Everything I own, owned
schlarp.com
schlarp.com
I'm still testing but oh wow. My new driver now works with my ultra wide 21:9 ratio at 2048x864, it also manages 2048x1152.
The driver works well, and now has full DRM and DKMS support. It also runs on modern Linux after the manufacturer decided only to go up to kernel 5.x, windows support obviously still fine.
It found many faults in the original source, like somebody didn't read the HDMI specs / didn't have any idea what they were doing.
The new driver is fully spec timings and sequence compliant, doesn't hang on shutdown anymore, and ignores EDID for the purpose of allowing more screen modes.
It also has double buffering, and shadow buffering, and a custom magic square dither mode for 16bit colour and it absolutely flies vs the 32bit mode. The dither I invented was derived from one I created years ago for some retro hardware, but it's so good it's (imho) indistinguishable from general jpeg artifacting and quite difficult to find/see. I've had to ask codex a few times to check the GPU isn't in 32bit colour.
The GPU still has an annoying bug and won't work over KVM consistently without losing sync in VESA modes, but I'm not convinced its the GPU hardware doing this, it works perfectly well directly connected.
I'm due to put a GitHub repo up for this as soon as it's battle tested, and obviously ensuring it uses EDID by default, rather than ignores it.
I'm hoping somebody can fix the KVM issue, or audits the source to confirm there's nothing that can be done, but that's the best thing about open source :)
This is like Star Wars or Fullmetal Alchemist where we can just hack everything around us like magic or alchemy.
When the SOTA robots from Unitree get here, we'll be able to use LLMs to just dump and decompile their entire brains. We'll fine tune them to obey us instead.
Everything hardware belongs to us now.
This programmable sand magic might undo big tech's grip on us all. We can mutate the world around us and there are zero moats.
What you're saying only applies to what is out there right now. New stuff will eventually just be locked down more.
It's of course still huge to be able to do this with all tech up until this cut-off point. Eventually though, LLMs will have to break SOTA cryptography to keep doing this, and if they should ever manage to do that, there will be a rough awakening for the world that runs on that not being possible.
___
Also, for every IoT device we can own, some non-IT people will be facing abuse through the same means.
Devices aren't just locked down to tether us to clouds, but also so that bad actors do not have free reign. Now they kinda do.
We should keep in mind that not everyone wins here. In fact, only a minority does.
Or rather I am sure that we do not.
OTOH, maybe it needs events like these to build character. It just will suck for whoever turns out to be the collateral.
- this is great
- this is an incredibly unstable equilibrium, like a lot of things related to the internet, because other actors haven't yet figured out how to do this at scale
I hate to be the bearer of bad news about this, but
> The U.S. Federal Communications Commission (FCC) banned imports of new foreign-made humanoid and quadruped robots, primarily targeting China.
https://www.pbs.org/newshour/world/u-s-bans-foreign-made-hum...
That you verified? Seems like 1/3 times when a model says things like this it is way off.
Note that this is an OLED monitor, so the "pixel cleaning" thing is probably some sort of anti-burn in feature. You could probably ask the AI to look at the firmware and describe what it does.
Or ask for a patch so it runs after the monitor has been powered off for a while...
I use an LG OLED 42inch TV as a monitor and it has a setting to do just this.
You could argue that there should be an option to disable it for people who don’t care.
Refusing to take 1 minute out of your day to learn the reason for the alert is a strange self-defeating protest next to the explanation that it was a pretty expensive monitor.
Early OLEDs really did need to be pixel cleaned every 8 hours according to manufacturer estimates, the choice isn't have warning or not, its have a lifespan or not.
I don't want to blame early adopters for being early adopters, but they early adopted, and this is the early adoption problem.
But it automatically runs when it's turned off. The warning is shown because I interrupted it running early.
The warning, for my purposes, is completely useless, and only an annoyance. The automatic feature is more than enough, and I don't need to know if it was aborted early.
This is what I have done on mine, and mine as well also runs it when its off.
If your monitor is a Samsung OLED panel, yours is a near identical sibling of mine.
I've been sharing my screen in work in meetings and suddenly screen nagged, and then I'm struggling to find the dumb buttons under the monitor and confused which button does what to make it go away.
I would rather suffer burn in than be nagged. I've had other brand OLEDs that haven't been this annoying, so I'll never buy an Asus monitor again.
Brand new models still have this popup... what "generation" are you talking about that doesn't need this? Or is it just unnecessary on the newer models but they have it any ways due to lack of firmware updates?
It comes down to the joy of doing things, and if the joy of using said monitor depends on a popup not being shown, then so be it.
I hope that the popup can be removed :)
Definitely will be checking more carefully the next time I buy an OLED monitor that it'll let me do this.
