I did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware.
I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152.
The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine.
It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes.
It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour.
The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected.
I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it.
I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy.
When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead.
Everything hardware belongs to us now.
This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.
It's of course still huge to be able to do this with all tech up until this cut-off point.
Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.
___
Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.
Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.
We should keep in mind that not everyone wins here. In fact, only a minority does.
- this is an incredibly unstable equilibrium, like a lot of things related to the internet, because other actors haven't yet figured out how to do this at scale
I love this comment so much. It really feels like the big tech is losing the grip. In Rick and Morty, the way Rick is using tech to amuse himself always inspires me. I could only dream of doing anything related a few years back when I watched it. Yesterday I was reverse engineering a cheap but good label maker from AliExpress to write my own app printing labels the way I want them with the fonts and graphics I like with no cancer ads like on the official version. Maybe in a few years I could build a portal gun or turn myself into a pickle, who knows. Fun times!
Until the manufacturers enter an arms race and copy a page out of the mobile hardware vendors book. But perhaps they'll do it badly and we've got a few more years.
> My ASUS ROG Swift PG42UQ monitor was actually where I started, because I got annoyed at the pop-up overlay that comes up every once in a while that tells me to run “pixel cleaning”. I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever. Maybe there’s a debug menu or something that can turn it off, or worst case we patch a branch in the firmware?
Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
Yeah, you actually want to do this with monitors of that generation to make them last.
You could argue that there should be an option to disable it for people who don’t care.
Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
I understand what it does, I think the alert is annoying. It takes at least five minutes and automatically runs when the monitor is off. I’ve had it for a few years and have no burn in issues despite not doing this every eight hours on command.
My MSI monitor does it, I don't object to it in principle. What I do object to is a tool, that I own, demanding this is done on its own schedule rather than mine in a way I can't always dismiss. There's no reason it shouldn't be configurable to do it at three in the morning rather than when I'm trying to run the standup for example.
Definitely will be checking more carefully the next time I buy an OLED monitor that it'll let me do this.
And yet, they own the device. If they choose to not care about burn-in and want their device to respect that, that's their prerogative, not anyone else's.
> Yeah, you actually want to do this with monitors of that generation to make them last.
Brand new models still have this popup... what "generation" are you talking about that doesn't need this? Or is it just unnecessary on the newer models but they have it any ways due to lack of firmware updates?
Eh I think the monitors should just handle this automatically - mine do. I basically have no idea that they do any cleaning cycles except when I check their “advanced” menu and it says it’s run 1200 times or whatever
The Internet seems rather reluctant to explain what exactly "pixel cleaning" does, but based on the vague useless "explanations" I could find, I suspect it's a sort of "flat-field correction" where it calibrates the pixel drive current to darken the less worn and/or brighten the more worn ones so it eliminates the burn-in effect. This obviously leads to a vicious cycle where more worn pixels are driven harder and hence wear faster...
IMHO OLED is a planned-obsolescence dead-end anyway; LCDs can last literally decades, maybe with a backlight replacement, but OLEDs are designed to fail in a few years. I have a few (rather expensive) pieces of test equipment with OLEDs that became unreadable after only a few years and had to be replaced (fortunately with a regular LCD, and some firmware patching), while others with old-school CSTN/TN LCDs are still fine.
If OLEDs are 'designed to fail' they've certainly gone about it in a very roundabout way - there would be much easier ways to do planned obsolescence if that was actually the goal of display manufacturers.
I looked it up, his monitor does do it automatically after it's been powered off for a few minutes. He's getting the nag message because the monitor has been on and displaying a picture for over 8 hours.
I have an ASUS PG32UCDM and an ASUS XG27UCDMG, and both can permanently disable the "pixel cleaning reminder." Have you tried update firmware and look in the monitor UI?
That is just crap UX. Sonys OLED tv-s for example do this automatically while in standby mode in addition to pixel shift while displaying an image. On the other hand Phillips OLED tv-s also ask the user if they want to do a panel refresh.
Perhaps you didn't read the text you just copied and pasted, but here it is for you:
"I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever."
No need for ackshually, the guy is clear with what he desires. That is, by the way, the point of TFA. I want my devices to do what I want, not what a product manager wants or what a dude on hacker news wants.
The author even dropped a comment here doubling down on his intent. That is the main problem, when the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
The user should be the final authority over what his computer does. Not the computer manufacturer. Not the OS developer. Not the 3P app developer. Not some product manager at a software company. The end user.
Even time computer says no, or does something without your permission, or does something counter to your wishes, or alerts you to do something, or urges you to do something, or makes you opt-out, is a failure.
>...the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
Not just tell, actually nag, coerce and force, often in the teeth of their own total idiocy.
"Your password needs to be between 8 and 15 characters and include an upper case letter, a symbol and a number. (And an actually good, strong password will be rejected).
See that all the time, still, in 2026. So very smaht.
I definitely love this article and this spirit. I've accumulated a lot of crap/cheap IoT, I'll probably owning them!
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
The CRA that will be active starting december 2027 will also do similar things like RED. Cant ship with fixed static credentials anymore or manufacturer backdoors (unless the user activates them)
Hum, I don't really know. I was pretty sure it applies to anything connected to the internet even if it's Ethernet-only, but double checked. And reading the EU directive, it looks pretty obvious to me that you're right, it's only for devices with wireless connectivity... (the wireless connectivity doesn't need to be wifi/internet though. like if you have a 433mhz-to-ethernet gateway it still fits).
(Technically it says "which intentionally emits and/or receives radio waves for the purpose of radio communication", I'll let HN crowd determine if Ethernet emits/receive radio waves in an enclosed channel called Ethernet cable)
I just reverse engineered the Supernote note file format with an agent a few weeks ago. For years the community had been asking for a document on the format. And in a few hours the agent, with 20 something file format example fixtures and 30 something prompts, was able to reverse out the format.
It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.
While it’s impressive work from the LLM and a TS implementation is novel, there’s at least a couple of pre-existing Python REs eg. https://github.com/jya-dev/supernote-tool :)
It seems like most of these "an LLM solved this in only X hours! " could have been "I found an open source solution that did what I needed with X minutes of web search."
Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
I personally own a Supernote, but I'm not a heavy user of it. For the sake of my own curiosity, what benefits will you get out of having reverse engineered the Supernote note file format? It would be super rad to be able to move my notes between other devices, which is one big plus that comes to my mind.
Two weeks ago I told Claude “I have a <wifi outlet relay> on the LAN at <IP>. Assume direct control of it.” And about 8 command approvals later I had a new firmware running on it.
Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
I’ve been doing this with Qwen 3.8 27B with success. Kindle, Android Tablet, and Raspberry Pi all working better and fully owned thanks to agentic help. No issues with hitting the guardrails here ofc.
You can’t be loyal to these things. I ditched ChatGPT during the peak Claude hype after Christmas.
I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
Inspired by this article I started to work on migrating my cat's feeder to ESPHome. Within 2 mere hours I'm am basically done but also wanted to RE their update path to avoid having to connect to UART to flash the new firmware. To my surprise, the stock firmware has some issue with the vendor's server where it downgrades to plain HTTP after 5 retries. It exposes all keys, device id and firmware upgrade path to MITM attacks. Absolutely bonkers and it shows how bad these IoT companies are at security.
> I haven’t actually been brave enough to write a modified firmware to the thing yet - it’s a pretty expensive monitor - but I’ll get there at some point.
Honestly if you don't have working patches, it's really not owned.
I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.
Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...
We are NOT there yet but I hope we get there soon.
If you're prepared to get out a soldering iron and/or chip-clip, you can usually back up and restore whatever IC stores the firmware you're modifying, giving you a recovery path.
> we also need good glitching tools
There are a lot already, what do you feel is missing?
How should I learn more about how to do it, what to buy, etc ? I haven't found ChatGPT to be a good teacher about this topic, and in particular re glitching, AI will refuse to discuss specifics
I have enough basic soldering to get UART attached, but not sure what to try after that.
Equipment-wise, I currently just have a few ESP32-C3s and electronics basics kit and some basic soldering stuff.
Using LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic.
The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
TBH this is one of a few things that feels exciting about LLMs. I've recently revived a flip-dot panel from an old bus by reverse engineering and replacing its firmware -- https://www.bobek.cz/buse/
oh wow, this is cool! I managed to reverse engineer a BS120 led display[1], we ended up hooking it into our hackerspace's[2] home assistant instance, displaying everything from static messages to when trams are departing. I enjoyed the challenge of REing it by hand, but the ESP32 firmware to connect it was vibed by a fellow member.
> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
> Operating systems aren’t really equipped to work with the user to ensure that a microphone stays a microphone, and doesn’t spontaneously turn into a keyboard that hits Win+R and drops a payload to steal all your data when the room is quiet enough that it can assume you aren’t watching.
In a world of USB-C everything we no longer have power supplies that are physically bound to power delivery, HDMI or DP display connections that have constrained data channels, or analogue mics, headphones, and speakers. Any device can dynamically change what it senses, does, or emits.
I recently realized something similar. I think that usb-proxy[1] could be used to force what looks like a mass storage device to stay a mass storage device, and likely could be built to be a sort of firewall. usb-proxy is a toy project showing that you can physically "MITM" USB with an RPi, but it could be a starting point.
Was daydreaming the other day about how this could be used by adversaries to hack even air-gapped computers. Any peripheral which contains a microchip and some ram is a vector. Does the compartmentalized facility ever bring in a new monitor, or mouse, or keyboard? All of those things could be hacked to hack their new host. And then taking data into/out of the facility. Which devices have lights? Any LED that can be blinked is a low-speed output channel. Which have light-level sensors, or sound sensors? Or any RF capability? If bluetooth is disabled by software but the hardware is still there...
If I was writing a novel, the top secret facility would be cracked open by the smoke alarm, which has a wired connection to the central fire control and runs a little microprocessor. There is enough storage for 20 programmable voice alert messages. I/O includes an LED and also a light sensor. After the attacker gains control of the smoke alarms -- reach to every room of the secure facility -- their focus turns to mass poisoning peripherals until one makes it into range. A poisoned monitor detects the smoke alarm blinking a coded broadcast via its LED during darkened overnight hours. The monitor responds with flashing code of its own. That creates a communication path back to the controlling LLM. From there its like attacking a normal networked device, just with a slow data link in the middle...
> HDMI or DP display connections that have constrained data channels
HDMI has theoretical support for 100 MBit/s Ethernet [1] but in practice I agree, haven't seen that one used in practice.
IIRC it came in 2009 with HDMI 1.4, at that time Wifi in practice was mostly 802.11g with IIRC 20-ish MBit/s as 802.11n was still formally a draft... the idea was to give high-bandwidth networking to home entertainment devices without requiring to run physical Ethernet to each tiny device, but it quickly became superseded by 802.11n Wifi on one side, and on the other side, the "enrichment" of stuff on DVDs or broadcast TV with internet-based content never truly materialized.
This is why most of the browsers rejected these specs. They are super useful, but the security risks are incredible. Most USB devices were not designed to hold up to being exposed to the internet.
I kinda remember that the counterargument Google used is that only devices with a special attribute would ever be available through WebHID, ensuring that such older devices would never be exposed.
Cue my surprise when it turns out you can use WebHID to program a Minidisc / Net-MD device [1], so.. they never did implement that filter, apparently. I mean, certainly it is useful, but ... What The F., Google?
Note that when you say “rejected”, Mozilla’s position has actually shifted a bit. At the end of 2022, it shipped MIDI in the form of an extension that it will prompt to install for the purpose, with more detailed information and a couple of other details that make it less unsafe. After a few years of that, consensus has grown that this seems to be working acceptably, and that the technique may be considered for other risky areas. They haven’t said anything about USB publicly, to my knowledge, which is definitely way more dangerous than MIDI (even SysEx), but I have heard one rumour (of dubious provenance) that they may cautiously proceed with USB and such too some time soon. Though this sort of thing definitely weighs against that, showing that maybe they were right the first time.
The key takeaway for me was he bought a $300 microphone and is acting indignant that he has full access to his own hardware via — gasp — a command shell.
Do we live in a bizarro world now where we expect — no, demand — our hardware be locked down?
It's worth mentioning all USB mics are toys anyway. Analog interfaces have gone away — artificially so — now they cram them into the device.
You make a good point: hardware should not be default-locked from owner control and manipulation in the name of security. In fact, in the name of security, the default should be open enough to not only manipulate and reflash through owner accessible channels, it should also be easily flashable through chip clips in the worst case compromise scenario. Owner control of all Universal Machines in an object he owns must be a paramount right, akin to the first and second amendments in the bill of rights! This includes your game consoles, vehicles, stoves, washing machines, TVs, microwaves, and even that Qualcomm processor in cellphone basebands. If it is a Universal Machine which executes code from writeable storage (or firmware/microcode provided to it, like during OS boot or driver initialization), it must permit owners to change it. If it comes with cryptographic integrity check keys, the owner must be able to both write his own keys and purge the OEM's keys. Behavior should not change, even the warning Google Pixels give immediately on turn-on are unacceptable, unless it does it by default for the OEM's keys and firmware too; no change in product behavior or appearance when an owner exercises his right to modify his Universal Machines, except where the change arises from the firmware itself that the owner applies.
At this point manufacturers should just open-source their firmwares as there's no barrier for entry to reverse engineer it. They will instead gain from army of end-users willing to put their time and tokens into fixing their bugs for free.
>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying!
Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.
You can say a lot about Apple but the engineering is clever at the hardware level.
It's not even that clever, really. The camera power rail must be physically close to the camera, so it's trivial to hang an LED off it. A device manufacturer has to go out of their way to make it so the LED and camera function are independent, and I'm sure many do, for the worst reasons you can possibly think of.
This still would allow one to "strobe" the power line making it impossible for a human to see the LED but the camera could still capture snapshots and at a decent framerate even.
One of my old Logitech webcams have its recording light wired up to V4L2 protocol directly. I can change its recording light mode (on/off/blink) from software by changing recording light mode directly. Wonder whether that Insta360 also had that.
I'd have tried that first before diving into the firmware head-first.
Also I thought you could trust iMessage if, unlike everyone, you disabled iCloud backup (and, unlike everyone, so did the recipient). Perhaps a way for the feds to be able to pin dumb criminals while giving investigative journalists & dissidents a way to stay safer.
Ah, I remember when reversing hardware took weeks / months, an oscilloscope, logic analyzer, Ghidra/IDA, Wireshark, breakout boards, wireless sniffers... back in the olden days of... 2019.
It's kind of funny, but AI can also use an oscilloscope. My friend vibe coded a software synth on a Raspberry Pi Pico. When he realized his oscilloscope had a network interface, he had Claude figure out how to connect to it over the network and analyze the actual audio output.
I posted [1] a few days ago my experience using LLM to reverse engineering an entirely undocumented device that was only supported by a (crappy) Windows application, and it was honestly remarkable how good Claude was at decompiling the Windows EXE and reverse engineering the protocol. Very exciting. "The developer refuses to write software for this device" is no longer as scary as it used to be.
I did this a while back with my Eaton UPS and Opus 4.8, glad I didn't need to install windows 11 just to push a blob. The day when a LLM os can make unique drivers will be one I wait for
An Agent helped me get a Windows XP Korean MMORPG private server running on my Steam Deck last week. The community obviously got us most of the way there (huge props to them) but setting it up on Linux seemed like a brick wall. Now it works. Amazing for keeping old tech open and running: https://github.com/P0nk/Cosmic/discussions/350
I had used codex to reverse engineer an electric skateboard to unbrick it. It was a bit more involved because it required soldering wires directly to the UART headers in a very awkward location.
Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
This is giving me the confidence to RE my cat feeder. The company (Petlibro) has an outage and now my chilled wet feeder that should be a dumb, offline feeder is basically bricked now.
The device reports fine wifi but the backing services are totally busted.
I have one of their dry food ones and no longer need it. Sad story, but it happens.
My cat scarfed and barfed periodically, and I always wanted the Petlibro (the simple one) to slow feed by incrementally turning the auger, just to see if it helped. I might dig it out and try my hand at this.
We were already there. For most people, we are still there. For most devices (especially popular ones, with enough manufacturing volume) there's just enough hardening, downgrade prevention, encrypted or signed firmware blobs, on top of already rare reverse engineering skills and patience, to make it infeasible for most people to give it a crack. Using an LLM for that also isn't a mainstream idea either (plus you're unlikely to have a Claude subscription if you're not a software developer in the first place).
Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
I think that this is not true -- the achievements mentioned here are hardly ground breaking and mostly build on work that was already done years before LLMs were a thing.
There are things that the "open source movement" dreams about, and one just has to search around... E.g. like codecs, Qualcomm's aptX lossless, adaptative, and other more recent variations.
It's not new capabilities, it's new levels of access. Reverse engineering this stuff used to be a very tedious process which required a lot of specialised skill. Which is why most devices haven't been reverse engineered or hacked despite being full of low hanging fruit.
