do with DeepSeek Flash, and for more gnarly problems you switch to GLM or Kimi. But sure, if you do everything in large models like Kimi K3 or GLM it gets expensive quickly.
trencedamp 7 hours ago [-]
What were you trying to do with vintage computers?
WorldPeas 11 hours ago [-]
kimi k3 is wonderful, I suggest you give it or GLM a try when you get the chance, I just use openrouter or cursor
srcreigh 16 hours ago [-]
> I haven’t actually been brave enough to write a modified firmware to the thing yet - it’s a pretty expensive monitor - but I’ll get there at some point.
Honestly if you don't have working patches, it's really not owned.
I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.
Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...
We are NOT there yet but I hope we get there soon.
Retr0id 16 hours ago [-]
If you're prepared to get out a soldering iron and/or chip-clip, you can usually back up and restore whatever IC stores the firmware you're modifying, giving you a recovery path.
> we also need good glitching tools
There are a lot already, what do you feel is missing?
beshur 1 hours ago [-]
What about automotive? I suspect automotive firmwares to be more protected already, but where do I start with playing with the infotainment systems?
srcreigh 15 hours ago [-]
How should I learn more about how to do it, what to buy, etc ? I haven't found ChatGPT to be a good teacher about this topic, and in particular re glitching, AI will refuse to discuss specifics
I have enough basic soldering to get UART attached, but not sure what to try after that.
Equipment-wise, I currently just have a few ESP32-C3s and electronics basics kit and some basic soldering stuff.
jwrallie 10 hours ago [-]
I flashed coreboot on an x220 once [0], and I think that can give you a good overall idea of how backing up and reprogramming an SPI memory works. From that you could do your own research checking the ICs in your hardware, and extrapolating to the correct tools you will need to read/write the chip you have in mind.
ch341a programmer with a clip attachment. That's basically it. A 10 USD investment. No soldering unless flash chip is SMD.
MayeulC 4 hours ago [-]
Please make sure you fix the 3.3 V output if you get that device. Most revisions have a PCB layout issue that will output 5V even in 3.3 V, which has bricked stuff before. There are many ways to fix it, one trace cut and one jumper is how I did it.
I think all of them sold nowadays have this fixed but yes, absolutely worth checking.
Retr0id 15 hours ago [-]
There are plenty of pre-2023 resources out there, especially conference talks. But, Claude has no issues discussing glitching if you have CVP.
s3p 13 hours ago [-]
I guess this is a fine reply but just seeing your earlier comment, mentioning there are tons of glitching tools out there, I would've hoped to hear about some specifics here. Just my 2c
Retr0id 10 hours ago [-]
I'd be listing tools all day, it's not worth naming anything specific unless a specific target / use case was named.
If someone said "we need good package managers", I'm not going to randomly start listing package managers without knowing what distro and/or programming language they're using.
ShinyLeftPad 13 hours ago [-]
Is this the zoomer syndrome I am hearing about lately? My friend says zoomer coworkers increasingly start asking easily searchable questions, and also (this part is not your comment, just my 2c) in a demanding tone like you owe them money. Allegedly they spend all their time in LLMs and lose the ability to gather information
I wonder what humanity will look like in 20 years if this doesn't stop.
rustcleaner 12 hours ago [-]
Look, he doesn't know what to search for. He doesn't have your experience to know what is crap and what is good info, and the big models will ninny-nanny him for '''safety reasons.''' There is so much more shit to wade through today than a decade ago. Cut the kid some slack and be a mentor! Gatekeeping kills.
ShinyLeftPad 11 hours ago [-]
It's right there in the comment, firmware glitching tools?! I have zero experience in this topic and even I was able to find exactly what the guy asked for on first page of google results
This is the same as what my friend says. She would have no idea what they are asking, fire up search engine, find the thing, and tell them to do the same. But "demand answers" is the default behavior for zoomers
nl 5 hours ago [-]
Why this judgemental tone?
One person's "asking a question" is another's "demanding an answer"
Clearly both search engines and chat interfaces are merging, and clearly they should be because they fulfill the same kind of requirements.
Complaining about that seems a lot like those who complained about how the correct url for altavista should always be altavista.digital.com, not altavista.com and how autocomplete is bad.
csh0 12 hours ago [-]
I have encountered this behavior in people of all ages for as long as I can remember.
ShinyLeftPad 11 hours ago [-]
I haven't and neither my friend
perching_aix 11 hours ago [-]
And what are we supposed to do with the two of you apparantly living under a rock [0], and going through baby's first "kids these days" moments, exactly?
Never heard of LMGTFY ("Let Me Google That For You")? Why do you think it exists?
Or "Google / Wikipedia is your friend"?
Or RTFM ("Read The Fucking Manual")?
Really not new inventions (and "zoomers" were there for them, cause the oldest ones are pushing 30! [1]). Not hard to search for either, by the way...
[0] or rather, going through some very conveniently selective amnesia
[1] just to really give you a sense of how stupid this generation-xyz thing is, this "generation" includes people whose first OS was entirely possibly Windows 98, and at the same time, people whose first OS was Windows 10
ShinyLeftPad 10 hours ago [-]
I heard of them but have literally never seen any of those phrases on HN. Therefore I'm saying what I'm saying;)
I saw LMGTFY link once maybe...
perching_aix 11 hours ago [-]
> Is this the zoomer syndrome I am hearing about lately?
Sounds easily searchable...
15 hours ago [-]
Retr0id 17 hours ago [-]
Using LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic.
The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
stackghost 12 hours ago [-]
I find whenever I do this I run into the bullshit cyber guardrails. What model are you using and how are you prompting it?
Retr0id 10 hours ago [-]
Opus 5 with CVP, no special prompting. In this instance just about any larger model from the last 12 months would have done the trick.
stackghost 32 minutes ago [-]
>with CVP
Ah, there's the rub.
teddyh 16 hours ago [-]
Key takeaway:
> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
_kb 15 hours ago [-]
The preceding sentence is equally prescient:
> Operating systems aren’t really equipped to work with the user to ensure that a microphone stays a microphone, and doesn’t spontaneously turn into a keyboard that hits Win+R and drops a payload to steal all your data when the room is quiet enough that it can assume you aren’t watching.
In a world of USB-C everything we no longer have power supplies that are physically bound to power delivery, HDMI or DP display connections that have constrained data channels, or analogue mics, headphones, and speakers. Any device can dynamically change what it senses, does, or emits.
arboles 9 hours ago [-]
I recently realized something similar. I think that usb-proxy[1] could be used to force what looks like a mass storage device to stay a mass storage device, and likely could be built to be a sort of firewall. usb-proxy is a toy project showing that you can physically "MITM" USB with an RPi, but it could be a starting point.
Was daydreaming the other day about how this could be used by adversaries to hack even air-gapped computers. Any peripheral which contains a microchip and some ram is a vector. Does the compartmentalized facility ever bring in a new monitor, or mouse, or keyboard? All of those things could be hacked to hack their new host. And then taking data into/out of the facility. Which devices have lights? Any LED that can be blinked is a low-speed output channel. Which have light-level sensors, or sound sensors? Or any RF capability? If bluetooth is disabled by software but the hardware is still there...
If I was writing a novel, the top secret facility would be cracked open by the smoke alarm, which has a wired connection to the central fire control and runs a little microprocessor. There is enough storage for 20 programmable voice alert messages. I/O includes an LED and also a light sensor. After the attacker gains control of the smoke alarms -- reach to every room of the secure facility -- their focus turns to mass poisoning peripherals until one makes it into range. A poisoned monitor detects the smoke alarm blinking a coded broadcast via its LED during darkened overnight hours. The monitor responds with flashing code of its own. That creates a communication path back to the controlling LLM. From there its like attacking a normal networked device, just with a slow data link in the middle...
_kb 12 hours ago [-]
In environments where the threat model requires it you can/must already buy hardware variants that are non-radio. It's not just disabled in software but is a different physical SKU. Likewise data diodes for USB, audio, or display connections are also common.
The novelty is the uniform adaption of USB-C for the rest of the world and the endless attack surface that provides.
rustcleaner 12 hours ago [-]
This is one reason why I run Qubes OS as my daily driver.
mschuster91 9 hours ago [-]
> HDMI or DP display connections that have constrained data channels
HDMI has theoretical support for 100 MBit/s Ethernet [1] but in practice I agree, haven't seen that one used in practice.
IIRC it came in 2009 with HDMI 1.4, at that time Wifi in practice was mostly 802.11g with IIRC 20-ish MBit/s as 802.11n was still formally a draft... the idea was to give high-bandwidth networking to home entertainment devices without requiring to run physical Ethernet to each tiny device, but it quickly became superseded by 802.11n Wifi on one side, and on the other side, the "enrichment" of stuff on DVDs or broadcast TV with internet-based content never truly materialized.
