logoalt Hacker News

Everything I own, owned

342 pointsby schlarpcyesterday at 10:41 PM101 commentsview on HN

https://web.archive.org/web/20260823225933/https://schlarp.c...


Comments

Waterluviantoday at 1:38 AM

Two weeks ago I told Claude “I have a <wifi outlet relay> on the LAN at <IP>. Assume direct control of it.” And about 8 command approvals later I had a new firmware running on it.

Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.

show 1 reply
ndiddytoday at 12:13 AM

> My ASUS ROG Swift PG42UQ monitor was actually where I started, because I got annoyed at the pop-up overlay that comes up every once in a while that tells me to run “pixel cleaning”. I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever. Maybe there’s a debug menu or something that can turn it off, or worst case we patch a branch in the firmware?

Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.

show 6 replies
srcreighyesterday at 11:31 PM

> I haven’t actually been brave enough to write a modified firmware to the thing yet - it’s a pretty expensive monitor - but I’ll get there at some point.

Honestly if you don't have working patches, it's really not owned.

I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.

Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...

We are NOT there yet but I hope we get there soon.

show 1 reply
philipsyesterday at 11:09 PM

I just reverse engineered the Supernote note file format with an agent a few weeks ago. For years the community had been asking for a document on the format. And in a few hours the agent, with 20 something file format example fixtures and 30 something prompts, was able to reverse out the format.

It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.

https://github.com/philips/supernote-typescript/blob/main/pl...

https://philips.github.io/supernote-typescript/

show 3 replies
teddyhyesterday at 11:22 PM

Key takeaway:

> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.

show 3 replies
simonwtoday at 1:48 AM

We have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.

show 2 replies
NavinFtoday at 1:12 AM

>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying!

Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.

show 1 reply
Retr0idyesterday at 11:18 PM

Using LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic.

The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!

compiler-develyesterday at 11:46 PM

It's amazing to see LLMs give us software and hardware freedoms that the open source movement has only ever dreamed about.

show 6 replies
ks2048today at 1:22 AM

I can see the benefit of from-scratch personalized software, but in the spirit of open-source, how about all the world contributes to useful software for everyone else?

Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.

SubiculumCodetoday at 2:14 AM

I guess there is this dream that AI will help us finally close the Linux driver gap, and maybe even conquer the android phone closed hardware driver conundrum making almost every phone locked down. One can hope.

throwyawayyyyyesterday at 11:48 PM

I initially thought, but why would you want a "webcam whose activity LED I can switch off while it records"? But then I think I got the point: why would one want a webcam which _could be hacked_ so that its activity LED didn't go on.

show 1 reply
SlightlyLeftPadyesterday at 11:58 PM

I had used codex to reverse engineer an electric skateboard to unbrick it. It was a bit more involved because it required soldering wires directly to the UART headers in a very awkward location.

Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.

show 1 reply
tuckerpotoday at 12:12 AM

Ah, I remember when reversing hardware took weeks / months, an oscilloscope, logic analyzer, Ghidra/IDA, Wireshark, breakout boards, wireless sniffers... back in the olden days of... 2019.

show 1 reply
lifeisstillgoodyesterday at 11:26 PM

I am wondering if there is a list of “things you should learn to do with your LLM” (But not the rubbish ads youtube keeps showing me)

Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.

SchemaLoadyesterday at 10:58 PM

I'm hopeful that in the future we can end planned obsolescence from devices that require companion apps which eventually get shut down. Just vibe reverse engineering replacements.

show 1 reply
arn3nyesterday at 11:06 PM

This a fascinating security write up. I had no idea the models were this capable for reverse engineering.

I heard CISA is getting defunded. I wonder if it'll become a common assumption for Americans that all their devices are just perpetually compromised.

show 2 replies
kachhalimbutoday at 12:34 AM

Sidenote to the technical discussion. The article read like a Martha Wells murderbot novel to me. Fascinating.

vinay_ystoday at 1:35 AM

Why does this feel like arms race where the only real winner is the arms seller?

trebligdivadyesterday at 11:54 PM

The i2c over USB with no auth is just way way too common; I've also seen that on a device.

0cf8612b2e1eyesterday at 11:44 PM

  The pixel cleaning warning turns out to have no native way to disable it, and it’ll always show up after 8 hours of runtime.
Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
show 1 reply
usernomdeguerreyesterday at 11:28 PM

So is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?

mrheosupertoday at 2:06 AM

As FW engineer, I am both horrified and intrigued.

The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.

But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.

Sorry community, but it's our job to make the reverse engineer harder.

rspeeletoday at 12:54 AM

I remember that name from NCSSM! Cool to see you on the front page of HN.

rarismayesterday at 11:38 PM

The larpcoding epidemic needs to be stopped

show 3 replies
wewewedxfgdfyesterday at 11:14 PM

All this ownage will get shut down when manufacturers start whining to politicians and the AI companies will ask how high to jump.

show 3 replies
soulofmischieftoday at 12:46 AM

I have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do.

I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.

It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.

It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.

markzuckerberhhyesterday at 11:58 PM

holy crap how ! i'd love to jailbreak my old quest 2. its such a good device too bad about all the facebook spyware!

Jhatertoday at 2:36 AM

[dead]