Did the open source movement dream of outsourcing what they loved to do themselves for free, as in both beer and freedom, to products which are trained on the corpus of their own knowledge without any consent and sold by behemoth corporations on a subscription basis?
"only ever" feels like a stretch. Libratbag, QMK, OpenWRT, Nouveau and Asahi all took up the task without much or any AI help. They're not all just dreamers.
There's a difference between the people sitting at the table and the mice scurrying around catching the crumbs. Freedom is sitting at the table. The OP, sadly, is catching the crumbs.
I did this just yesterday with a smart light. Used Deepseek-v4-flash. In about 2h I had a custom firmware on the smart light running that I could control from its api endpoints. Also now Im hosting a small web-server on there that lets me set schedules and sleep timers.
No im not relying on their proprietary cloud anymore to toggle my lights. Which is insane to start with. Why should my phone that is in my home network need to send the "light on" command ot some cloud in a different country, only to then send the command back into my home network and turn the light on.
Im definitly very exited to try this our with more devices in my live.
Perhaps I’m daydreaming, but maybe some vendors will accept this new reality and begin just selling the hardware without locking users in. Perhaps they’ll even make it easier for users to truly own their products.
No, they will just encrypt firmware, add more signature verifications and lock devices to accounts in order to complicate reuse, increase sales and produce more ewaste.
I agree, but like many others I'm willing to pay a fair price for that freedom and ownership, and I believe there is a customer base to be captured. And in the end there's a cost for a company to put all of those locks in place, which they could simply avoid.
We have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.
I desperately want this, but our Frame has never been connected to the Wifi, and I'm really reluctant to do so, as it will probably start snitching and/or delivering ads...
The tv-ws-api can be used over ethernet. I control my Frame TV from a pi through direct ethernet cable and the pi separately connects to my home LAN over WiFi and serves an app for Frame art control. The TV has never had direct access to the LAN or internet. Check the frame subreddit for several such projects.
Nice! I actually built something similar back in early 2023 [1], which used a collection of SDXL models to generate a new random painting every hour upscaled to 4K and then broadcasted to my frame using the Samsung WS API wrapper [2].
People are praising how this new age of owning our stuff is here, while actually all this will bring is stricter lockdown in every level of the supply chain. Enjoy while it lasts, but I expect even more closed stuff, and less openness from these t.rends
The other option is to look for better products that take simplicity, security, ownership and verifiability seriously. I think there's a market. Consider Precusor[0] who's design philosophy could be duplicated. Such a company could become the Anker of computer peripherals: build quality products that decommoditize markets. Now is the time to make such a company, because by the time the peripherapocolypse hits (in a few months) by then it will be too late.
What I wish is that we started reverse-engineering audio receivers, many of which run regular Linux. Manufacturers tend to release the new models with hardly any hardware changes, sometimes only software updates. To be able to backport an Airplay2 to an older, fully functional receiver would be amazing.
I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
How’d you get Opus 5 not to just give up instantly for reverse engineering? Are you sure you’re using Opus 5 and not 4.8 by automatic fallback?
I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
I guess there is this dream that AI will help us finally close the Linux driver gap, and maybe even conquer the android phone closed hardware driver conundrum making almost every phone locked down. One can hope.
I definitely managed to get Linux running in full on my Xiaomi Pad tablet, each and every feature of it! Writing drivers is a breeze now, what remains difficult is upstreaming them.
I initially thought, but why would you want a "webcam whose activity LED I can switch off while it records"? But then I think I got the point: why would one want a webcam which _could be hacked_ so that its activity LED didn't go on.
I am certain if it can be “tricked” into using it with the LED off, there is certainly a feature being sold to “enterprises” where it happens on purpose.
I can see the benefit of from-scratch personalized software, but in the spirit of open-source, how about all the world contributes to useful software for everyone else?
Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
I'm starting to believe that bespoke, personalized software is the only way to combat feature bloat. Every software (proprietary or open source) I download and use has features I don't want getting in the way and bugs that the developers/maintainers are not prioritizing.
I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
I posted this on another thread but can someone please run this on some old iPads so we can be able to fully install Linux on them. If AI is so good surely it can do that and save millions of devices from turning into ewaste.
My Sony TV also faced some issues in the past, which at least let me start some investigation. Unfortunately it confirmed my assumptions that the hardware is very limited and already runs on full load most of the time. Still thinking about putting some more effort into this, but killing the device was also one of my concerns.
A really fun project was extendending the abilities of my reMarkable Pro. I missed a decent Manga Reader on the device, so I created a native one which makes use of my custom server.
I'm hopeful that in the future we can end planned obsolescence from devices that require companion apps which eventually get shut down. Just vibe reverse engineering replacements.
we could have ended planned obsolescence decades ago if we put strong policies in place. I would really like a systemic solution instead of every-man-for-himself vibe coding. I've been following the "stop killing games" movement for that reason. fingers crossed.
About 1.5 years ago I reported a vulnerability with my router’s ipv6. The firewall was wide open, and router management SSH was listening externally, among a few other vulnerabilities. After pulling teeth, the router fixed ssh, but not the firewall.
A couple months ago I used AI to find a novel shell injection exploit and obtain root creds in the router, so I could print out the firewall configuration , init script flaws , and write up a vulnerability report. AI found the bug and wrote the patch to fix it for the vendor, without having the original code ( the bug was in shell script, thankfully).
The vendor had commented out the IPv6 firewall init, probably to pass QA , knowing consumers don’t usually use or test IPv6.
Upon getting the report, the vendor fixed the issue.
I spent a decade in robotics and have built firmware for dozens of devices. And yet I was never able to successfully fix my webcam device driver on linux with Claude. I'm jealous of this person's prompting skills! Or perhaps pwning is easier than fixing the nightmare that is Intel open source device drivers?
1. The author might be exaggerating or lying in regards to the capabilities, ease of use, and result
2. if Claude can do it without hardware access, I struggle to see how it could be anything other than unsigned unencrypted firmware images that you can unpack and mess with
I did something similar but with smart home devices. I use the homebridge interface to connect my smart home devices to Apple's homekit protocol. Some homebridge plugins for my devices were outdated and no longer maintained, so I asked Codex/Claude to help me create a patch of it as a local fork, so my smart home devices can still run without problems.
It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
Maybe this is what Jevon's Paradox looks like for LLMs.
Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
I've spent SO MUCH TIME in my life trying to get laboratory machinery, usually only ten of them in the world, to spit out their data nicely. They have UIs but usually god-awful, and all data is hidden away somewhere (they're written by biologists, for biologists). I wish I could go void some warranties....
Yep, Claude did well here. From the experiment, to the website design, to more than likely all the writing/summaries. What is truly fascinating is not that long ago people were doing hard experiments regularly like this without any LLMs.
this is interesting, while i greatly apreciate the ability with claude code to basically customize my own firmware. There are things that I am strictly speaking wondering about the authors choices. The Author removed Pixel Cleaning? As far as I understand Pixel Cleaning is a process to make sure your OLED Monitor lives longer, why would you want to not do that?
My monitor can run a pixel cleaning automatically when it detects that there is no longer a signal coming in. That way it periodically cleans, but has never done so while I was using it. I presume the author uses the same mechanism and just doesn't want to be bothered about it.
This is the first exciting thing I've seen done with LLMs in quite some time. Turning on or off an LED doesn't seem world shattering, but the idea that we might be able to unlock or add functionality to hardware we own makes me giddy
This is timely! I'm trying to take control of my Echo Wall Clock which connects to an Alexa device that I want to get rid of. There's very little info on it but Claude was able to find the FCC filings and now we've got lo-res images of the circuit board. It's inspecting the test pads on the circuit board now to see if it can figure out how to replace the firmware.
Did something like this to play RTMP-over-HTTP from a security camera, no server required. didn't poke for rce yet. And same for a capture card with a HDMI loop out that was dropping audio when the monitor you plugged into it didn't advertise sound support in its edid, now it works.
Honestly I do like this trend if it genuinely leads to more interoperability. Im not sure that is the case though and in fact I worry people will start to imagine that anybody can do that in no time and that future devices will remain hackable this way. I have no doubt it was fun for OP to do but I bet most people who try that, people with less understanding, will inevitably end up nowhere or, worst, with bricked device in unrecoverable states. I feel this is one of the best use of AI at the moment, namely gaining agency by having devices do what their own wants and I hope it will lead to manufacturers selling both safer AND more interoperable devices but I'll remain prudently skeptical.
Maybe, but also the cat is out of the bag, as open weights models can do it.
I suppose you could make having those illegal through on-device scanning and legally mandating usage of operating systems that do that?