This is why most of the browsers rejected these specs. They are super useful, but the security risks are incredible. Most USB devices were not designed to hold up to being exposed to the internet.
AshamedCaptain 16 hours ago [-]
I kinda remember that the counterargument Google used is that only devices with a special attribute would ever be available through WebHID, ensuring that such older devices would never be exposed.
Cue my surprise when it turns out you can use WebHID to program a Minidisc / Net-MD device [1], so.. they never did implement that filter, apparently. I mean, certainly it is useful, but ... What The F., Google?
The user has to first specifically pick the device from the list and grant the website access. If a user is confused by a permissions prompt and has no idea what is going on, the default path is to reject the permission.
SchemaLoad 15 hours ago [-]
In the real world the default action for a user when presented with a permissions popup is to accept it because they get asked 20 times a day, have no idea what the implications of it are and just want to get on with their day.
So software designers need to avoid asking the users to approve potentially highly dangerous things.
Jach 12 hours ago [-]
This is untrue. Chrome's "acceptance rates" for proceeding through its bad SSL cert warnings used to be pretty high, but with a redesign they basically flipped the numbers so most people didn't proceed to connect to the site. Similarly with cookie banners, where making it more difficult to say no (by e.g. moving a decline button to a second interaction layer) meaningfully raises acceptance rates; if users were just blindly accepting everything, then there'd be no reason to make it harder to say no. Apple's App Tracking Transparency (ATT) prompt has users overwhelmingly answering no even years after introduction (though of course opt-in is increasing). A study on permission prompts in Android found that the main factor in first-use denial rates was whether users thought the app needed the permission it was requesting or not, showing some actual comprehension of what they're being asked. Another found higher denial rates if the frequency of the prompt was on every access instead of once, rather than apathetic blanket acceptance.
Design prompts for potentially dangerous actions so refusal is easy and what's being asked is legible, and people will refuse plenty.
Barbing 13 hours ago [-]
I think Safari does this with popups & downloads. Tiny little icons that barely appear [to change]. Can annoy me when I miss them but sometimes I figure maybe it’s for The Greater Good.
jeroenhd 9 hours ago [-]
WebHID being used to access a microphone is risky though. Microphones are already often exposed to web browsers, so asking for microphone access wouldn't be out of the ordinary.
Maybe MD drives aren't really at risk, but things like HID peripherals definitely are.
AshamedCaptain 15 hours ago [-]
You realize that most of the time that you are giving access to an older HID device, you are giving the website permission to convert that device into a persistent backdoor forever? No matter if you later close the browser or revoke the permission -- the damage has already been done? Most devices predating WebHID and the like have almost no protection (why would they?), and you can corrupt or even entirely replace the firmware quite easily. heck, NetMD is one example (the browser can overwrite its firmware with no trouble!), as are the devices listed in TFA .
It is basically the same reason most desktops do not give the logged in user access to /dev/hidraw*, even though it makes a shitton of sense and would simplify many things greatly.
This is one of the few areas where I think Mozilla did the right thing without question.
NavinF 15 hours ago [-]
WebUSB has been live in Chrome for 9 years and nothing happened. Compare to all the features that result in people getting hacked every day. Your threat model is ridiculous.
AshamedCaptain 14 hours ago [-]
Look, I find it funny that I find myself arguing on the other side of the discussion that I'm frequently on, but here is where I draw the line, and I think what is ridiculous is to think otherwise.
How many hoops Google asks you to go to install an Android app ? (Androids amounts to basically the most sandboxed environment one can have today; malware installed there can practically do _nothing_) MANY. Centralized register of apps and remote blacklisting, a lot of permission prompts, password check, and they are even literally pushing to even have a physical 24h cool-off period if you skip the centralized register.
How many hoops does Google ask you to go an allow a random website unfettered access to destroy your hardware? One. Permission. Prompt. In a bubble prompt, that barely registers above noise compared to other permission prompts browsers ask.
Of course these are two ridiculous extremes, but they exemplify the point. There is a reason a browser won't allow a random website to write over random sectors of your hard disk just because you said "accept" to a bubble-style permission prompt about wanting to "save files to your hard disk". The line has to be drawn somewhere, and allowing what basically amounts to raw access to IO ports just after a single permission prompt listing the device name is where I draw it. Any user, even knowledgeable ones, is simply going to be _incapable_ of truly understanding the risks behind allowing this access.
I would be much more in favor of allowing random IPC to services in your local computer (after a permission prompt) than this., something that is equally useful if not more than allow raw access to HID.
Devices need to be hidden behind drivers that multiplex and control access to the device at the OS level. A bus that was never meant to be exposed to user-level access should not be exposed to random programs much less websites. This is not security, this is "mistake prevention" level, in the same way operating systems disallow a random user-level program from overwriting the hard disk.
And do not read this as "devices should sign their firmwares and what not". That is (for me) definitely the wrong take but literally the only take that is left on the table due to Google's stupid behavior.
mschuster91 9 hours ago [-]
> How many hoops Google asks you to go to install an Android app ? (Androids amounts to basically the most sandboxed environment one can have today; malware installed there can practically do _nothing_) MANY. Centralized register of apps and remote blacklisting, a lot of permission prompts, password check, and they are even literally pushing to even have a physical 24h cool-off period if you skip the centralized register.
I 'member (and miss) the old Android days before everything became the locked down hellscape Android is these days. And I also member why it became that way, there was a loooot of bad actors exploiting that open model.
For operating systems it's similar. DOS/Windows up to and through ME didn't have the concept of different user levels, the file system didn't allow for it, and if you had physical access to the machine it was trivial to corrupt and subvert it. Only with Windows XP, Microsoft switched the consumer OS to NT and its multi-user model.
And so it will be for WebUSB et al. First it will be a pretty open and unrestricted world, and only if there turns out to be a significant problem, security will (need to) be tightened.
chrismorgan 8 hours ago [-]
Note that when you say “rejected”, Mozilla’s position has actually shifted a bit. At the end of 2022, it shipped MIDI in the form of an extension that it will prompt to install for the purpose, with more detailed information and a couple of other details that make it less unsafe. After a few years of that, consensus has grown that this seems to be working acceptably, and that the technique may be considered for other risky areas. They haven’t said anything about USB publicly, to my knowledge, which is definitely way more dangerous than MIDI (even SysEx), but I have heard one rumour (of dubious provenance) that they may cautiously proceed with USB and such too some time soon. Though this sort of thing definitely weighs against that, showing that maybe they were right the first time.
pudgywalsh 16 hours ago [-]
The key takeaway for me was he bought a $300 microphone and is acting indignant that he has full access to his own hardware via — gasp — a command shell.
Do we live in a bizarro world now where we expect — no, demand — our hardware be locked down?
It's worth mentioning all USB mics are toys anyway. Analog interfaces have gone away — artificially so — now they cram them into the device.
All mics are analog.
rustcleaner 11 hours ago [-]
You make a good point: hardware should not be default-locked from owner control and manipulation in the name of security. In fact, in the name of security, the default should be open enough to not only manipulate and reflash through owner accessible channels, it should also be easily flashable through chip clips in the worst case compromise scenario. Owner control of all Universal Machines in an object he owns must be a paramount right, akin to the first and second amendments in the bill of rights! This includes your game consoles, vehicles, stoves, washing machines, TVs, microwaves, and even that Qualcomm processor in cellphone basebands. If it is a Universal Machine which executes code from writeable storage (or firmware/microcode provided to it, like during OS boot or driver initialization), it must permit owners to change it. If it comes with cryptographic integrity check keys, the owner must be able to both write his own keys and purge the OEM's keys. Behavior should not change, even the warning Google Pixels give immediately on turn-on are unacceptable, unless it does it by default for the OEM's keys and firmware too; no change in product behavior or appearance when an owner exercises his right to modify his Universal Machines, except where the change arises from the firmware itself that the owner applies.
16 hours ago [-]
bobek 8 hours ago [-]
TBH this is one of a few things that feels exciting about LLMs. I've recently revived a flip-dot panel from an old bus by reverse engineering and replacing its firmware -- https://www.bobek.cz/buse/
brammeleman 7 hours ago [-]
Looks like the video links are broken, would love to see these displays in action.
e-topy 3 hours ago [-]
oh wow, this is cool! I managed to reverse engineer a BS120 led display[1], we ended up hooking it into our hackerspace's[2] home assistant instance, displaying everything from static messages to when trams are departing. I enjoyed the challenge of REing it by hand, but the ESP32 firmware to connect it was vibed by a fellow member.
