logoalt Hacker News

I spent $266 and four AI models to own my tablet. GLM-5.3 finished it in a day

595 pointsby dr_pardeetoday at 2:23 PM263 commentsview on HN

Comments

kmeisthaxtoday at 4:51 PM

> Is it legal? In the US, yes: the Librarian of Congress’s 2024 DMCA exemptions (in effect through October 2027, next rulemaking already underway) cover rooting tablets you own to remove unwanted software. My device, my risk, my API bill. Nobody else’s hardware was ever touched.

For you, yes, prompt kiddie rooting your own device is legal. In fact, it's one of the only things I actually want AI to do, because breaking DRM is a bullshit job[0] and shouldn't exist. AI deals in bullshit, so it's very poetic to use AI to destroy its own bullshit. However, from the point of view of the model provider, there are very specific legal risks to letting someone vibe code their own jailbreaks, especially if a model is already cloud-hosted and heavily regulated. Allowing hacking on your own devices could be construed as trafficking in circumvention tools, so offering that capability to randos opens Anthropic up to another billion-dollar lawsuit.

I could see this being another thing that gets put behind Trusted Access programs. Corellium was able to get away with offering cloud-hosted virtual iOS devices, using an OS they don't own, because DMCA 1201 has an explicit carveout for security research. But "make my device stop doing this thing I don't want" isn't security research, so a lot of prompt kiddie jailbreak uses become legally fraught again.

[0] In the same Graeberian sense that all military officials are staffing bullshit jobs - it is a job that exists solely to undo some other job.

root_axistoday at 4:40 PM

Ok, now try it with an iPad

dr_pardeetoday at 2:24 PM

Author here. Quick context: the tablet is a 2021 Fire HD 10 that ran my Home Assistant dashboard and kept powering itself off: the logs showed Amazon's own software issuing the shutdowns, and the only permanent fix was root, which has never existed publicly for this model. Anthropic's and OpenAI's cyber safeguards wouldn't touch the project. Moonshot's Kimi K3 found an unpatched 2022 Mali CVE (CVE-2022-38181: fixed upstream in 2022, patched by Amazon in 2024, but my firmware never got it), GLM-5.2 caught two fatal bugs in the exploit, and GLM-5.3 finished it in a day. The full technical write-up with every offset and dead end is HANDOFF.md in the repo. Happy to answer questions: especially about the model-steering side, which was most of my actual contribution.

show 6 replies
luciana1utoday at 5:21 PM

[dead]

sebstefantoday at 7:53 PM

[dead]

caminantetoday at 4:04 PM

[flagged]

show 2 replies