Not sure. Not sure if this tech can be contained.
Dario does it for the wrong reasons, but it's not like there would be no point in his fearmongering.
__
I wonder if someone will try something like with printers, in that new and more powerful compute units see signatures of models and just refuse execution in the same way inkjet printers refuse to print euro bills.
I'm not sure if that would be a sensible thing to do, but that is a different question from "will someone try that path?"
I bought a Evnia 27M2N8500 and has been having issues too with the Pixel cleaning, sometimes i turn it on and it says its been 4 hours, or simply never show it the whole day... I'm not brave enough to brick the 700 euros monitor :( for the rest of the things i own i pretty much did the same as most of the OG software is just bloat, 1gb to just control pc fans is evil.
The pixel cleaning warning turns out to have no native way to disable it, and it’ll always show up after 8 hours of runtime.
Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis.
I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.
Built custom firmware for my Line 6 Pod GO HD guitar multi-fx the other day. Turned into a complete midi controller so it wasn't gathering dust. Fun times!
So is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?
> Network-connected devices seem near universally fucked at this point?
I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.
And no, not a programmable switch. A hardware switch.
They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes.
this is awesome! I also did something similar with the Orba by Artiphon [1]. Initially I was pretty disappointed by the current state of the Android app, and honestly I just wanted to see what happens if I plug this thing in and ask my Bob bot to take a look around. What I didn't know before starting was that Artiphon went bankrupt last year, which is a bummer cause they made a lot of cool hardware. I have not considered the firmware route, and just relied on decompiling whatever APK/exe, but the idea of controlling a device which is essentially no longer maintained, and all for a few hours of bobbing is quite spectacular.
I have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do.
I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.
It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.
It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.
This indeed works very well, most device are not very well locked down because of proje t resources limitation, and this opens a new era of hacking.
Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI.
This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.
As FW engineer, I am both horrified and intrigued.
The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.
But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.
Sorry community, but it's our job to make the reverse engineer harder.
Why is your job to make the reverse engineer harder? When the user buys a product, it should be theirs to do whatever they want, even brick it. Your job should be creating the product the user wants to use, not building obstacles, otherwise you are creating something actively user-hostile. What if your company goes out of business and the user ends up with a device that can't be updated, that depends on cloud services that don't exist anymore, or worse with security vulnerabilities?
If you can use a custom chip yep, if it's commodity hardware probably not. You could use secure boot/secure memory etc but that can be a footgun in itself later.
> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.
Oh very good!
> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.
This requires submitting a photo ID to Persona, something no one should be comfortable doing. There are very real privacy concerns with Persona, so much so that Discord dropped them as their provider.
This fills me with the sadness of the Jeep hack. Incredible fantastic super amazing work to liberate devices! Finally a peak behind the curtain!
But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"
I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
Any intelligent powerful person should be going entirely offline now--if I had net worth over $10mm, I wouldn't own a computer--I would have a secretary control my computer for me. We're going to see really horrible, persistent blackmail in the next few years destroying lives and reputations. It will eventually be the end of the consumer internet.
This looks like an ad for a bunch of products as "hackable". The Authors only other blog post is also about using Claude for similar ideas, without actually showing the end product from a kick skim.
Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.
I did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware.
I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152.
The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine.
It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes.
It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour.
The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected.
I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it.
I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
> It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
That you verified? Seems like 1/3 times when a model says things like this it is way off.
This is so neat.
This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy.
When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead.
Everything hardware belongs to us now.
This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
Don't get your hopes up.
What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.
It's of course still huge to be able to do this with all tech up until this cut-off point. Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.
___
Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.
Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.
We should keep in mind that not everyone wins here. In fact, only a minority does.
7 replies →
My two thoughts are:
- this is great
- this is an incredibly unstable equilibrium, like a lot of things related to the internet, because other actors haven't yet figured out how to do this at scale
I love this comment so much. It really feels like the big tech is losing the grip. In Rick and Morty, the way Rick is using tech to amuse himself always inspires me. I could only dream of doing anything related a few years back when I watched it. Yesterday I was reverse engineering a cheap but good label maker from AliExpress to write my own app printing labels the way I want them with the fonts and graphics I like with no cancer ads like on the official version. Maybe in a few years I could build a portal gun or turn myself into a pickle, who knows. Fun times!
2 replies →
Until the manufacturers enter an arms race and copy a page out of the mobile hardware vendors book. But perhaps they'll do it badly and we've got a few more years.
1 reply →
When do the locked old apple pads open up for Linux?
2 replies →
> When the SOTA robots from Unitree get here
I hate to be the bearer of bad news about this, but
> The U.S. Federal Communications Commission (FCC) banned imports of new foreign-made humanoid and quadruped robots, primarily targeting China.
https://www.pbs.org/newshour/world/u-s-bans-foreign-made-hum...
> custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode
While that is cool, why do you need such a thing? More FPS? Less video RAM?
[flagged]
> My ASUS ROG Swift PG42UQ monitor was actually where I started, because I got annoyed at the pop-up overlay that comes up every once in a while that tells me to run “pixel cleaning”. I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever. Maybe there’s a debug menu or something that can turn it off, or worst case we patch a branch in the firmware?
Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
Yeah, you actually want to do this with monitors of that generation to make them last.
You could argue that there should be an option to disable it for people who don’t care.
Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
I understand what it does, I think the alert is annoying. It takes at least five minutes and automatically runs when the monitor is off. I’ve had it for a few years and have no burn in issues despite not doing this every eight hours on command.
2 replies →
My MSI monitor does it, I don't object to it in principle. What I do object to is a tool, that I own, demanding this is done on its own schedule rather than mine in a way I can't always dismiss. There's no reason it shouldn't be configurable to do it at three in the morning rather than when I'm trying to run the standup for example.
Definitely will be checking more carefully the next time I buy an OLED monitor that it'll let me do this.
And yet, they own the device. If they choose to not care about burn-in and want their device to respect that, that's their prerogative, not anyone else's.
> Yeah, you actually want to do this with monitors of that generation to make them last.
Brand new models still have this popup... what "generation" are you talking about that doesn't need this? Or is it just unnecessary on the newer models but they have it any ways due to lack of firmware updates?
Reminds me of the degauss button on my old eizo crt...
1 reply →
How is it strange that among the 900,000 1-minute tasks you need to complete on a given day, this one is low on the list?
2 replies →
Eh I think the monitors should just handle this automatically - mine do. I basically have no idea that they do any cleaning cycles except when I check their “advanced” menu and it says it’s run 1200 times or whatever
6 replies →
The Internet seems rather reluctant to explain what exactly "pixel cleaning" does, but based on the vague useless "explanations" I could find, I suspect it's a sort of "flat-field correction" where it calibrates the pixel drive current to darken the less worn and/or brighten the more worn ones so it eliminates the burn-in effect. This obviously leads to a vicious cycle where more worn pixels are driven harder and hence wear faster...
IMHO OLED is a planned-obsolescence dead-end anyway; LCDs can last literally decades, maybe with a backlight replacement, but OLEDs are designed to fail in a few years. I have a few (rather expensive) pieces of test equipment with OLEDs that became unreadable after only a few years and had to be replaced (fortunately with a regular LCD, and some firmware patching), while others with old-school CSTN/TN LCDs are still fine.
If OLEDs are 'designed to fail' they've certainly gone about it in a very roundabout way - there would be much easier ways to do planned obsolescence if that was actually the goal of display manufacturers.
2 replies →
Is is possible that some technologies could have longevity trade offs and not be "planned obsolescence"?
OLEDS have two HUGE advantages over LCDs
Extremely accurate and vivid colors due to their low black level.
And VERY fast pixel response times, 0.01ms to 0.03ms compared to 1ms to 5ms for the fastest LCD gaming monitors.
Pixel cleaning sounds little like blinker fluid to me...
I don't think learning more about what it does is going to make them change their mind here.
> You could probably ask the AI to look at the firmware and describe what it does.
Or ask for a patch so it runs after the monitor has been powered off for a while...
I use an LG OLED 42inch TV as a monitor and it has a setting to do just this.
I looked it up, his monitor does do it automatically after it's been powered off for a few minutes. He's getting the nag message because the monitor has been on and displaying a picture for over 8 hours.
That's exactly what it is, and it's pretty important to run
I have an ASUS PG32UCDM and an ASUS XG27UCDMG, and both can permanently disable the "pixel cleaning reminder." Have you tried update firmware and look in the monitor UI?