At this point manufacturers should just open-source their firmwares as there's no barrier for entry to reverse engineer it. They will instead gain from army of end-users willing to put their time and tokens into fixing their bugs for free.
tuckerpo 16 hours ago [-]
Ah, I remember when reversing hardware took weeks / months, an oscilloscope, logic analyzer, Ghidra/IDA, Wireshark, breakout boards, wireless sniffers... back in the olden days of... 2019.
fwipsy 16 hours ago [-]
if an AI could do it without an oscilloscope, probably a human could too.
drivers99 14 hours ago [-]
It's kind of funny, but AI can also use an oscilloscope. My friend vibe coded a software synth on a Raspberry Pi Pico. When he realized his oscilloscope had a network interface, he had Claude figure out how to connect to it over the network and analyze the actual audio output.
nabilt 10 hours ago [-]
I had claude write an mcp server to talk to my scope since most are connected over Ethernet. It was pretty fun.
I posted [1] a few days ago my experience using LLM to reverse engineering an entirely undocumented device that was only supported by a (crappy) Windows application, and it was honestly remarkable how good Claude was at decompiling the Windows EXE and reverse engineering the protocol. Very exciting. "The developer refuses to write software for this device" is no longer as scary as it used to be.
I did this a while back with my Eaton UPS and Opus 4.8, glad I didn't need to install windows 11 just to push a blob. The day when a LLM os can make unique drivers will be one I wait for
NavinF 15 hours ago [-]
>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying!
Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
kestrel-robotic 14 hours ago [-]
> the LED can't be controlled from software
If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.
You can say a lot about Apple but the engineering is clever at the hardware level.
It's not. I can place my iPhone next to my trackpad and the MacBook thinks I closed the lid.
BYazfVCcq 7 hours ago [-]
That's not what people mean by 'bypassing', turning it off is obviously easy. The point is that activating the microphone while the lid is closed is pretty much impossible.
ryandrake 13 hours ago [-]
It's not even that clever, really. The camera power rail must be physically close to the camera, so it's trivial to hang an LED off it. A device manufacturer has to go out of their way to make it so the LED and camera function are independent, and I'm sure many do, for the worst reasons you can possibly think of.
Gigachad 12 hours ago [-]
It's more a testament to how little most companies care. The solution is simple and yet most products are defective.
randyrand 5 hours ago [-]
For most products the LED is not a simple on/off indicator. It signals device state, user confirmations, ota updates, etc etc etc.
I’m at a loss for how you would signal all of that without a GPIO.
Gigachad 5 hours ago [-]
The record indicator should be purely reserved for showing if the camera is on. If you want to show all that other stuff, put a second LED on it.
Marsymars 11 hours ago [-]
Nest cameras used to have a user toggle to enable/disable the camera LED; not the worst reason I can think of.
mschuster91 9 hours ago [-]
Yeah, and then came people hiding cameras in places where you clearly did not want a camera to be. Bathrooms in public areas, hotels, workplaces and AirBnBs are a much too common issue, it's like daily news some creep gets busted for running cameras.
Marsymars 2 hours ago [-]
Yeah, my implication was just that the worst thing I could think of were cameras where the owners don't realize that some third-party is recording them.
LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.
mschuster91 2 hours ago [-]
> Yeah, my implication was just that the worst thing I could think of were cameras where the owners don't realize that some third-party is recording them.
At the point we are in time... honestly, I don't expect this thing called "privacy" any more. And I'm, notably, German. Glassholes, camera surveillance everywhere, our police is more and more turning into the rabid hellscape that is American police with far-right authoritarians at the helm and more and more forces joining up with Palantir or working on a European alternative.
I'm dead sure that at least law enforcement plus dedicated individuals with access to ad data brokers can work out precisely when I had a wank and what I wanked to, now there being a video of me wanking would only be the icing on the cake.
> LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.
Many even forget about that piece of opsec, which is why they get caught in the first place, eventually the tape falls off.
avidiax 9 hours ago [-]
It could be a typical design that the camera and LED always have power, and the LED is switchable.
Giving the camera plus LED a separate power supply means that the camera has to boot or come online, which maybe increases the dwell time. And the camera is not visible on the USB bus when powered off.
I think there's more engineering to Apple's design than it first seems.
aaronmdjones 7 hours ago [-]
The thing visible on the bus is the interface chip, not the sensor. Most cameras which I've seen hardwire their activity LEDs (it is impossible to grab stills or record video without lighting up the LED) do so by connecting the activity LED to the sensor power rail. With the sensor powered off, the device is still visible on the bus but you get no usable image data.
AshamedCaptain 5 hours ago [-]
This still would allow one to "strobe" the power line making it impossible for a human to see the LED but the camera could still capture snapshots and at a decent framerate even.
bayindirh 6 hours ago [-]
One of my old Logitech webcams have its recording light wired up to V4L2 protocol directly. I can change its recording light mode (on/off/blink) from software by changing recording light mode directly. Wonder whether that Insta360 also had that.
I'd have tried that first before diving into the firmware head-first.
sneak 14 hours ago [-]
Apple also claims that iMessage is end to end encrypted. Their privacy stance is 99% posturing.
Barbing 13 hours ago [-]
The teardown showed this is the 1% right?
Also I thought you could trust iMessage if, unlike everyone, you disabled iCloud backup (and, unlike everyone, so did the recipient). Perhaps a way for the feds to be able to pin dumb criminals while giving investigative journalists & dissidents a way to stay safer.
exprez135 13 hours ago [-]
According to Apple, you can have iCloud backup enabled while maintaining E2E encryption with their Advanced Data Protection option:
You do have to be sure to not enable web access via icloud.com
Gigachad 12 hours ago [-]
You also have to make sure everyone you contact did this, which is impossible.
Much easier to use a 3rd party app like Signal.
MertsA 12 hours ago [-]
Even with "E2E" encryption with iMessage, you're still trusting Apple completely and totally with key distribution. If a new device is added to your account by an attacker or by Apple themselves, your existing devices will happily loop them in to share iMessage access with them. The vast, vast majority of iMessage users are never going to dig into the Apple keychain app to actually check what keys are being trusted and this is something that can be targeted to a single account so no one outside of Apple never even needs to know it happened.
> An unrecognized new device was added to that person’s Apple Account. This alert might mean that the person you are messaging has an issue with one of their devices, or that a sophisticated attacker might be attempting to eavesdrop on the conversation.
My understanding is that iMessage implements PFS. To get around PFS and access older messages, one needs to get their hand on a backup, which needs fully enrolling a device, not just messaging key exchange hackery.
And as far
as trusting Apple with key exchange, well, if you're running their OS and hardware, I suppose that trust of key exchange is the least of your concern (or part of the whole deal anyway depending on how you look at it)
soundworlds 5 hours ago [-]
An Agent helped me get a Windows XP Korean MMORPG private server running on my Steam Deck last week. The community obviously got us most of the way there (huge props to them) but setting it up on Linux seemed like a brick wall. Now it works. Amazing for keeping old tech open and running: https://github.com/P0nk/Cosmic/discussions/350
SlightlyLeftPad 16 hours ago [-]
I had used codex to reverse engineer an electric skateboard to unbrick it. It was a bit more involved because it required soldering wires directly to the UART headers in a very awkward location.
Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
darknavi 16 hours ago [-]
This is giving me the confidence to RE my cat feeder. The company (Petlibro) has an outage and now my chilled wet feeder that should be a dumb, offline feeder is basically bricked now.
The device reports fine wifi but the backing services are totally busted.
I have one of their dry food ones and no longer need it. Sad story, but it happens.
My cat scarfed and barfed periodically, and I always wanted the Petlibro (the simple one) to slow feed by incrementally turning the auger, just to see if it helped. I might dig it out and try my hand at this.
SoftTalker 15 hours ago [-]
Why do you have a cat when you can't be bothered to feed it yourself?
NegativeLatency 13 hours ago [-]
Try getting a cat sitter around Christmas or a holiday weekend and then ask this again.
recursive 14 hours ago [-]
You're making some assumptions.
Weird question anyway. Why eat food at all if you can't be bothered to farm it yourself.
mschuster91 9 hours ago [-]
As soon as you have more than one cat, which you absolutely should because cats at least when held in captivity require playmates matching their physical ability, you should have some sort of smart feeder system.
Otherwise, you will inevitably end up with one chonk and one cat with food panic that gorges on whatever food it can grab in a single setting before everything is gone.
compiler-devel 16 hours ago [-]
It's amazing to see LLMs give us software and hardware freedoms that the open source movement has only ever dreamed about.
layer8 16 hours ago [-]
The flip side is that this might become a thing of the past for future hardware/firmware, if AI hardening becomes standard practice.
There’s no substitute for having open systems that aren’t cryptographically locked down by the manufacturer.
spaqin 15 hours ago [-]
We were already there. For most people, we are still there. For most devices (especially popular ones, with enough manufacturing volume) there's just enough hardening, downgrade prevention, encrypted or signed firmware blobs, on top of already rare reverse engineering skills and patience, to make it infeasible for most people to give it a crack. Using an LLM for that also isn't a mainstream idea either (plus you're unlikely to have a Claude subscription if you're not a software developer in the first place).
Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
rustcleaner 11 hours ago [-]
>We were already there. For most people, we are still there. For most devices (especially popular ones, with enough manufacturing volume) there's just enough hardening, downgrade prevention, encrypted or signed firmware blobs, on top of already rare reverse engineering skills and patience, to make it infeasible for most people to give it a crack.
This should be illegal. Any politicians who run on [economically, financially] doing to these companies what is being done to Russia and Iran, if they refuse to immediately publish their hardware private keys, I will vote for. Up to and including jailing boards, stiffing bond and equity holders, and selling their assets as scrap, if they choose to purge their keys to prevent disclosure or if disclosure is impossible due to technical design. Maybe if a few trillion dollars worth of businesses suddenly vaporize into legal smoke, the remainders will start behaving for the next hundred years...
AshamedCaptain 16 hours ago [-]
I think that this is not true -- the achievements mentioned here are hardly ground breaking and mostly build on work that was already done years before LLMs were a thing.
There are things that the "open source movement" dreams about, and one just has to search around... E.g. like codecs, Qualcomm's aptX lossless, adaptative, and other more recent variations.
SchemaLoad 15 hours ago [-]
It's not new capabilities, it's new levels of access. Reverse engineering this stuff used to be a very tedious process which required a lot of specialised skill. Which is why most devices haven't been reverse engineered or hacked despite being full of low hanging fruit.
wartywhoa23 5 hours ago [-]
Did the open source movement dream of outsourcing what they loved to do themselves for free, as in both beer and freedom, to products which are trained on the corpus of their own knowledge without any consent and sold by behemoth corporations on a subscription basis?
matheusmoreira 15 hours ago [-]
Brings me a lot of joy to see these articles. They've inspired me to reverse engineer my laptop again.
bigyabai 16 hours ago [-]
"only ever" feels like a stretch. Libratbag, QMK, OpenWRT, Nouveau and Asahi all took up the task without much or any AI help. They're not all just dreamers.
apricot 13 hours ago [-]
Enjoy it while it lasts.
kibwen 16 hours ago [-]
There's a difference between the people sitting at the table and the mice scurrying around catching the crumbs. Freedom is sitting at the table. The OP, sadly, is catching the crumbs.
15 hours ago [-]
ziofill 4 hours ago [-]
Perhaps I’m daydreaming, but maybe some vendors will accept this new reality and begin just selling the hardware without locking users in. Perhaps they’ll even make it easier for users to truly own their products.
neop1x 2 hours ago [-]
No, they will just encrypt firmware, add more signature verifications and lock devices to accounts in order to complicate reuse, increase sales and produce more ewaste.
ziofill 2 hours ago [-]
I agree, but like many others I'm willing to pay a fair price for that freedom and ownership, and I believe there is a customer base to be captured. And in the end there's a cost for a company to put all of those locks in place, which they could simply avoid.
seanclayton 3 hours ago [-]
DIY kits have been a thing... forever? There's lots of open source hardware out there, and some you can even buy if you demand commercial access.
lennart-rth 4 hours ago [-]
I did this just yesterday with a smart light. Used Deepseek-v4-flash. In about 2h I had a custom firmware on the smart light running that I could control from its api endpoints. Also now Im hosting a small web-server on there that lets me set schedules and sleep timers.
No im not relying on their proprietary cloud anymore to toggle my lights. Which is insane to start with. Why should my phone that is in my home network need to send the "light on" command ot some cloud in a different country, only to then send the command back into my home network and turn the light on.
Im definitly very exited to try this our with more devices in my live.
fodkodrasz 9 hours ago [-]
People are praising how this new age of owning our stuff is here, while actually all this will bring is stricter lockdown in every level of the supply chain. Enjoy while it lasts, but I expect even more closed stuff, and less openness from these t.rends
simpaticoder 9 hours ago [-]
The other option is to look for better products that take simplicity, security, ownership and verifiability seriously. I think there's a market. Consider Precusor[0] who's design philosophy could be duplicated. Such a company could become the Anker of computer peripherals: build quality products that decommoditize markets. Now is the time to make such a company, because by the time the peripherapocolypse hits (in a few months) by then it will be too late.
If I can't hack it with local access and an AI, a random hacker can't do it either.
I do lament the loss of control, but the increase in security will be objectively good for humanity as a whole.
Cthulhu_ 8 hours ago [-]
While closedness is bad, I assumed peripherals like these were closed anyway; the fact they were hackable implies they were not secure enough.
So if closed means they are secure, which 99.99% of end users expect, I'm actually okay with it.
attila-lendvai 3 hours ago [-]
closed is never secure. it's just open only for a smaller circle.
pjmlp 9 hours ago [-]
Well, the takeway is that we should keep pushing to write everything in Assembly and C, so that human errors allow such "ownership".
wartywhoa23 5 hours ago [-]
AI PR department at it again: sell to hackers what they ostensibly used to love doing themselves babbling about the ideals of freedom and openness.
So much for the "hackers", I guess.
simonw 14 hours ago [-]
We have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.
isoprophlex 11 hours ago [-]
I desperately want this, but our Frame has never been connected to the Wifi, and I'm really reluctant to do so, as it will probably start snitching and/or delivering ads...
_joel 6 hours ago [-]
Adguard and Smart TV blocklist might help. It's crazy how much my Sony wants to sneak out behind my back if I'd let it.
brusseliz 6 hours ago [-]
The tv-ws-api can be used over ethernet. I control my Frame TV from a pi through direct ethernet cable and the pi separately connects to my home LAN over WiFi and serves an app for Frame art control. The TV has never had direct access to the LAN or internet. Check the frame subreddit for several such projects.
isoprophlex 2 hours ago [-]
excellent! this is just what i'd find allowable. direct frame-to-internet seems like a nightmare unless you'd create your own firmware like another commenter says. thanks!
wingtw 10 hours ago [-]
New, ad free, firmware is obv a couple of prompts away...just sayin... ;)
vunderba 14 hours ago [-]
Nice! I actually built something similar back in early 2023 [1], which used a collection of SDXL models to generate a new random painting every hour upscaled to 4K and then broadcasted to my frame using the Samsung WS API wrapper [2].
Neat. What’s the lift from here to get a zero-token spend image upload?
cromka 8 hours ago [-]
What I wish is that we started reverse-engineering audio receivers, many of which run regular Linux. Manufacturers tend to release the new models with hardly any hardware changes, sometimes only software updates. To be able to backport an Airplay2 to an older, fully functional receiver would be amazing.
I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
aetherspawn 12 hours ago [-]
How’d you get Opus 5 not to just give up instantly for reverse engineering? Are you sure you’re using Opus 5 and not 4.8 by automatic fallback?
I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
schlarpc 12 hours ago [-]
I have CVP access, which removes the external refusals for Opus 5. I submitted my LinkedIn and Github and got approved in less than 10 minutes.
aetherspawn 8 hours ago [-]
Are you on an enterprise plan? I’m on a personal plan so I never bothered. I assumed they wouldn’t approve.
Also is your LinkedIn cyber security adjacent?
schlarpc 7 hours ago [-]
Personal plan, but yes, my day job is being a security engineer for big tech.
cowboylowrez 3 hours ago [-]
Whats your thoughts on this being a temporary phenom, that will last until big corp applies AI's to resist this? Reading your article I get the feeling that the only security measures that you ran up against were just the obscurity defeated by disassembly. Plenty of posts here going "enjoy it while it lasts" but since you are actually working in the security field I'm curious about what you think of bigcorp pushback against this sort of thing?
SubiculumCode 14 hours ago [-]
I guess there is this dream that AI will help us finally close the Linux driver gap, and maybe even conquer the android phone closed hardware driver conundrum making almost every phone locked down. One can hope.
cromka 7 hours ago [-]
I definitely managed to get Linux running in full on my Xiaomi Pad tablet, each and every feature of it! Writing drivers is a breeze now, what remains difficult is upstreaming them.
throwyawayyyy 16 hours ago [-]
I initially thought, but why would you want a "webcam whose activity LED I can switch off while it records"? But then I think I got the point: why would one want a webcam which _could be hacked_ so that its activity LED didn't go on.
drfloyd51 16 hours ago [-]
I am certain if it can be “tricked” into using it with the LED off, there is certainly a feature being sold to “enterprises” where it happens on purpose.
ks2048 15 hours ago [-]
I can see the benefit of from-scratch personalized software, but in the spirit of open-source, how about all the world contributes to useful software for everyone else?
Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
ryandrake 13 hours ago [-]
I'm starting to believe that bespoke, personalized software is the only way to combat feature bloat. Every software (proprietary or open source) I download and use has features I don't want getting in the way and bugs that the developers/maintainers are not prioritizing.
I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
raybb 10 hours ago [-]
I posted this on another thread but can someone please run this on some old iPads so we can be able to fully install Linux on them. If AI is so good surely it can do that and save millions of devices from turning into ewaste.
echelon 10 hours ago [-]
You can!
