logoalt Hacker News

Everything I own, owned

1342 pointsby schlarpcyesterday at 10:41 PM335 commentsview on HN

https://web.archive.org/web/20260823225933/https://schlarp.c...


Comments

0cf8612b2e1eyesterday at 11:44 PM

  The pixel cleaning warning turns out to have no native way to disable it, and it’ll always show up after 8 hours of runtime.
Come on, does anyone dog food their own products anymore? How could a single person developing the monitor actually believe consumers want to be bothered with this every day? If the hardware is really so terrible this must happen, find some way to incrementally do it silently or off hours. Anything else.
show 1 reply
WalterBrighttoday at 6:12 AM

> Network-connected devices seem near universally fucked at this point?

I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.

And no, not a programmable switch. A hardware switch.

They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.

show 1 reply
touchmetoday at 8:46 AM

I bought a Evnia 27M2N8500 and has been having issues too with the Pixel cleaning, sometimes i turn it on and it says its been 4 hours, or simply never show it the whole day... I'm not brave enough to brick the 700 euros monitor :( for the rest of the things i own i pretty much did the same as most of the OG software is just bloat, 1gb to just control pc fans is evil.

erikkritoday at 8:06 AM

I hope someone does this for the Sonos speakers

show 1 reply
wg0today at 1:34 PM

But seriously - is software industry over?

Where the next talent would come from?

webprofusiontoday at 3:53 AM

Built custom firmware for my Line 6 Pod GO HD guitar multi-fx the other day. Turned into a complete midi controller so it wasn't gathering dust. Fun times!

konraditurbetoday at 8:56 AM

I own the Insta360 Link too, will flash this firmware since I also want to turn off the LED ring.

usernomdeguerreyesterday at 11:28 PM

So is an actionable lesson here to favor devices that aren't USB/wifi connected if they don't have to be? Or perhaps just choose low-tech versions that don't attempt fancy features?

hajimuztoday at 11:22 AM

- Kindle Book decryption - Game Console(XBOX especially) Jailbreak

Let’s go!

jeroenhdtoday at 9:13 AM

Anthropic's Claude: own your things, for only 20 dollars per month!

show 1 reply
shrubbytoday at 8:28 AM

When will reversing unlock old Apple devices for other OS'es?

wewewedxfgdfyesterday at 11:14 PM

All this ownage will get shut down when manufacturers start whining to politicians and the AI companies will ask how high to jump.

show 4 replies
jimmy76615today at 11:59 AM

Which model does one use for this?

I generally like Codex (gpt 5.6 Sol), but the guardrails are often a problem. I find myself writing all kinds of fake lie stories all the time with some large damn explanation of why this is a very legitimate good guy kind of behavior and why I absolutely have to root this device etc. and I honestly hate how these tools (that are fucking wonderful!) train me to lie on a regular basis.

I would instantly have weeks full of very cool projects to work on if I get could access to something like Daybreak Red, but unfortunately I haven't yet found an OSS LLM that has had its guardrails removes without taking heavy brain damage.

vinay_ystoday at 1:35 AM

Why does this feel like arms race where the only real winner is the arms seller?

rspeeletoday at 12:54 AM

I remember that name from NCSSM! Cool to see you on the front page of HN.

show 1 reply
hn1rig3raktoday at 10:44 AM

Yep. Every single time.

tonymettoday at 3:52 PM

About 1.5 years ago I reported a vulnerability with my router’s ipv6. The firewall was wide open, and router management SSH was listening externally, among a few other vulnerabilities. After pulling teeth, the router fixed ssh, but not the firewall.

A couple months ago I used AI to find a novel shell injection exploit and obtain root creds in the router, so I could print out the firewall configuration , init script flaws , and write up a vulnerability report. AI found the bug and wrote the patch to fix it for the vendor, without having the original code ( the bug was in shell script, thankfully).

The vendor had commented out the IPv6 firewall init, probably to pass QA , knowing consumers don’t usually use or test IPv6.