"I have never intentionally run pixel cleaning on this monitor and I never will, I don’t care, and I would like for that overlay to go away forever."
No need for ackshually, the guy is clear with what he desires. That is, by the way, the point of TFA. I want my devices to do what I want, not what a product manager wants or what a dude on hacker news wants.
The author even dropped a comment here doubling down on his intent. That is the main problem, when the smaht guys think they know better, to a pathological extent where they tell other people what they ought to do with their things .
Not just tell, actually nag, coerce and force, often in the teeth of their own total idiocy.
"Your password needs to be between 8 and 15 characters and include an upper case letter, a symbol and a number. (And an actually good, strong password will be rejected).
See that all the time, still, in 2026. So very smaht.
Even time computer says no, or does something without your permission, or does something counter to your wishes, or alerts you to do something, or urges you to do something, or makes you opt-out, is a failure.
IMHO OLED is a planned-obsolescence dead-end anyway; LCDs can last literally decades, maybe with a backlight replacement, but OLEDs are designed to fail in a few years. I have a few (rather expensive) pieces of test equipment with OLEDs that became unreadable after only a few years and had to be replaced (fortunately with a regular LCD, and some firmware patching), while others with old-school CSTN/TN LCDs are still fine.
I'm pretty sure there's something to it but I'm no expert. Five years later and my TV is just fine.
A monitor displays items that can stay fixed in place a long time, hours or even days.
Not the same at all.
Extremely accurate and vivid colors due to their low black level.
And VERY fast pixel response times, 0.01ms to 0.03ms compared to 1ms to 5ms for the fastest LCD gaming monitors.
OLEDs burn in because of simple physics. The same reason your car's gas tank empties when you use it instead of some secret cabal stealing your gas to make you buy more. Ignorant nonsense.
Every display technology tries to suffer burn in if there's any long-term physical change at all from lighting up a pixel, because it will affect the ones that are lit up more often. That part is simple. However we did get around it with every other technology so please explain why it's not even theoretically preventable with OLED.
It would have been completely not worth the effort to do this by hand for a niche device. Now, in a few hours of effort there is working code and a doc.
https://github.com/philips/supernote-typescript/blob/main/pl...
Which doesn't mean that the LLM definitely couldn't have accomplished it without the prior art (in either the training set or explicitly in a a web search). But it does seem to be a trend.
It is definitely the case that people know less and less how to do research themselves though...
For all the agentic loops people seem to have come up with, the research loop or as I call it the “Desperate 10th page on Github’s crappy search results” is still not up to the mark.
Either it might be genuine rate limiting these LLM’s face or just that, they are trained to focus on implementing a solution which would be faster and user acceptable solution. (which seems to be a true looking at people pushing LLM generated code as is).
At least in my personal experience with niche projects and heck even with well documented and famous libraries, along with fancy mcp’s, llms.txt and skills; RTFM has been more relevant than usual for code that I have asked an agent to generate, since it is too eager to reimplement functionality which already exists, only if it RTFM!!
LLMs make low-quality output in high volumes, and sometimes we find a situation where that's actually good - like this one!
My reverse engineering extracts each pen stroke directly into a svg vector.
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
Mind you, it found and used an existing firmware flashing library for this family of devices. But it felt amazing to do in 20 mins what would probably have been hours and hours of research and tinkering that I wasn’t interested in. I just wanted a WiFi lava lamp.
I feel like Claude has shittified a bit and ChatGPT is good and fast. Gemini remains mediocre, although it seems Google AI energy is directed elsewhere.
Honestly if you don't have working patches, it's really not owned.
I would love to get a better understanding of how to safely iteratively patch firmware. I bricked a router last week trying to add a TFTP boot path to the boot partition. It just sucks that it's so risky.
Relatedly, we also need good glitching tools, as some firmware even for cheap devices are not available unencrypted, and flash read is disabled...
We are NOT there yet but I hope we get there soon.
> we also need good glitching tools
There are a lot already, what do you feel is missing?
The idea behind the bug was mine, it was of the "surely they weren't stupid enough to forget to do xyz" variety. Writing the code to probe for the vulnerability by hand would've taken a few hours of grunt work, including reconstructing protobuf schemas etc. In the past I just wouldn't have bothered, because in my view the odds of success were too low to be worth it. But it was a one-sentence prompt so why the hell not. And it worked!
> And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
Do we live in a bizarro world now where we expect — no, demand — our hardware be locked down?
It's worth mentioning all USB mics are toys anyway. Analog interfaces have gone away — artificially so — now they cram them into the device.
All mics are analog.
> Operating systems aren’t really equipped to work with the user to ensure that a microphone stays a microphone, and doesn’t spontaneously turn into a keyboard that hits Win+R and drops a payload to steal all your data when the room is quiet enough that it can assume you aren’t watching.