Don't be afraid to try. You're limited only by time and imagination now.
lifeisstillgood 16 hours ago [-]
I am wondering if there is a list of “things you should learn to do with your LLM”
(But not the rubbish ads youtube keeps showing me)
Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.
jfsebastian 9 hours ago [-]
My Sony TV also faced some issues in the past, which at least let me start some investigation. Unfortunately it confirmed my assumptions that the hardware is very limited and already runs on full load most of the time. Still thinking about putting some more effort into this, but killing the device was also one of my concerns.
A really fun project was extendending the abilities of my reMarkable Pro. I missed a decent Manga Reader on the device, so I created a native one which makes use of my custom server.
mportela 4 hours ago [-]
Mind sharing it? I would also love a manga reader for remarkable!
SchemaLoad 17 hours ago [-]
I'm hopeful that in the future we can end planned obsolescence from devices that require companion apps which eventually get shut down. Just vibe reverse engineering replacements.
diabllicseagull 14 hours ago [-]
we could have ended planned obsolescence decades ago if we put strong policies in place. I would really like a systemic solution instead of every-man-for-himself vibe coding. I've been following the "stop killing games" movement for that reason. fingers crossed.
nulltrace 16 hours ago [-]
A replacement app could just send the vendor-signed image and leave the signature check to the device. Plenty useful once the official app disappears.
arn3n 17 hours ago [-]
This a fascinating security write up. I had no idea the models were this capable for reverse engineering.
I heard CISA is getting defunded. I wonder if it'll become a common assumption for Americans that all their devices are just perpetually compromised.
tptacek 17 hours ago [-]
I'm not sure CISA ever did anything material about this problem, or was likely to in the future.
micromacrofoot 16 hours ago [-]
we haven't even seen the peak yet, as the author says
> Network-connected devices seem near universally fucked at this point?
lrvick 12 hours ago [-]
> I can’t help but think about what an AI-equipped automatically-reverse-engineering worm could do today.
Everyone should read Daemon and Freedom, like right now.
schlarpc 10 hours ago [-]
I didn’t put this in the post, but yeah, I think about Daemon almost every day at this point. Unbelievably prescient novel.
That is the second book, but yes. Read Daemon first.
tired_and_awake 12 hours ago [-]
I spent a decade in robotics and have built firmware for dozens of devices. And yet I was never able to successfully fix my webcam device driver on linux with Claude. I'm jealous of this person's prompting skills! Or perhaps pwning is easier than fixing the nightmare that is Intel open source device drivers?
lionkor 9 hours ago [-]
There are two nuances here;
1. The author might be exaggerating or lying in regards to the capabilities, ease of use, and result
2. if Claude can do it without hardware access, I struggle to see how it could be anything other than unsigned unencrypted firmware images that you can unpack and mess with
trebligdivad 16 hours ago [-]
The i2c over USB with no auth is just way way too common; I've also seen that on a device.
megadragon9 10 hours ago [-]
I did something similar but with smart home devices. I use the homebridge interface to connect my smart home devices to Apple's homekit protocol. Some homebridge plugins for my devices were outdated and no longer maintained, so I asked Codex/Claude to help me create a patch of it as a local fork, so my smart home devices can still run without problems.
It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
wg0 2 hours ago [-]
But seriously - is software industry over?
Where the next talent would come from?
snowwrestler 11 hours ago [-]
Maybe this is what Jevon's Paradox looks like for LLMs.
Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
a_bonobo 8 hours ago [-]
I've spent SO MUCH TIME in my life trying to get laboratory machinery, usually only ten of them in the world, to spit out their data nicely. They have UIs but usually god-awful, and all data is hidden away somewhere (they're written by biologists, for biologists). I wish I could go void some warranties....
sshagent 7 hours ago [-]
This is great stuff. Wouldn't this be lovely to go "fix" misbehaving devices (LG TV)
mastermage 9 hours ago [-]
this is interesting, while i greatly apreciate the ability with claude code to basically customize my own firmware. There are things that I am strictly speaking wondering about the authors choices. The Author removed Pixel Cleaning? As far as I understand Pixel Cleaning is a process to make sure your OLED Monitor lives longer, why would you want to not do that?
8-prime 8 hours ago [-]
My monitor can run a pixel cleaning automatically when it detects that there is no longer a signal coming in. That way it periodically cleans, but has never done so while I was using it. I presume the author uses the same mechanism and just doesn't want to be bothered about it.
kachhalimbu 15 hours ago [-]
Sidenote to the technical discussion. The article read like a Martha Wells murderbot novel to me. Fascinating.
Shocka1 16 minutes ago [-]
Yep, Claude did well here. From the experiment, to the website design, to more than likely all the writing/summaries. What is truly fascinating is not that long ago people were doing hard experiments regularly like this without any LLMs.
Like Dublin, in the rare ould times.
Tepix 10 hours ago [-]
Printers are a juicy target, they can have enough CPU/RAM/storage to be a good hiding place for backdoors.
Or you just want to patch out rejection of 3rd party ink/toner.
trencedamp 8 hours ago [-]
This is the first exciting thing I've seen done with LLMs in quite some time. Turning on or off an LED doesn't seem world shattering, but the idea that we might be able to unlock or add functionality to hardware we own makes me giddy
cj00 11 hours ago [-]
This is timely! I'm trying to take control of my Echo Wall Clock which connects to an Alexa device that I want to get rid of. There's very little info on it but Claude was able to find the FCC filings and now we've got lo-res images of the circuit board. It's inspecting the test pads on the circuit board now to see if it can figure out how to replace the firmware.
Marsymars 11 hours ago [-]
I have interest in this. My Echo Wall Clock is the only reason I still have an Alexa device in my home.
hollow-moe 9 hours ago [-]
Did something like this to play RTMP-over-HTTP from a security camera, no server required. didn't poke for rce yet. And same for a capture card with a HDMI loop out that was dropping audio when the monitor you plugged into it didn't advertise sound support in its edid, now it works.
utopiah 9 hours ago [-]
Honestly I do like this trend if it genuinely leads to more interoperability. Im not sure that is the case though and in fact I worry people will start to imagine that anybody can do that in no time and that future devices will remain hackable this way. I have no doubt it was fun for OP to do but I bet most people who try that, people with less understanding, will inevitably end up nowhere or, worst, with bricked device in unrecoverable states. I feel this is one of the best use of AI at the moment, namely gaining agency by having devices do what their own wants and I hope it will lead to manufacturers selling both safer AND more interoperable devices but I'll remain prudently skeptical.
pmdr 10 hours ago [-]
I suspect all this will go away soon, even from Chinese models for, uh, security reasons.
hypfer 9 hours ago [-]
Maybe, but also the cat is out of the bag, as open weights models can do it.
I suppose you could make having those illegal through on-device scanning and legally mandating usage of operating systems that do that?
Not sure. Not sure if this tech can be contained.
Dario does it for the wrong reasons, but it's not like there would be no point in his fearmongering.
__
I wonder if someone will try something like with printers, in that new and more powerful compute units see signatures of models and just refuse execution in the same way inkjet printers refuse to print euro bills.
I'm not sure if that would be a sensible thing to do, but that is a different question from "will someone try that path?"
touchme 7 hours ago [-]
I bought a Evnia 27M2N8500 and has been having issues too with the Pixel cleaning, sometimes i turn it on and it says its been 4 hours, or simply never show it the whole day... I'm not brave enough to brick the 700 euros monitor :( for the rest of the things i own i pretty much did the same as most of the OG software is just bloat, 1gb to just control pc fans is evil.
16 hours ago [-]
hajimuz 4 hours ago [-]
- Kindle Book decryption
- Game Console(XBOX especially) Jailbreak
The pixel cleaning warning turns out to have no native way to disable it, and it’ll always show up after 8 hours of runtime.
Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
chubot 16 hours ago [-]
I have an LG TV with a similar problem. I think it’s supposed to pixel clean when you turn it off, and I do every night.
Yet for some reason I can’t escape these annoying pixel cleaning interruptions. Seems like a bug in the firmware.
0cf8612b2e1e 16 hours ago [-]
That feels like it should only require a single person working on the product to experience and demand an immediate fix.
harry8 14 hours ago [-]
That feels like every review of LG should mention their quality is garbage to me, impacting their sales dramatically.
Why hasn't that happened?
SoftTalker 14 hours ago [-]
You are making a subsistence living in China writing TV firmware on contract to LG. Why do you do anything other than exactly what they ask for?
0cf8612b2e1e 14 hours ago [-]
Sure, someone at the bottom of the totem pole may not have autonomy to make decisions. There are others who can dictate policy. Is there no LG salesman who wants to take home this unit and becomes embarrassed about the behavior? A LG VP who might have this very unit on the desk?
The second day of owning this monitor and seeing the same message should be a wake up call to everyone in the LG product line to fix the annoyance.
konraditurbe 7 hours ago [-]
I own the Insta360 Link too, will flash this firmware since I also want to turn off the LED ring.