Or update the firmware to do it every n hours or screen blanks or something automatic with no nag
Every 8 hours is insane, though
That is just crap UX. Sonys OLED tv-s for example do this automatically while in standby mode in addition to pixel shift while displaying an image. On the other hand Phillips OLED tv-s also ask the user if they want to do a panel refresh.
Perhaps you didn't read the text you just copied and pasted, but here it is for you:
"I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever."
No need for ackshually, the guy is clear with what he desires. That is, by the way, the point of TFA. I want my devices to do what I want, not what a product manager wants or what a dude on hacker news wants.
The author even dropped a comment here doubling down on his intent. That is the main problem, when the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
The user should be the final authority over what his computer does. Not the computer manufacturer. Not the OS developer. Not the 3P app developer. Not some product manager at a software company. The end user.
Even time computer says no, or does something without your permission, or does something counter to your wishes, or alerts you to do something, or urges you to do something, or makes you opt-out, is a failure.
8 replies →
>...the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
Not just tell, actually nag, coerce and force, often in the teeth of their own total idiocy.
"Your password needs to be between 8 and 15 characters and include an upper case letter, a symbol and a number. (And an actually good, strong password will be rejected).
See that all the time, still, in 2026. So very smaht.
I definitely love this article and this spirit. I've accumulated a lot of crap/cheap IoT, I'll probably owning them!
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
The CRA that will be active starting december 2027 will also do similar things like RED. Cant ship with fixed static credentials anymore or manufacturer backdoors (unless the user activates them)
> for anything connected to the internet
Are you sure? iirc that (for now?) only applies to stuff with wireless connectivity, though maybe I'm misinformed or misremembering.
Which would still be "all IoT, basically", of course.
Hum, I don't really know. I was pretty sure it applies to anything connected to the internet even if it's Ethernet-only, but double checked. And reading the EU directive, it looks pretty obvious to me that you're right, it's only for devices with wireless connectivity... (the wireless connectivity doesn't need to be wifi/internet though. like if you have a 433mhz-to-ethernet gateway it still fits).
(Technically it says "which intentionally emits and/or receives radio waves for the purpose of radio communication", I'll let HN crowd determine if Ethernet emits/receive radio waves in an enclosed channel called Ethernet cable)
I have a box of ancient Android and Windows phone handsets which I'm now looking at in a new light.
I just reverse engineered the Supernote note file format with an agent a few weeks ago. For years the community had been asking for a document on the format. And in a few hours the agent, with 20 something file format example fixtures and 30 something prompts, was able to reverse out the format.
It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.
https://github.com/philips/supernote-typescript/blob/main/pl...
https://philips.github.io/supernote-typescript/
While it’s impressive work from the LLM and a TS implementation is novel, there’s at least a couple of pre-existing Python REs eg. https://github.com/jya-dev/supernote-tool :)
I know of the project but it doesn’t actually extract the stroke information. It converts the raster into vector.
My reverse engineering extracts each pen stroke directly into a svg vector.
2 replies →
It seems like most of these "an LLM solved this in only X hours! " could have been "I found an open source solution that did what I needed with X minutes of web search."
Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
6 replies →
I personally own a Supernote, but I'm not a heavy user of it. For the sake of my own curiosity, what benefits will you get out of having reverse engineered the Supernote note file format? It would be super rad to be able to move my notes between other devices, which is one big plus that comes to my mind.
I built a management website and plugin for Obsidian.
https://supernote.ifup.org/
https://youtu.be/ihRh_F43-iQ
Two weeks ago I told Claude “I have a <wifi outlet relay> on the LAN at <IP>. Assume direct control of it.” And about 8 command approvals later I had a new firmware running on it.
Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
Surprising. I have hit its BS guardrails a lot lately, working on my vintage computers from the 80s and early 90s. Just about done with Claude.
I’ve been doing this with Qwen 3.8 27B with success. Kindle, Android Tablet, and Raspberry Pi all working better and fully owned thanks to agentic help. No issues with hitting the guardrails here ofc.
5 replies →
You can’t be loyal to these things. I ditched ChatGPT during the peak Claude hype after Christmas.
I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
3 replies →
What were you trying to do with vintage computers?
kimi k3 is wonderful, I suggest you give it or GLM a try when you get the chance, I just use openrouter or cursor
Inspired by this article I started to work on migrating my cat's feeder to ESPHome. Within 2 mere hours I'm am basically done but also wanted to RE their update path to avoid having to connect to UART to flash the new firmware. To my surprise, the stock firmware has some issue with the vendor's server where it downgrades to plain HTTP after 5 retries. It exposes all keys, device id and firmware upgrade path to MITM attacks. Absolutely bonkers and it shows how bad these IoT companies are at security.
Vendor is PetKit btw.
> I haven’t actually been brave enough to write a modified firmware to the thing yet - it’s a pretty expensive monitor - but I’ll get there at some point.
Honestly if you don't have working patches, it's really not owned.
I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.
Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...
We are NOT there yet but I hope we get there soon.
If you're prepared to get out a soldering iron and/or chip-clip, you can usually back up and restore whatever IC stores the firmware you're modifying, giving you a recovery path.
> we also need good glitching tools
There are a lot already, what do you feel is missing?
What about automotive? I suspect automotive firmwares to be more protected already, but where do I start with playing with the infotainment systems?
How should I learn more about how to do it, what to buy, etc ? I haven't found ChatGPT to be a good teacher about this topic, and in particular re glitching, AI will refuse to discuss specifics
I have enough basic soldering to get UART attached, but not sure what to try after that.
Equipment-wise, I currently just have a few ESP32-C3s and electronics basics kit and some basic soldering stuff.
17 replies →
Using LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic.
The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
I find whenever I do this I run into the bullshit cyber guardrails. What model are you using and how are you prompting it?
Opus 5 with CVP, no special prompting. In this instance just about any larger model from the last 12 months would have done the trick.
2 replies →
TBH this is one of a few things that feels exciting about LLMs. I've recently revived a flip-dot panel from an old bus by reverse engineering and replacing its firmware -- https://www.bobek.cz/buse/
Looks like the video links are broken, would love to see these displays in action.
oh wow, this is cool! I managed to reverse engineer a BS120 led display[1], we ended up hooking it into our hackerspace's[2] home assistant instance, displaying everything from static messages to when trams are departing. I enjoyed the challenge of REing it by hand, but the ESP32 firmware to connect it was vibed by a fellow member.
[1]: https://git.sr.ht/~e-topy/bs120 [2]: https://base48.cz; feel free to come by anytime
Key takeaway:
> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
The preceding sentence is equally prescient:
> Operating systems aren’t really equipped to work with the user to ensure that a microphone stays a microphone, and doesn’t spontaneously turn into a keyboard that hits Win+R and drops a payload to steal all your data when the room is quiet enough that it can assume you aren’t watching.
In a world of USB-C everything we no longer have power supplies that are physically bound to power delivery, HDMI or DP display connections that have constrained data channels, or analogue mics, headphones, and speakers. Any device can dynamically change what it senses, does, or emits.
I recently realized something similar. I think that usb-proxy[1] could be used to force what looks like a mass storage device to stay a mass storage device, and likely could be built to be a sort of firewall. usb-proxy is a toy project showing that you can physically "MITM" USB with an RPi, but it could be a starting point.
[1] https://github.com/AristoChen/usb-proxy
Was daydreaming the other day about how this could be used by adversaries to hack even air-gapped computers. Any peripheral which contains a microchip and some ram is a vector. Does the compartmentalized facility ever bring in a new monitor, or mouse, or keyboard? All of those things could be hacked to hack their new host. And then taking data into/out of the facility. Which devices have lights? Any LED that can be blinked is a low-speed output channel. Which have light-level sensors, or sound sensors? Or any RF capability? If bluetooth is disabled by software but the hardware is still there...
If I was writing a novel, the top secret facility would be cracked open by the smoke alarm, which has a wired connection to the central fire control and runs a little microprocessor. There is enough storage for 20 programmable voice alert messages. I/O includes an LED and also a light sensor. After the attacker gains control of the smoke alarms -- reach to every room of the secure facility -- their focus turns to mass poisoning peripherals until one makes it into range. A poisoned monitor detects the smoke alarm blinking a coded broadcast via its LED during darkened overnight hours. The monitor responds with flashing code of its own. That creates a communication path back to the controlling LLM. From there its like attacking a normal networked device, just with a slow data link in the middle...
1 reply →
This is one reason why I run Qubes OS as my daily driver.
> HDMI or DP display connections that have constrained data channels
HDMI has theoretical support for 100 MBit/s Ethernet [1] but in practice I agree, haven't seen that one used in practice.
