Reverse-engineering is cheap now
37 points by edward 18 hours ago | 35 comments
  • jdw64 18 hours ago |
    I personally think what has become cheaper is the cost of documentation. Gen AI documentation is flat and explicit, so I sometimes find it more convenient than human-written documentation, especially for APIs. (Many people criticize AI's distinctive writing style, but I don't really care about style in manuals.)

    Human-written API documentation, on the other hand, tends to be inconsistent in quality

    • lnsru 18 hours ago |
      Everything human made is inconsistent. I can tell just from an error in schematic which of my former colleagues created that schematic. Everyone of them had training on the job and have thrir signature errors. That’s why automation is crucial for quality control.
      • jdw64 17 hours ago |
        Hardware SDKs and API manuals are terrible. Personally, I found the camera ones (e.g., Canon) especially bad.
    • efitz 17 hours ago |
      This is part of it but the models are REALLY good at reverse engineering. With the Bluetooth printer I was trying to get to work without a vendor app, it built a python app to handle protocol encode/decode and poking the device, and it reversed the driver provided by the vendor to figure out how the vendor was using the device, and so forth. Wi to the LoRa devices we set up an SDR to intercept the signal, did scanning until we found the device, but ultimately failed because we didn’t know the signal hopping algorithm. I have also reversed a Bluetooth peripheral with Claude to figure out how the vendor was setting the device settings, and was able to get the device to work without the vendor software. That was wild- Apple Developer has a profile you can download and install that will give you monitor access to the Bluetooth stack; it was amazing.

      So I use AI for exactly what Simon’s post discusses, and am thrilled to be able to rid myself of crap software written by device vendors, and make the devices work without my stuff.

    • mvATM99 17 hours ago |
      Cheaper to write definitely, no so much cheaper to read. AI generated docs tend to be so annoyingly verbose if not reined in during prompting.

      But well, any documentation is good when a human would've written zero docs

      • jdw64 17 hours ago |
        Rather than that, the quality of human-written documentation is just too inconsistent. Because it's not written by a single person.

        AI's verbosity is definitely a problem, but I think it's something you can just check once more. Of course, opinions vary.

  • efitz 18 hours ago |
    I was doing this the last few weekends with some LoRa smart home devices and a thermal shipping label printer.

    Also this weekend I found out that Claude is better at writing Home Assistant automations than I am and I have been doing it for years.

    • memjay 17 hours ago |
      Do you give Claude access to HA somehow? Or how does it get the relevant device names/ids?
      • efitz 11 hours ago |
        Yes, using the API - I gave it an API key in an environment variable.
  • zuzululu 18 hours ago |
    what are some stuff that people are interested in reverse engineering ? ive never done it before but recently got interested after people started porting mario 64 to the playstation.
    • guessmyname 17 hours ago |
      > what are some stuff that people are interested in reverse engineering ?

      Software license/key verification. Sometimes it’s as easy as replacing a “JNE” with a “JE”, or replacing “JMP”, or even just “NOP” some “CMP” operation. It’s a fun challenge, at least for people who enjoy solving puzzles.

      • zuzululu 16 hours ago |
        yeah i remember those days warez, crackers, keygen using regedit to try bypass trials thats a pretty neat use case i hadn't thought of
    • menaerus 17 hours ago |
      OBD vehicle diagnostic software.
      • zuzululu 16 hours ago |
        thats a good one. even better if ya open source it ;)
    • homarp 17 hours ago |
      anything that has a 'not very good' app you are forced to use, everything that imposes 'licensing' limit on hardware you own.

      e.g. why do I need V380 app to configure and watch the feed of my IP Camera.