14 hours ago [-]
jimmy76615 4 hours ago [-]
Which model does one use for this?
I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis.
I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.
jeroenhd 7 hours ago [-]
Anthropic's Claude: own your things, for only 20 dollars per month!
theshrike79 3 hours ago [-]
The difference is that you'll own the hacked solution forever, even if you unsubscribe from Claude.
Using AI to build tools you own and operate is the way.
webprofusion 12 hours ago [-]
Built custom firmware for my Line 6 Pod GO HD guitar multi-fx the other day. Turned into a complete midi controller so it wasn't gathering dust. Fun times!
shrubby 7 hours ago [-]
When will reversing unlock old Apple devices for other OS'es?
usernomdeguerre 16 hours ago [-]
So is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?
WalterBright 10 hours ago [-]
> Network-connected devices seem near universally fucked at this point?
I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.
And no, not a programmable switch. A hardware switch.
They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
hypfer 9 hours ago [-]
Give it time.
The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes.
I like your idea
wewewedxfgdf 17 hours ago [-]
All this ownage will get shut down when manufacturers start whining to politicians and the AI companies will ask how high to jump.
SchemaLoad 17 hours ago [-]
The best models for reverse engineering right now are the Chinese ones. You can download them and run them unrestricted right now.
sixtyj 16 hours ago [-]
Open hardware being reverse engineered with LLM is cool.
I’d say John Deer will be among first ones requesting a halt.
It was similar with Napster vs recording companies… and then Spotify bulldozed everything with its attitude.
With LLM it could be much faster.
nemothekid 12 hours ago [-]
If Opus 5 can do it, there will probably be a Chinese OSS model that can do it before the end of the year.
bloaf 15 hours ago [-]
What's that? A law that all manufacturers need to have had a security review from one of the major AI player's AI models?
hn1rig3rak 5 hours ago [-]
Yep. Every single time.
vinay_ys 14 hours ago [-]
Why does this feel like arms race where the only real winner is the arms seller?
rspeele 15 hours ago [-]
I remember that name from NCSSM! Cool to see you on the front page of HN.
schlarpc 12 hours ago [-]
We should catch up some time, it’s been ages!
holofermes 6 hours ago [-]
this is awesome! I also did something similar with the Orba by Artiphon [1]. Initially I was pretty disappointed by the current state of the Android app, and honestly I just wanted to see what happens if I plug this thing in and ask my Bob bot to take a look around. What I didn't know before starting was that Artiphon went bankrupt last year, which is a bummer cause they made a lot of cool hardware. I have not considered the firmware route, and just relied on decompiling whatever APK/exe, but the idea of controlling a device which is essentially no longer maintained, and all for a few hours of bobbing is quite spectacular.
This indeed works very well, most device are not very well locked down because of proje t resources limitation, and this opens a new era of hacking.
Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI.
This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.
soulofmischief 15 hours ago [-]
I have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do.
I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.
It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.
It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.
mrheosuper 14 hours ago [-]
As FW engineer, I am both horrified and intrigued.
The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.
But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.
Sorry community, but it's our job to make the reverse engineer harder.
panta 6 hours ago [-]
Why is your job to make the reverse engineer harder? When the user buys a product, it should be theirs to do whatever they want, even brick it. Your job should be creating the product the user wants to use, not building obstacles, otherwise you are creating something actively user-hostile. What if your company goes out of business and the user ends up with a device that can't be updated, that depends on cloud services that don't exist anymore, or worse with security vulnerabilities?
mrheosuper 6 hours ago [-]
"Making reverse engineer harder" is just a side product of "improving security" that upper-level people like to hear.
I definitely don't want my C-suite people reading "The product X of company Y has been reversed engineered" on their newspaper.
panta 5 hours ago [-]
In the old days, when businesses were not governed by pure greed, many electronic products, if not the majority, included schematics in their user manual.
If a product today made a point of pride of having fully open source firmware and included a github/gitlab link, there would be no reverse engineering to write about. Security can be obtained also with an open source firmware.
webprofusion 12 hours ago [-]
If you can use a custom chip yep, if it's commodity hardware probably not. You could use secure boot/secure memory etc but that can be a footgun in itself later.
mrheosuper 10 hours ago [-]
What do you mean "Custom chip", like ASIC ? Never in my career that i feel the need to make our own ASIC.
menaerus 8 hours ago [-]
Parent comment was likely about how are you supposed to put LLM into your chip. Commodity ICs are already optimized down to their minimums wrt compute/memory/storage. Ultimately, I think it will prove that RE examples like this are going to become a difficult problem to solve.
mrheosuper 6 hours ago [-]
Oh no, i mean using LLM in the loop, keep forcing it to break our device, gives it every tool that an average tinker can access.
menaerus 5 hours ago [-]
I misunderstood you then, sorry. Yes, that makes complete sense but ultimately I think this will likely not be enough. Implementation will be hardened but new models with better capabilities will be released, and will discover vulnerabilities that would not have been caught or discovered with prior models.
lowbloodsugar 10 hours ago [-]
> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.
Oh very good!
> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.
Oh that was going so well. Just wow.
PeterStuer 10 hours ago [-]
Wait,what?
Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"?
WTF Anthropic? Is the trick not using Python?
AlfeG 6 hours ago [-]
You can request for Cyber Verification Program (CVP) access from Anthropic
driverdan 48 minutes ago [-]
This requires submitting a photo ID to Persona, something no one should be comfortable doing. There are very real privacy concerns with Persona, so much so that Discord dropped them as their provider.
romanovcode 8 hours ago [-]
Maybe. It wrote C code that override some of my hardware without a single complaints. Try it
jauntywundrkind 11 hours ago [-]
This fills me with the sadness of the Jeep hack. Incredible fantastic super amazing work to liberate devices! Finally a peak behind the curtain!
But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"
I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
RS-232 6 hours ago [-]
Thanks, I hate it.
The camera in particular is exactly why I’ve reverted to using devices without networking capabilities.
dncornholio 8 hours ago [-]
Nothing owned.. Maybe the webcam a bit but this is mainly, again, just slop.
markzuckerberhh 16 hours ago [-]
holy crap how !
i'd love to jailbreak my old quest 2.
its such a good device too bad about all the facebook spyware!
fenestella 1 hours ago [-]
[flagged]
ozereray1 4 hours ago [-]
[dead]
malixp 10 hours ago [-]
[dead]
jaco6 12 hours ago [-]
Any intelligent powerful person should be going entirely offline now--if I had net worth over $10mm, I wouldn't own a computer--I would have a secretary control my computer for me. We're going to see really horrible, persistent blackmail in the next few years destroying lives and reputations. It will eventually be the end of the consumer internet.
Jhater 13 hours ago [-]
[dead]
rarisma 16 hours ago [-]
[flagged]
compiler-devel 16 hours ago [-]
Why? Does it bother you to see people using their own devices in the ways that they want?
rgovostes 15 hours ago [-]
Technically this is Schlarpcoding.
drfloyd51 16 hours ago [-]
That’s what they said when ASM was created. It’s what they said when C was created. Java. SQL. Powershell.
Programming has always been about putting more power into the tools.
Sadly, there doesn’t seem to be as much need for hardcore engineers.
asdfsa32 13 hours ago [-]
This looks like an ad for a bunch of products as "hackable". The Authors only other blog post is also about using Claude for similar ideas, without actually showing the end product from a kick skim.
Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.
I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152.
The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine.
It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes.
It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour.
The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected.
I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it.
I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
That you verified? Seems like 1/3 times when a model says things like this it is way off.
This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy.
When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead.
Everything hardware belongs to us now.
This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.
It's of course still huge to be able to do this with all tech up until this cut-off point. Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.
___
Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.
Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.
We should keep in mind that not everyone wins here. In fact, only a minority does.
Or rather I am sure that we do not.
OTOH, maybe it needs events like these to build character. It just will suck for whoever turns out to be the collateral.
do you ponder "unpleasant moral stuff" every time you chop vegetables?
>As an anchor, knives or sharp objects were used in about 97,000 homicides globally in 2017, equivalent to roughly 266 deaths per day.
>There is no reliable single global count, so the best concise answer is about 10,000 people injured by stabbing each day worldwide, not counting deaths separately.
I can guarantee you that 95% of those are done with the humble kitchen knife.
- this is great
- this is an incredibly unstable equilibrium, like a lot of things related to the internet, because other actors haven't yet figured out how to do this at scale
Using LLMs to do this stuff is more like using a gadget built by the guy - not like being the guy.
Mortyposting on main
I have a bunch of iPads stashed for this.
I hate to be the bearer of bad news about this, but
> The U.S. Federal Communications Commission (FCC) banned imports of new foreign-made humanoid and quadruped robots, primarily targeting China.
https://www.pbs.org/newshour/world/u-s-bans-foreign-made-hum...
While that is cool, why do you need such a thing? More FPS? Less video RAM?
Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
You could argue that there should be an option to disable it for people who don’t care.
Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
I've been sharing my screen in work in meetings and suddenly screen nagged, and then I'm struggling to find the dumb buttons under the monitor and confused which button does what to make it go away.
I would rather suffer burn in than be nagged. I've had other brand OLEDs that haven't been this annoying, so I'll never buy an Asus monitor again.
Definitely will be checking more carefully the next time I buy an OLED monitor that it'll let me do this.
Brand new models still have this popup... what "generation" are you talking about that doesn't need this? Or is it just unnecessary on the newer models but they have it any ways due to lack of firmware updates?
It comes down to the joy of doing things, and if the joy of using said monitor depends on a popup not being shown, then so be it.
I hope that the popup can be removed :)
Early OLEDs really did need to be pixel cleaned every 8 hours according to manufacturer estimates, the choice isn't have warning or not, its have a lifespan or not.
I don't want to blame early adopters for being early adopters, but they early adopted, and this is the early adoption problem.
But it automatically runs when it's turned off. The warning is shown because I interrupted it running early.
The warning, for my purposes, is completely useless, and only an annoyance. The automatic feature is more than enough, and I don't need to know if it was aborted early.
IMHO OLED is a planned-obsolescence dead-end anyway; LCDs can last literally decades, maybe with a backlight replacement, but OLEDs are designed to fail in a few years. I have a few (rather expensive) pieces of test equipment with OLEDs that became unreadable after only a few years and had to be replaced (fortunately with a regular LCD, and some firmware patching), while others with old-school CSTN/TN LCDs are still fine.
I'm pretty sure there's something to it but I'm no expert. Five years later and my TV is just fine.
A monitor displays items that can stay fixed in place a long time, hours or even days.
Not the same at all.
Extremely accurate and vivid colors due to their low black level.
And VERY fast pixel response times, 0.01ms to 0.03ms compared to 1ms to 5ms for the fastest LCD gaming monitors.
Or ask for a patch so it runs after the monitor has been powered off for a while...
I use an LG OLED 42inch TV as a monitor and it has a setting to do just this.
"I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever."
No need for ackshually, the guy is clear with what he desires. That is, by the way, the point of TFA. I want my devices to do what I want, not what a product manager wants or what a dude on hacker news wants.
The author even dropped a comment here doubling down on his intent. That is the main problem, when the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
Even time computer says no, or does something without your permission, or does something counter to your wishes, or alerts you to do something, or urges you to do something, or makes you opt-out, is a failure.
Besides, the negative sentiment that OP shares here sis for me much stronger than any burned pixel, annoyances like this are a sure way for me to not buy a product if I read this in reviews
Not just tell, actually nag, coerce and force, often in the teeth of their own total idiocy.
"Your password needs to be between 8 and 15 characters and include an upper case letter, a symbol and a number. (And an actually good, strong password will be rejected).
See that all the time, still, in 2026. So very smaht.
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
Are you sure? iirc that (for now?) only applies to stuff with wireless connectivity, though maybe I'm misinformed or misremembering.
Which would still be "all IoT, basically", of course.
(Technically it says "which intentionally emits and/or receives radio waves for the purpose of radio communication", I'll let HN crowd determine if Ethernet emits/receive radio waves in an enclosed channel called Ethernet cable)
Vendor is PetKit btw.
It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.
https://github.com/philips/supernote-typescript/blob/main/pl...
https://philips.github.io/supernote-typescript/
My reverse engineering extracts each pen stroke directly into a svg vector.
https://philips.github.io/supernote-web-component/
Click the "Pen" icon then the "Play" button.
Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
For all the agentic loops people seem to have come up with, the research loop or as I call it the “Desperate 10th page on Github’s crappy search results” is still not up to the mark.
Either it might be genuine rate limiting these LLM’s face or just that, they are trained to focus on implementing a solution which would be faster and user acceptable solution. (which seems to be a true looking at people pushing LLM generated code as is).
At least in my personal experience with niche projects and heck even with well documented and famous libraries, along with fancy mcp’s, llms.txt and skills; RTFM has been more relevant than usual for code that I have asked an agent to generate, since it is too eager to reimplement functionality which already exists, only if it RTFM!!
It is definitely the case that people know less and less how to do research themselves though...
As a simplistic example, suppose one section of the file is known by the model to be bzip2 compressed - the LLM may use xxd to scan for common magic numbers that "just so happens" to include 42 5A (Bz). Every step of analysis is like this - what threads to look for, and which ones to pull on. Somebody or something who mostly-remembers the answer is going to find the answer quicker than if they'd gone in blind.
[1] https://www.anthropic.com/research/tracing-thoughts-language...
https://supernote.ifup.org/
https://youtu.be/ihRh_F43-iQ
Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
https://en.wikipedia.org/wiki/ThreadX
Initially at least. Had some changes of ownership and rebrands meanwhile.
Now playing: "Hot Chocolate - It's just an illusion"
I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
Honestly if you don't have working patches, it's really not owned.
I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.
Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...
We are NOT there yet but I hope we get there soon.
> we also need good glitching tools
There are a lot already, what do you feel is missing?
I have enough basic soldering to get UART attached, but not sure what to try after that.
Equipment-wise, I currently just have a few ESP32-C3s and electronics basics kit and some basic soldering stuff.
[0] https://stoisavljevic.com/articles/coreboot
https://libreboot.org/docs/install/spi.html#do-not-buy-ch341...
If someone said "we need good package managers", I'm not going to randomly start listing package managers without knowing what distro and/or programming language they're using.
I wonder what humanity will look like in 20 years if this doesn't stop.
This is the same as what my friend says. She would have no idea what they are asking, fire up search engine, find the thing, and tell them to do the same. But "demand answers" is the default behavior for zoomers
One person's "asking a question" is another's "demanding an answer"
Clearly both search engines and chat interfaces are merging, and clearly they should be because they fulfill the same kind of requirements.
Complaining about that seems a lot like those who complained about how the correct url for altavista should always be altavista.digital.com, not altavista.com and how autocomplete is bad.
Never heard of LMGTFY ("Let Me Google That For You")? Why do you think it exists?
Or "Google / Wikipedia is your friend"?
Or RTFM ("Read The Fucking Manual")?
Really not new inventions (and "zoomers" were there for them, cause the oldest ones are pushing 30! [1]). Not hard to search for either, by the way...
[0] or rather, going through some very conveniently selective amnesia
[1] just to really give you a sense of how stupid this generation-xyz thing is, this "generation" includes people whose first OS was entirely possibly Windows 98, and at the same time, people whose first OS was Windows 10
I saw LMGTFY link once maybe...
Sounds easily searchable...
The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
Ah, there's the rub.
> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
> Operating systems aren’t really equipped to work with the user to ensure that a microphone stays a microphone, and doesn’t spontaneously turn into a keyboard that hits Win+R and drops a payload to steal all your data when the room is quiet enough that it can assume you aren’t watching.
In a world of USB-C everything we no longer have power supplies that are physically bound to power delivery, HDMI or DP display connections that have constrained data channels, or analogue mics, headphones, and speakers. Any device can dynamically change what it senses, does, or emits.
[1] https://github.com/AristoChen/usb-proxy
If I was writing a novel, the top secret facility would be cracked open by the smoke alarm, which has a wired connection to the central fire control and runs a little microprocessor. There is enough storage for 20 programmable voice alert messages. I/O includes an LED and also a light sensor. After the attacker gains control of the smoke alarms -- reach to every room of the secure facility -- their focus turns to mass poisoning peripherals until one makes it into range. A poisoned monitor detects the smoke alarm blinking a coded broadcast via its LED during darkened overnight hours. The monitor responds with flashing code of its own. That creates a communication path back to the controlling LLM. From there its like attacking a normal networked device, just with a slow data link in the middle...
The novelty is the uniform adaption of USB-C for the rest of the world and the endless attack surface that provides.
HDMI has theoretical support for 100 MBit/s Ethernet [1] but in practice I agree, haven't seen that one used in practice.
IIRC it came in 2009 with HDMI 1.4, at that time Wifi in practice was mostly 802.11g with IIRC 20-ish MBit/s as 802.11n was still formally a draft... the idea was to give high-bandwidth networking to home entertainment devices without requiring to run physical Ethernet to each tiny device, but it quickly became superseded by 802.11n Wifi on one side, and on the other side, the "enrichment" of stuff on DVDs or broadcast TV with internet-based content never truly materialized.
[1] https://en.wikipedia.org/wiki/HDMI#HEC
Cue my surprise when it turns out you can use WebHID to program a Minidisc / Net-MD device [1], so.. they never did implement that filter, apparently. I mean, certainly it is useful, but ... What The F., Google?
[1] https://web.minidisc.wiki/
So software designers need to avoid asking the users to approve potentially highly dangerous things.
Design prompts for potentially dangerous actions so refusal is easy and what's being asked is legible, and people will refuse plenty.