IIRC it came in 2009 with HDMI 1.4, at that time Wifi in practice was mostly 802.11g with IIRC 20-ish MBit/s as 802.11n was still formally a draft... the idea was to give high-bandwidth networking to home entertainment devices without requiring to run physical Ethernet to each tiny device, but it quickly became superseded by 802.11n Wifi on one side, and on the other side, the "enrichment" of stuff on DVDs or broadcast TV with internet-based content never truly materialized.
[1] https://en.wikipedia.org/wiki/HDMI#HEC
This is why most of the browsers rejected these specs. They are super useful, but the security risks are incredible. Most USB devices were not designed to hold up to being exposed to the internet.
I kinda remember that the counterargument Google used is that only devices with a special attribute would ever be available through WebHID, ensuring that such older devices would never be exposed.
Cue my surprise when it turns out you can use WebHID to program a Minidisc / Net-MD device [1], so.. they never did implement that filter, apparently. I mean, certainly it is useful, but ... What The F., Google?
[1] https://web.minidisc.wiki/
9 replies →
Note that when you say “rejected”, Mozilla’s position has actually shifted a bit. At the end of 2022, it shipped MIDI in the form of an extension that it will prompt to install for the purpose, with more detailed information and a couple of other details that make it less unsafe. After a few years of that, consensus has grown that this seems to be working acceptably, and that the technique may be considered for other risky areas. They haven’t said anything about USB publicly, to my knowledge, which is definitely way more dangerous than MIDI (even SysEx), but I have heard one rumour (of dubious provenance) that they may cautiously proceed with USB and such too some time soon. Though this sort of thing definitely weighs against that, showing that maybe they were right the first time.
The key takeaway for me was he bought a $300 microphone and is acting indignant that he has full access to his own hardware via — gasp — a command shell.
Do we live in a bizarro world now where we expect — no, demand — our hardware be locked down?
It's worth mentioning all USB mics are toys anyway. Analog interfaces have gone away — artificially so — now they cram them into the device.
All mics are analog.
You make a good point: hardware should not be default-locked from owner control and manipulation in the name of security. In fact, in the name of security, the default should be open enough to not only manipulate and reflash through owner accessible channels, it should also be easily flashable through chip clips in the worst case compromise scenario. Owner control of all Universal Machines in an object he owns must be a paramount right, akin to the first and second amendments in the bill of rights! This includes your game consoles, vehicles, stoves, washing machines, TVs, microwaves, and even that Qualcomm processor in cellphone basebands. If it is a Universal Machine which executes code from writeable storage (or firmware/microcode provided to it, like during OS boot or driver initialization), it must permit owners to change it. If it comes with cryptographic integrity check keys, the owner must be able to both write his own keys and purge the OEM's keys. Behavior should not change, even the warning Google Pixels give immediately on turn-on are unacceptable, unless it does it by default for the OEM's keys and firmware too; no change in product behavior or appearance when an owner exercises his right to modify his Universal Machines, except where the change arises from the firmware itself that the owner applies.
At this point manufacturers should just open-source their firmwares as there's no barrier for entry to reverse engineer it. They will instead gain from army of end-users willing to put their time and tokens into fixing their bugs for free.
>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying!
Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
> the LED can't be controlled from software
If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.
You can say a lot about Apple but the engineering is clever at the hardware level.
Also the Hall effect sensor disabling the mic when a MacBook lid is closed, apparently just about impossible to bypass. https://en.wikipedia.org/wiki/Hall_effect
2 replies →
It's not even that clever, really. The camera power rail must be physically close to the camera, so it's trivial to hang an LED off it. A device manufacturer has to go out of their way to make it so the LED and camera function are independent, and I'm sure many do, for the worst reasons you can possibly think of.
9 replies →
This still would allow one to "strobe" the power line making it impossible for a human to see the LED but the camera could still capture snapshots and at a decent framerate even.
One of my old Logitech webcams have its recording light wired up to V4L2 protocol directly. I can change its recording light mode (on/off/blink) from software by changing recording light mode directly. Wonder whether that Insta360 also had that.
I'd have tried that first before diving into the firmware head-first.
Apple also claims that iMessage is end to end encrypted. Their privacy stance is 99% posturing.
The teardown showed this is the 1% right?
Also I thought you could trust iMessage if, unlike everyone, you disabled iCloud backup (and, unlike everyone, so did the recipient). Perhaps a way for the feds to be able to pin dumb criminals while giving investigative journalists & dissidents a way to stay safer.
4 replies →
Ah, I remember when reversing hardware took weeks / months, an oscilloscope, logic analyzer, Ghidra/IDA, Wireshark, breakout boards, wireless sniffers... back in the olden days of... 2019.
if an AI could do it without an oscilloscope, probably a human could too.
It's kind of funny, but AI can also use an oscilloscope. My friend vibe coded a software synth on a Raspberry Pi Pico. When he realized his oscilloscope had a network interface, he had Claude figure out how to connect to it over the network and analyze the actual audio output.
I had claude write an mcp server to talk to my scope since most are connected over Ethernet. It was pretty fun.
https://netliststudio.com/articles/2026/02/23/claude-oscillo...
2 replies →
I posted [1] a few days ago my experience using LLM to reverse engineering an entirely undocumented device that was only supported by a (crappy) Windows application, and it was honestly remarkable how good Claude was at decompiling the Windows EXE and reverse engineering the protocol. Very exciting. "The developer refuses to write software for this device" is no longer as scary as it used to be.
1: https://news.ycombinator.com/item?id=49353141
I did this a while back with my Eaton UPS and Opus 4.8, glad I didn't need to install windows 11 just to push a blob. The day when a LLM os can make unique drivers will be one I wait for
An Agent helped me get a Windows XP Korean MMORPG private server running on my Steam Deck last week. The community obviously got us most of the way there (huge props to them) but setting it up on Linux seemed like a brick wall. Now it works. Amazing for keeping old tech open and running: https://github.com/P0nk/Cosmic/discussions/350
I had used codex to reverse engineer an electric skateboard to unbrick it. It was a bit more involved because it required soldering wires directly to the UART headers in a very awkward location.
Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
This is giving me the confidence to RE my cat feeder. The company (Petlibro) has an outage and now my chilled wet feeder that should be a dumb, offline feeder is basically bricked now.
The device reports fine wifi but the backing services are totally busted.
Have you seen https://github.com/taylorfinnell/petlibro-esphome?
I have one of their dry food ones and no longer need it. Sad story, but it happens.
My cat scarfed and barfed periodically, and I always wanted the Petlibro (the simple one) to slow feed by incrementally turning the auger, just to see if it helped. I might dig it out and try my hand at this.
Why do you have a cat when you can't be bothered to feed it yourself?
3 replies →
It's amazing to see LLMs give us software and hardware freedoms that the open source movement has only ever dreamed about.
The flip side is that this might become a thing of the past for future hardware/firmware, if AI hardening becomes standard practice.
There’s no substitute for having open systems that aren’t cryptographically locked down by the manufacturer.
We were already there. For most people, we are still there. For most devices (especially popular ones, with enough manufacturing volume) there's just enough hardening, downgrade prevention, encrypted or signed firmware blobs, on top of already rare reverse engineering skills and patience, to make it infeasible for most people to give it a crack. Using an LLM for that also isn't a mainstream idea either (plus you're unlikely to have a Claude subscription if you're not a software developer in the first place).
Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
1 reply →
I think that this is not true -- the achievements mentioned here are hardly ground breaking and mostly build on work that was already done years before LLMs were a thing.
There are things that the "open source movement" dreams about, and one just has to search around... E.g. like codecs, Qualcomm's aptX lossless, adaptative, and other more recent variations.
It's not new capabilities, it's new levels of access. Reverse engineering this stuff used to be a very tedious process which required a lot of specialised skill. Which is why most devices haven't been reverse engineered or hacked despite being full of low hanging fruit.
Did the open source movement dream of outsourcing what they loved to do themselves for free, as in both beer and freedom, to products which are trained on the corpus of their own knowledge without any consent and sold by behemoth corporations on a subscription basis?
Brings me a lot of joy to see these articles. They've inspired me to reverse engineer my laptop again.
"only ever" feels like a stretch. Libratbag, QMK, OpenWRT, Nouveau and Asahi all took up the task without much or any AI help. They're not all just dreamers.
Enjoy it while it lasts.
There's a difference between the people sitting at the table and the mice scurrying around catching the crumbs. Freedom is sitting at the table. The OP, sadly, is catching the crumbs.
