Live data from Hacker News

Everything I own, owned

schlarp.com

181–190 of 367 posts

Re: Everything I own, owned

#181
post #8

Using LLMs for RE and bug hunting is a lot of fun. Today I reported an absolute doozy of a bug to Google's VRP. The vuln was in an HTTP API endpoint I don't have the source for, only RE'd client logic. The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, includi…

I find whenever I do this I run into the bullshit cyber guardrails. What model are you using and how are you prompting it?

Opus 5 with CVP, no special prompting. In this instance just about any larger model from the last 12 months would have done the trick.

Re: Everything I own, owned

#182
> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.

Oh very good!

> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.

Oh that was going so well. Just wow.

Re: Everything I own, owned

#183

Earlier quoted context omitted.

You can’t be loyal to these things. I ditched ChatGPT during the peak Claude hype after Christmas. I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.

Just sign up with something like openrouter and keep switching models until one completes the task.

Paying by the token is a much more expensive way of doing it than signing up for the various coding plans when you need them.

Re: Everything I own, owned

#185

Earlier quoted context omitted.

I haven't and neither my friend

And what are we supposed to do with the two of you apparantly living under a rock [0], and going through baby's first "kids these days" moments, exactly? Never heard of LMGTFY ("Let Me Google That For You")? Why do you think it exists? Or "Google / Wikipedia is your friend"? Or RTFM ("Read The Fucking Manual")? Really not new inventions (and "zoomers" were there for them, cause the oldest ones are pushing 30! [1]). N…

I heard of them but have literally never seen any of those phrases on HN. Therefore I'm saying what I'm saying;)

I saw LMGTFY link once maybe...

Re: Everything I own, owned

#186
post #88

We have a Samsung Frame TV. I told Codex to scan our network to find it and then build a custom tool for updating the image gallery that it uses when it's in "art" mode. It did that, and now I can tell a Codex session controlled from my phone to "use this image" and it shows up on the TV a few moments later.

I desperately want this, but our Frame has never been connected to the Wifi, and I'm really reluctant to do so, as it will probably start snitching and/or delivering ads...

New, ad free, firmware is obv a couple of prompts away...just sayin... ;)

Re: Everything I own, owned

#187

I did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware. I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152. The driver works well, and now has full DRM and DKMS support. It also runs on mo…

This is so neat. This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy. When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead. Everything hardware belongs to us now. This programmable sand magic might undo big tech's grip on us all. We can mutate the world a…

Until the manufacturers enter an arms race and copy a page out of the mobile hardware vendors book. But perhaps they'll do it badly and we've got a few more years.

Re: Everything I own, owned

#188
post #139

> I can’t help but think about what an AI-equipped automatically-reverse-engineering worm could do today. Everyone should read Daemon and Freedom, like right now.

I didn’t put this in the post, but yeah, I think about Daemon almost every day at this point. Unbelievably prescient novel.

Re: Everything I own, owned

#189

I did this but with a dedicated machine for the Silicon Motion sm750 GPU. A budget single HDMI output GPU card for servers and a max resolution of 1080p. It is based on an older VGA/DVI version of the same hardware. I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152. The driver works well, and now has full DRM and DKMS support. It also runs on mo…

This is so neat. This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy. When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead. Everything hardware belongs to us now. This programmable sand magic might undo big tech's grip on us all. We can mutate the world a…

Don't get your hopes up.

What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.

It's of course still huge to be able to do this with all tech up until this cut-off point. Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.

___

Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.

Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.

We should keep in mind that not everyone wins here. In fact, only a minority does.

Re: Everything I own, owned

#190
> Network-connected devices seem near universally fucked at this point?

I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.

And no, not a programmable switch. A hardware switch.

They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.

Post reply on HN