Upon getting the report, the vendor fixed the issue.

holofermestoday at 9:23 AM

this is awesome! I also did something similar with the Orba by Artiphon [1]. Initially I was pretty disappointed by the current state of the Android app, and honestly I just wanted to see what happens if I plug this thing in and ask my Bob bot to take a look around. What I didn't know before starting was that Artiphon went bankrupt last year, which is a bummer cause they made a lot of cool hardware. I have not considered the firmware route, and just relied on decompiling whatever APK/exe, but the idea of controlling a device which is essentially no longer maintained, and all for a few hours of bobbing is quite spectacular.

[1] https://github.com/holofermes/orba-protocol

PeterStuertoday at 5:27 AM

Wait,what?

Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"?

WTF Anthropic? Is the trick not using Python?

show 2 replies
soulofmischieftoday at 12:46 AM

I have been tinkering with various firmwares of devices around the house lately as well. I have an agent hooked up to various GPIO pinouts and play lab monkey for it. Honestly they are getting better and better at exploratory research and self-supervision for these kinds of tasks and it's fun to watch. I don't often have to interject, though sometimes I do.

I watched an agent identify and find the correct firmware for a device by taking photos of its circuit boards and comparing them to those found online in internal documentation, patents, parts sheets, etc.

It's pretty fun! If you have your HAM license you can do some fun stuff letting an agemt control an SDR, too. Still a lot of fun to be had even in passive mode.

It will be interesting watching what kind of tinkerer/hacker/enthusiast cultures arises from these new paradigms. Wait til people start suping up their vehicles with natural language agents that have access to subsystems. Imagine entire automated labs hooked up to agents.

mrheosupertoday at 2:06 AM

As FW engineer, I am both horrified and intrigued.

The fact that there are so many devices lack even basic security features horrified me. A webcam that activity light can be turned off remotely, that's a big no no for me.

But the use of LLM is also very interesting, we may put LLM in the loop to harden our devices.

Sorry community, but it's our job to make the reverse engineer harder.

show 1 reply
BiteCode_devtoday at 8:26 AM

This indeed works very well, most device are not very well locked down because of proje t resources limitation, and this opens a new era of hacking.

Unminifying, deobfuscating, api probing, hardware scanning and firmware decompiling are all operations that benefit a lot from AI.

This will start a new cat and mouse race, as it's also cheaper than ever to add friction to prevent those with AI as well and companies will notice soon. They historically hate hacking despite the fact a lot of success in their field can be directly traced back to it.

lowbloodsugartoday at 5:55 AM

> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.

Oh very good!

> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.

Oh that was going so well. Just wow.

jauntywundrkindtoday at 5:05 AM

This fills me with the sadness of the Jeep hack. Incredible fantastic super amazing work to liberate devices! Finally a peak behind the curtain!

But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"

I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.

RS-232today at 9:39 AM

Thanks, I hate it.

The camera in particular is exactly why I’ve reverted to using devices without networking capabilities.

dncornholiotoday at 7:31 AM

Nothing owned.. Maybe the webcam a bit but this is mainly, again, just slop.

markzuckerberhhyesterday at 11:58 PM

holy crap how ! i'd love to jailbreak my old quest 2. its such a good device too bad about all the facebook spyware!

fenestellatoday at 2:38 PM

[flagged]

ozereray1today at 11:42 AM

[dead]

malixptoday at 5:58 AM

[dead]

jaco6today at 3:50 AM

Any intelligent powerful person should be going entirely offline now--if I had net worth over $10mm, I wouldn't own a computer--I would have a secretary control my computer for me. We're going to see really horrible, persistent blackmail in the next few years destroying lives and reputations. It will eventually be the end of the consumer internet.

Jhatertoday at 2:36 AM

[dead]

rarismayesterday at 11:38 PM

The larpcoding epidemic needs to be stopped

show 3 replies
asdfsa32today at 3:13 AM

This looks like an ad for a bunch of products as "hackable". The Authors only other blog post is also about using Claude for similar ideas, without actually showing the end product from a kick skim.

Anthropic has been run "Use Claude for hardware" ads nonstop. Seems very suss.