I did this just yesterday with a smart light. Used Deepseek-v4-flash. In about 2h I had a custom firmware on the smart light running that I could control from its api endpoints. Also now Im hosting a small web-server on there that lets me set schedules and sleep timers. No im not relying on their proprietary cloud anymore to toggle my lights. Which is insane to start with. Why should my phone that is in my home network need to send the "light on" command ot some cloud in a different country, only to then send the command back into my home network and turn the light on.
Im definitly very exited to try this our with more devices in my live.
Perhaps I’m daydreaming, but maybe some vendors will accept this new reality and begin just selling the hardware without locking users in. Perhaps they’ll even make it easier for users to truly own their products.
No, they will just encrypt firmware, add more signature verifications and lock devices to accounts in order to complicate reuse, increase sales and produce more ewaste.
I agree, but like many others I'm willing to pay a fair price for that freedom and ownership, and I believe there is a customer base to be captured. And in the end there's a cost for a company to put all of those locks in place, which they could simply avoid.
DIY kits have been a thing... forever? There's lots of open source hardware out there, and some you can even buy if you demand commercial access.
We have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.
I desperately want this, but our Frame has never been connected to the Wifi, and I'm really reluctant to do so, as it will probably start snitching and/or delivering ads...
Adguard and Smart TV blocklist might help. It's crazy how much my Sony wants to sneak out behind my back if I'd let it.
The tv-ws-api can be used over ethernet. I control my Frame TV from a pi through direct ethernet cable and the pi separately connects to my home LAN over WiFi and serves an app for Frame art control. The TV has never had direct access to the LAN or internet. Check the frame subreddit for several such projects.
1 reply →
New, ad free, firmware is obv a couple of prompts away...just sayin... ;)
Nice! I actually built something similar back in early 2023 [1], which used a collection of SDXL models to generate a new random painting every hour upscaled to 4K and then broadcasted to my frame using the Samsung WS API wrapper [2].
[1] - https://mordenstar.com/projects/save-our-screens
[2] - https://github.com/xchwarze/samsung-tv-ws-api
Neat. What’s the lift from here to get a zero-token spend image upload?
People are praising how this new age of owning our stuff is here, while actually all this will bring is stricter lockdown in every level of the supply chain. Enjoy while it lasts, but I expect even more closed stuff, and less openness from these t.rends
The other option is to look for better products that take simplicity, security, ownership and verifiability seriously. I think there's a market. Consider Precusor[0] who's design philosophy could be duplicated. Such a company could become the Anker of computer peripherals: build quality products that decommoditize markets. Now is the time to make such a company, because by the time the peripherapocolypse hits (in a few months) by then it will be too late.
[0] https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...
If I can't hack it with local access and an AI, a random hacker can't do it either.
I do lament the loss of control, but the increase in security will be objectively good for humanity as a whole.
While closedness is bad, I assumed peripherals like these were closed anyway; the fact they were hackable implies they were not secure enough.
So if closed means they are secure, which 99.99% of end users expect, I'm actually okay with it.
closed is never secure. it's just open only for a smaller circle.
Well, the takeway is that we should keep pushing to write everything in Assembly and C, so that human errors allow such "ownership".
AI PR department at it again: sell to hackers what they ostensibly used to love doing themselves babbling about the ideals of freedom and openness.
So much for the "hackers", I guess.
What I wish is that we started reverse-engineering audio receivers, many of which run regular Linux. Manufacturers tend to release the new models with hardly any hardware changes, sometimes only software updates. To be able to backport an Airplay2 to an older, fully functional receiver would be amazing.
I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
How’d you get Opus 5 not to just give up instantly for reverse engineering? Are you sure you’re using Opus 5 and not 4.8 by automatic fallback?
I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
I have CVP access, which removes the external refusals for Opus 5. I submitted my LinkedIn and Github and got approved in less than 10 minutes.
Are you on an enterprise plan? I’m on a personal plan so I never bothered. I assumed they wouldn’t approve.
Also is your LinkedIn cyber security adjacent?
2 replies →
I guess there is this dream that AI will help us finally close the Linux driver gap, and maybe even conquer the android phone closed hardware driver conundrum making almost every phone locked down. One can hope.
I definitely managed to get Linux running in full on my Xiaomi Pad tablet, each and every feature of it! Writing drivers is a breeze now, what remains difficult is upstreaming them.
I initially thought, but why would you want a "webcam whose activity LED I can switch off while it records"? But then I think I got the point: why would one want a webcam which _could be hacked_ so that its activity LED didn't go on.
I am certain if it can be “tricked” into using it with the LED off, there is certainly a feature being sold to “enterprises” where it happens on purpose.
I can see the benefit of from-scratch personalized software, but in the spirit of open-source, how about all the world contributes to useful software for everyone else?
Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
I'm starting to believe that bespoke, personalized software is the only way to combat feature bloat. Every software (proprietary or open source) I download and use has features I don't want getting in the way and bugs that the developers/maintainers are not prioritizing.
I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
I am wondering if there is a list of “things you should learn to do with your LLM” (But not the rubbish ads youtube keeps showing me)
Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.
I posted this on another thread but can someone please run this on some old iPads so we can be able to fully install Linux on them. If AI is so good surely it can do that and save millions of devices from turning into ewaste.
You can!
Don't be afraid to try. You're limited only by time and imagination now.
My Sony TV also faced some issues in the past, which at least let me start some investigation. Unfortunately it confirmed my assumptions that the hardware is very limited and already runs on full load most of the time. Still thinking about putting some more effort into this, but killing the device was also one of my concerns.
A really fun project was extendending the abilities of my reMarkable Pro. I missed a decent Manga Reader on the device, so I created a native one which makes use of my custom server.
Mind sharing it? I would also love a manga reader for remarkable!
I'm hopeful that in the future we can end planned obsolescence from devices that require companion apps which eventually get shut down. Just vibe reverse engineering replacements.
we could have ended planned obsolescence decades ago if we put strong policies in place. I would really like a systemic solution instead of every-man-for-himself vibe coding. I've been following the "stop killing games" movement for that reason. fingers crossed.
A replacement app could just send the vendor-signed image and leave the signature check to the device. Plenty useful once the official app disappears.
This a fascinating security write up. I had no idea the models were this capable for reverse engineering.
I heard CISA is getting defunded. I wonder if it'll become a common assumption for Americans that all their devices are just perpetually compromised.
I'm not sure CISA ever did anything material about this problem, or was likely to in the future.
we haven't even seen the peak yet, as the author says
> Network-connected devices seem near universally fucked at this point?
About 1.5 years ago I reported a vulnerability with my router’s ipv6. The firewall was wide open, and router management SSH was listening externally, among a few other vulnerabilities. After pulling teeth, the router fixed ssh, but not the firewall.
A couple months ago I used AI to find a novel shell injection exploit and obtain root creds in the router, so I could print out the firewall configuration , init script flaws , and write up a vulnerability report. AI found the bug and wrote the patch to fix it for the vendor, without having the original code ( the bug was in shell script, thankfully).
The vendor had commented out the IPv6 firewall init, probably to pass QA , knowing consumers don’t usually use or test IPv6.
Upon getting the report, the vendor fixed the issue.
> I can’t help but think about what an AI-equipped automatically-reverse-engineering worm could do today.
Everyone should read Daemon and Freedom, like right now.
I didn’t put this in the post, but yeah, I think about Daemon almost every day at this point. Unbelievably prescient novel.
This one? https://en.wikipedia.org/wiki/Freedom%E2%84%A2
That is the second book, but yes. Read Daemon first.
I spent a decade in robotics and have built firmware for dozens of devices. And yet I was never able to successfully fix my webcam device driver on linux with Claude. I'm jealous of this person's prompting skills! Or perhaps pwning is easier than fixing the nightmare that is Intel open source device drivers?
There are two nuances here;
1. The author might be exaggerating or lying in regards to the capabilities, ease of use, and result
2. if Claude can do it without hardware access, I struggle to see how it could be anything other than unsigned unencrypted firmware images that you can unpack and mess with
The i2c over USB with no auth is just way way too common; I've also seen that on a device.
I did something similar but with smart home devices. I use the homebridge interface to connect my smart home devices to Apple's homekit protocol. Some homebridge plugins for my devices were outdated and no longer maintained, so I asked Codex/Claude to help me create a patch of it as a local fork, so my smart home devices can still run without problems.
It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
Maybe this is what Jevon's Paradox looks like for LLMs.
Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
I've spent SO MUCH TIME in my life trying to get laboratory machinery, usually only ten of them in the world, to spit out their data nicely. They have UIs but usually god-awful, and all data is hidden away somewhere (they're written by biologists, for biologists). I wish I could go void some warranties....
Sidenote to the technical discussion. The article read like a Martha Wells murderbot novel to me. Fascinating.