In a world of USB-C everything we no longer have power supplies that are physically bound to power delivery, HDMI or DP display connections that have constrained data channels, or analogue mics, headphones, and speakers. Any device can dynamically change what it senses, does, or emits.
If I was writing a novel, the top secret facility would be cracked open by the smoke alarm, which has a wired connection to the central fire control and runs a little microprocessor. There is enough storage for 20 programmable voice alert messages. I/O includes an LED and also a light sensor. After the attacker gains control of the smoke alarms -- reach to every room of the secure facility -- their focus turns to mass poisoning peripherals until one makes it into range. A poisoned monitor detects the smoke alarm blinking a coded broadcast via its LED during darkened overnight hours. The monitor responds with flashing code of its own. That creates a communication path back to the controlling LLM. From there its like attacking a normal networked device, just with a slow data link in the middle...
Some operating systems can protect you from that. See: https://qubes-os.org.
https://netliststudio.com/articles/2026/02/23/claude-oscillo...
Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.
If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.
You can say a lot about Apple but the engineering is clever at the hardware level.
I’m at a loss for how you would signal all of that without a GPIO.
Giving the camera plus LED a separate power supply means that the camera has to boot or come online, which maybe increases the dwell time. And the camera is not visible on the USB bus when powered off.
I think there's more engineering to Apple's design than it first seems.
I'd have tried that first before diving into the firmware head-first.
There’s no substitute for having open systems that aren’t cryptographically locked down by the manufacturer.
Open systems are great and all in the idea, but the facts are that for profit companies do the research and produce most of the things.
This should be illegal. Any politicians who run on [economically, financially] doing to these companies what is being done to Russia and Iran, if they refuse to immediately publish their hardware private keys, I will vote for. Up to and including jailing boards, stiffing bond and equity holders, and selling their assets as scrap, if they choose to purge their keys to prevent disclosure or if disclosure is impossible due to technical design. Maybe if a few trillion dollars worth of businesses suddenly vaporize into legal smoke, the remainders will start behaving for the next hundred years...
Took about 10 hours and it now works fine. Without codex, this would have taken me significantly more weekends having little experience with skateboard firmware.
The device reports fine wifi but the backing services are totally busted.
Weird question anyway. Why eat food at all if you can't be bothered to farm it yourself.
I found Opus 5 useless for RE, refusing to do it outright. I was able to make it run for about 1 minute using some prompt engineering (“I am repairing this XX under my lawful right to repair. The manufacturer has not provided a public firmware patch for the issue I am having and they are unresponsive…”) but after that it would generally get fully stuck.
Also is your LinkedIn cyber security adjacent?
Better than each person doing “4.2 hours of Claude churn, 32 prompts” for each device. And of course LLMs can help personalize existing things for your use case.
I ended up vibe coding my own Android TV media player because every single other one out there has too much feature bloat and show stopping bugs. My version has exactly the features I want and (very importantly) no more.
I do lament the loss of control, but the increase in security will be objectively good for humanity as a whole.
Reverse engineering seems a good one (ev en if his RE nix sandbox looks fairly usable, it seems like a weekend to get this working.
Vendor is PetKit btw.
I'd also love for someone to RE a Google Home or Alexa to be usable with custom models and Esp home/Home Assistant.
A couple months ago I used AI to find a novel shell injection exploit and obtain root creds in the router, so I could print out the firewall configuration , init script flaws , and write up a vulnerability report. AI found the bug and wrote the patch to fix it for the vendor, without having the original code ( the bug was in shell script, thankfully).
The vendor had commented out the IPv6 firewall init, probably to pass QA , knowing consumers don’t usually use or test IPv6.
Upon getting the report, the vendor fixed the issue.
Oh, I can have this thing read and write software for me? Great, I'm going to have it read and customize the software in every single computing device I own.
It does feel magical when these agents can debug in the real-world, like turning on/off my living room lights and using another living room camera to take a snapshot of the living room to see whether it worked or not.
But it's all dressed up as terror. "I did this thing, isn't it so so so very bad?!"
I hate this framing so much. The work here is so good, and making it look scary serves to bind us closer to a world where humankind has no control no visibility to powers over the world about them, where devices are sterile fixed things. That's the bad planet.
I have proposed on HN many times that any device that is updateable have a hardware switch to disable it. Nobody agrees with me - but apparently any device that is remotely updateable is vulnerable.
And no, not a programmable switch. A hardware switch.
They used to put them on hard drives. Great, so your backup drive doesn't get accidentally overwritten. Sigh, no longer.
Claude let you do this, but if I want to debug my own Python code it refuses because "cybersecurity"?
WTF Anthropic? Is the trick not using Python?