Maybe MD drives aren't really at risk, but things like HID peripherals definitely are.
It is basically the same reason most desktops do not give the logged in user access to /dev/hidraw*, even though it makes a shitton of sense and would simplify many things greatly.
This is one of the few areas where I think Mozilla did the right thing without question.
How many hoops Google asks you to go to install an Android app ? (Androids amounts to basically the most sandboxed environment one can have today; malware installed there can practically do _nothing_) MANY. Centralized register of apps and remote blacklisting, a lot of permission prompts, password check, and they are even literally pushing to even have a physical 24h cool-off period if you skip the centralized register.
How many hoops does Google ask you to go an allow a random website unfettered access to destroy your hardware? One. Permission. Prompt. In a bubble prompt, that barely registers above noise compared to other permission prompts browsers ask.
Of course these are two ridiculous extremes, but they exemplify the point. There is a reason a browser won't allow a random website to write over random sectors of your hard disk just because you said "accept" to a bubble-style permission prompt about wanting to "save files to your hard disk". The line has to be drawn somewhere, and allowing what basically amounts to raw access to IO ports just after a single permission prompt listing the device name is where I draw it. Any user, even knowledgeable ones, is simply going to be _incapable_ of truly understanding the risks behind allowing this access.
I would be much more in favor of allowing random IPC to services in your local computer (after a permission prompt) than this., something that is equally useful if not more than allow raw access to HID.
Devices need to be hidden behind drivers that multiplex and control access to the device at the OS level. A bus that was never meant to be exposed to user-level access should not be exposed to random programs much less websites. This is not security, this is "mistake prevention" level, in the same way operating systems disallow a random user-level program from overwriting the hard disk.
And do not read this as "devices should sign their firmwares and what not". That is (for me) definitely the wrong take but literally the only take that is left on the table due to Google's stupid behavior.
I 'member (and miss) the old Android days before everything became the locked down hellscape Android is these days. And I also member why it became that way, there was a loooot of bad actors exploiting that open model.
For operating systems it's similar. DOS/Windows up to and through ME didn't have the concept of different user levels, the file system didn't allow for it, and if you had physical access to the machine it was trivial to corrupt and subvert it. Only with Windows XP, Microsoft switched the consumer OS to NT and its multi-user model.
And so it will be for WebUSB et al. First it will be a pretty open and unrestricted world, and only if there turns out to be a significant problem, security will (need to) be tightened.
Do we live in a bizarro world now where we expect — no, demand — our hardware be locked down?
It's worth mentioning all USB mics are toys anyway. Analog interfaces have gone away — artificially so — now they cram them into the device.
All mics are analog.
[1]: https://git.sr.ht/~e-topy/bs120 [2]: https://base48.cz; feel free to come by anytime
https://netliststudio.com/articles/2026/02/23/claude-oscillo...
1: https://news.ycombinator.com/item?id=49353141
Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.
You can say a lot about Apple but the engineering is clever at the hardware level.
I’m at a loss for how you would signal all of that without a GPIO.
LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.
At the point we are in time... honestly, I don't expect this thing called "privacy" any more. And I'm, notably, German. Glassholes, camera surveillance everywhere, our police is more and more turning into the rabid hellscape that is American police with far-right authoritarians at the helm and more and more forces joining up with Palantir or working on a European alternative.
I'm dead sure that at least law enforcement plus dedicated individuals with access to ad data brokers can work out precisely when I had a wank and what I wanked to, now there being a video of me wanking would only be the icing on the cake.
> LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.
Many even forget about that piece of opsec, which is why they get caught in the first place, eventually the tape falls off.
Giving the camera plus LED a separate power supply means that the camera has to boot or come online, which maybe increases the dwell time. And the camera is not visible on the USB bus when powered off.
I think there's more engineering to Apple's design than it first seems.
I'd have tried that first before diving into the firmware head-first.
Also I thought you could trust iMessage if, unlike everyone, you disabled iCloud backup (and, unlike everyone, so did the recipient). Perhaps a way for the feds to be able to pin dumb criminals while giving investigative journalists & dissidents a way to stay safer.
https://support.apple.com/en-us/102651#advanced
You do have to be sure to not enable web access via icloud.com
Much easier to use a 3rd party app like Signal.
https://support.apple.com/en-us/118246
https://support.apple.com/en-us/118247
> An unrecognized new device was added to that person’s Apple Account. This alert might mean that the person you are messaging has an issue with one of their devices, or that a sophisticated attacker might be attempting to eavesdrop on the conversation.
My understanding is that iMessage implements PFS. To get around PFS and access older messages, one needs to get their hand on a backup, which needs fully enrolling a device, not just messaging key exchange hackery.
And as far as trusting Apple with key exchange, well, if you're running their OS and hardware, I suppose that trust of key exchange is the least of your concern (or part of the whole deal anyway depending on how you look at it)
Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
The device reports fine wifi but the backing services are totally busted.
My cat scarfed and barfed periodically, and I always wanted the Petlibro (the simple one) to slow feed by incrementally turning the auger, just to see if it helped. I might dig it out and try my hand at this.
Weird question anyway. Why eat food at all if you can't be bothered to farm it yourself.
Otherwise, you will inevitably end up with one chonk and one cat with food panic that gorges on whatever food it can grab in a single setting before everything is gone.
There’s no substitute for having open systems that aren’t cryptographically locked down by the manufacturer.
Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
This should be illegal. Any politicians who run on [economically, financially] doing to these companies what is being done to Russia and Iran, if they refuse to immediately publish their hardware private keys, I will vote for. Up to and including jailing boards, stiffing bond and equity holders, and selling their assets as scrap, if they choose to purge their keys to prevent disclosure or if disclosure is impossible due to technical design. Maybe if a few trillion dollars worth of businesses suddenly vaporize into legal smoke, the remainders will start behaving for the next hundred years...
There are things that the "open source movement" dreams about, and one just has to search around... E.g. like codecs, Qualcomm's aptX lossless, adaptative, and other more recent variations.
Im definitly very exited to try this our with more devices in my live.
[0] https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...
I do lament the loss of control, but the increase in security will be objectively good for humanity as a whole.
So if closed means they are secure, which 99.99% of end users expect, I'm actually okay with it.
So much for the "hackers", I guess.
[1] - https://mordenstar.com/projects/save-our-screens
[2] - https://github.com/xchwarze/samsung-tv-ws-api
I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
Also is your LinkedIn cyber security adjacent?
Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
Don't be afraid to try. You're limited only by time and imagination now.
Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.
A really fun project was extendending the abilities of my reMarkable Pro. I missed a decent Manga Reader on the device, so I created a native one which makes use of my custom server.
I heard CISA is getting defunded. I wonder if it'll become a common assumption for Americans that all their devices are just perpetually compromised.
> Network-connected devices seem near universally fucked at this point?
Everyone should read Daemon and Freedom, like right now.
1. The author might be exaggerating or lying in regards to the capabilities, ease of use, and result
2. if Claude can do it without hardware access, I struggle to see how it could be anything other than unsigned unencrypted firmware images that you can unpack and mess with
It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
Where the next talent would come from?
Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
Like Dublin, in the rare ould times.
Or you just want to patch out rejection of 3rd party ink/toner.
I suppose you could make having those illegal through on-device scanning and legally mandating usage of operating systems that do that?
Not sure. Not sure if this tech can be contained. Dario does it for the wrong reasons, but it's not like there would be no point in his fearmongering.
__
I wonder if someone will try something like with printers, in that new and more powerful compute units see signatures of models and just refuse execution in the same way inkjet printers refuse to print euro bills.
I'm not sure if that would be a sensible thing to do, but that is a different question from "will someone try that path?"
Let’s go!
Yet for some reason I can’t escape these annoying pixel cleaning interruptions. Seems like a bug in the firmware.
Why hasn't that happened?
The second day of owning this monitor and seeing the same message should be a wake up call to everyone in the LG product line to fix the annoyance.
I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis.
I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.
Using AI to build tools you own and operate is the way.
I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.
And no, not a programmable switch. A hardware switch.
They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes.
I like your idea
I’d say John Deer will be among first ones requesting a halt.
It was similar with Napster vs recording companies… and then Spotify bulldozed everything with its attitude.
With LLM it could be much faster.
[1] https://github.com/holofermes/orba-protocol
Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI.
This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.
I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.
It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.
It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.
The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.
But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.
Sorry community, but it's our job to make the reverse engineer harder.
I definitely don't want my C-suite people reading "The product X of company Y has been reversed engineered" on their newspaper.
Oh very good!
> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.
Oh that was going so well. Just wow.
Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"?
WTF Anthropic? Is the trick not using Python?
But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"
I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
The camera in particular is exactly why I’ve reverted to using devices without networking capabilities.
Programming has always been about putting more power into the tools.
Sadly, there doesn’t seem to be as much need for hardcore engineers.
Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.