Yep, Claude did well here. From the experiment, to the website design, to more than likely all the writing/summaries. What is truly fascinating is not that long ago people were doing hard experiments regularly like this without any LLMs.
Like Dublin, in the rare ould times.
This is great stuff. Wouldn't this be lovely to go "fix" misbehaving devices (LG TV)
this is interesting, while i greatly apreciate the ability with claude code to basically customize my own firmware. There are things that I am strictly speaking wondering about the authors choices. The Author removed Pixel Cleaning? As far as I understand Pixel Cleaning is a process to make sure your OLED Monitor lives longer, why would you want to not do that?
My monitor can run a pixel cleaning automatically when it detects that there is no longer a signal coming in. That way it periodically cleans, but has never done so while I was using it. I presume the author uses the same mechanism and just doesn't want to be bothered about it.
Printers are a juicy target, they can have enough CPU/RAM/storage to be a good hiding place for backdoors.
Or you just want to patch out rejection of 3rd party ink/toner.
But seriously - is software industry over?
Where the next talent would come from?
This is the first exciting thing I've seen done with LLMs in quite some time. Turning on or off an LED doesn't seem world shattering, but the idea that we might be able to unlock or add functionality to hardware we own makes me giddy
This is timely! I'm trying to take control of my Echo Wall Clock which connects to an Alexa device that I want to get rid of. There's very little info on it but Claude was able to find the FCC filings and now we've got lo-res images of the circuit board. It's inspecting the test pads on the circuit board now to see if it can figure out how to replace the firmware.
I have interest in this. My Echo Wall Clock is the only reason I still have an Alexa device in my home.
Did something like this to play RTMP-over-HTTP from a security camera, no server required. didn't poke for rce yet. And same for a capture card with a HDMI loop out that was dropping audio when the monitor you plugged into it didn't advertise sound support in its edid, now it works.
Honestly I do like this trend if it genuinely leads to more interoperability. Im not sure that is the case though and in fact I worry people will start to imagine that anybody can do that in no time and that future devices will remain hackable this way. I have no doubt it was fun for OP to do but I bet most people who try that, people with less understanding, will inevitably end up nowhere or, worst, with bricked device in unrecoverable states. I feel this is one of the best use of AI at the moment, namely gaining agency by having devices do what their own wants and I hope it will lead to manufacturers selling both safer AND more interoperable devices but I'll remain prudently skeptical.
I suspect all this will go away soon, even from Chinese models for, uh, security reasons.
Maybe, but also the cat is out of the bag, as open weights models can do it.
I suppose you could make having those illegal through on-device scanning and legally mandating usage of operating systems that do that?
Not sure. Not sure if this tech can be contained. Dario does it for the wrong reasons, but it's not like there would be no point in his fearmongering.
__
I wonder if someone will try something like with printers, in that new and more powerful compute units see signatures of models and just refuse execution in the same way inkjet printers refuse to print euro bills.
I'm not sure if that would be a sensible thing to do, but that is a different question from "will someone try that path?"
I bought a Evnia 27M2N8500 and has been having issues too with the Pixel cleaning, sometimes i turn it on and it says its been 4 hours, or simply never show it the whole day... I'm not brave enough to brick the 700 euros monitor :( for the rest of the things i own i pretty much did the same as most of the OG software is just bloat, 1gb to just control pc fans is evil.
Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
I have an LG TV with a similar problem. I think it’s supposed to pixel clean when you turn it off, and I do every night.
Yet for some reason I can’t escape these annoying pixel cleaning interruptions. Seems like a bug in the firmware.
That feels like it should only require a single person working on the product to experience and demand an immediate fix.
3 replies →
I hope someone does this for the Sonos speakers
https://github.com/luckyshot/OpenSound
- Kindle Book decryption - Game Console(XBOX especially) Jailbreak
Let’s go!
I own the Insta360 Link too, will flash this firmware since I also want to turn off the LED ring.
Which model does one use for this?
I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis.
I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.
Anthropic's Claude: own your things, for only 20 dollars per month!
The difference is that you'll own the hacked solution forever, even if you unsubscribe from Claude.
Using AI to build tools you own and operate is the way.
Built custom firmware for my Line 6 Pod GO HD guitar multi-fx the other day. Turned into a complete midi controller so it wasn't gathering dust. Fun times!
So is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?
When will reversing unlock old Apple devices for other OS'es?
> Network-connected devices seem near universally fucked at this point?
I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.
And no, not a programmable switch. A hardware switch.
They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
Give it time.
The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes.
I like your idea
All this ownage will get shut down when manufacturers start whining to politicians and the AI companies will ask how high to jump.
The best models for reverse engineering right now are the Chinese ones. You can download them and run them unrestricted right now.
Open hardware being reverse engineered with LLM is cool.
I’d say John Deer will be among first ones requesting a halt.
It was similar with Napster vs recording companies… and then Spotify bulldozed everything with its attitude.
With LLM it could be much faster.
If Opus 5 can do it, there will probably be a Chinese OSS model that can do it before the end of the year.
What's that? A law that all manufacturers need to have had a security review from one of the major AI player's AI models?
Yep. Every single time.
Why does this feel like arms race where the only real winner is the arms seller?
I remember that name from NCSSM! Cool to see you on the front page of HN.
We should catch up some time, it’s been ages!
this is awesome! I also did something similar with the Orba by Artiphon [1]. Initially I was pretty disappointed by the current state of the Android app, and honestly I just wanted to see what happens if I plug this thing in and ask my Bob bot to take a look around. What I didn't know before starting was that Artiphon went bankrupt last year, which is a bummer cause they made a lot of cool hardware. I have not considered the firmware route, and just relied on decompiling whatever APK/exe, but the idea of controlling a device which is essentially no longer maintained, and all for a few hours of bobbing is quite spectacular.
[1] https://github.com/holofermes/orba-protocol
I have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do.
I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.
It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.
It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.
This indeed works very well, most device are not very well locked down because of proje t resources limitation, and this opens a new era of hacking.
Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI.
This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.
As FW engineer, I am both horrified and intrigued.
The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.
But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.
Sorry community, but it's our job to make the reverse engineer harder.
Why is your job to make the reverse engineer harder? When the user buys a product, it should be theirs to do whatever they want, even brick it. Your job should be creating the product the user wants to use, not building obstacles, otherwise you are creating something actively user-hostile. What if your company goes out of business and the user ends up with a device that can't be updated, that depends on cloud services that don't exist anymore, or worse with security vulnerabilities?
"Making reverse engineer harder" is just a side product of "improving security" that upper-level people like to hear.
I definitely don't want my C-suite people reading "The product X of company Y has been reversed engineered" on their newspaper.
1 reply →
If you can use a custom chip yep, if it's commodity hardware probably not. You could use secure boot/secure memory etc but that can be a footgun in itself later.
What do you mean "Custom chip", like ASIC ? Never in my career that i feel the need to make our own ASIC.
3 replies →
> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.
Oh very good!
> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.
Oh that was going so well. Just wow.
Wait,what?
Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"?
WTF Anthropic? Is the trick not using Python?
You can request for Cyber Verification Program (CVP) access from Anthropic
This requires submitting a photo ID to Persona, something no one should be comfortable doing. There are very real privacy concerns with Persona, so much so that Discord dropped them as their provider.
Maybe. It wrote C code that override some of my hardware without a single complaints. Try it
This fills me with the sadness of the Jeep hack. Incredible fantastic super amazing work to liberate devices! Finally a peak behind the curtain!
But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"
I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
Thanks, I hate it.
The camera in particular is exactly why I’ve reverted to using devices without networking capabilities.
Nothing owned.. Maybe the webcam a bit but this is mainly, again, just slop.
holy crap how ! i'd love to jailbreak my old quest 2. its such a good device too bad about all the facebook spyware!
[flagged]
[dead]
[dead]
Any intelligent powerful person should be going entirely offline now--if I had net worth over $10mm, I wouldn't own a computer--I would have a secretary control my computer for me. We're going to see really horrible, persistent blackmail in the next few years destroying lives and reputations. It will eventually be the end of the consumer internet.
[dead]
[flagged]
Why? Does it bother you to see people using their own devices in the ways that they want?
Technically this is Schlarpcoding.
That’s what they said when ASM was created. It’s what they said when C was created. Java. SQL. Powershell.
Programming has always been about putting more power into the tools.
Sadly, there doesn’t seem to be as much need for hardcore engineers.
This looks like an ad for a bunch of products as "hackable". The Authors only other blog post is also about using Claude for similar ideas, without actually showing the end product from a kick skim.
Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.