      • zuzululu 16 hours ago |
        i think this is genuinely something i will do. so many products from china come with these really sketchy software looks like it was made in the 90s
    • mutkach 17 hours ago |
      One thing that I tried was porting an old and obscure 32-bit VST plugin from PowerPC to modern architectures
    • petercooper 15 hours ago |
      Various devices that I don't want to install the official software or drivers to control. I've done this with several things, but just as an example I have a MIDI MPC pad (the sort of thing samplers/beat makers use) and worked out it had various features not supported officially like controlling the lights on the pads. I also discovered some cheap Chinese lights my daughter owns are controllable over BLE without encryption.
  • ReptileMan 17 hours ago |
    Don't worry in 5 years you will have bootloader locked washing machines with crypto paired parts. That are protected under DMCA. For your own good and protection of course.
    • w4yai 17 hours ago |
      You're joking but I can't wait honestly. The hypocrisy will only become more and more obvious and unbearable to accept for literally everybody. When we'll reach that point, I believe we will look for healthier solutions.
      • ReptileMan 17 hours ago |
        I am not joking in slightest. Our only hope is to be able to create open boards for appliances and just drop in replace them.
  • txdv 17 hours ago |
    I'm currently writing a compiler (forever garage project) the speed at which Claude is able to debug with gdb what was wrongly generated is insane. I had not much prior expertise so maybe a professional in the field would be able to do it faster, but now people new to the field are able to debug at a very fast pace as well. It looks at ask code generated, understands llvm, can read and instrument gdb, all for 15$ a month
  • NooneAtAll3 17 hours ago |
    what's the deal with empty half-a-page-of-text posts lately?

    is this like the ultimate form of "headline is all you need"?

    I came here wanting to see after-action-report of someone actually using Ai or wtvr for reverse-engineering. Instead I got "I heard it was so. The end"

    • xtiansimon 12 hours ago |
      Ha. It does read like that. And Mr Willison could be forgiven since it is his blog.

      Maybe he had a particular audience in mind when he wrote it. An audience for whom the mere realization would rock the foundations of their stolid and boring lives.

      On the other hand, I’ve watched the movie Paycheck (2003), so my imagination has a high bar before it’s rocked by mere suggestion. Therefore, I wonder why the OP user @edward thought it was worthy of our attention.

      I expected to read their excited engagement with others here, but alas no. It’s a mystery.

    • techjamie 10 hours ago |
      I've used it to help me clean up and reverse malware samples to give the person running it problems. It's very good at taking the obfuscation apart and translating it into something easier to read. I can often get it to completely vibecode string decryption functions for me so I can get what exfils they're using and the like.

      Doing the same by hand can be really time consuming and difficult depending on how many obfuscation measures are layered on top.

    • alun 8 hours ago |
      I disagree. It's a high signal article that can create great discussions on what people on HN have reverse-engineered with AI.

      For example, just yesterday I reverse engineered the internal API of a SAAS tool we use and it allowed me to gain programmatic access to data that was only available in their slow clunky UI.

    • staticshock 7 hours ago |
      I suspect this article got upvoted partly for the headline & content, and partly because of who said it. Lots of people already have a good feel for the AI/journalism niche Simon Willison occupies, and can use that background knowledge to read into his words more productively.
  • xyzsparetimexyz 17 hours ago |
    Cheap is a relative term. How many people would pay $5 to reverse engineer a device in their home?

    There's no way to make a profit off reverse engineering home devices so I expect while this is likely to be one of the most groundbreaking impacts of LLMs, it won't see a ton of adoption until token costs come down.

    • throw738388 16 hours ago |
      Sounds like a businesses opportunity to do it at scale!

      Send $20 pi zero that will reflash expensive camera, that is out of support. Or do mail business, with reflashing devices.

      There are billions out of support devices, and rework is great industry in China. In US you sadly hit legal BS if doing it commercially...

      • xyzsparetimexyz 12 hours ago |
        I think its more a case of, when/if this kind of LLM can be run on a normal desktop then it'll become a big deal. But its also not the kind of work thats economically transformative at all
  • vanity0 17 hours ago |
    I would love to be able to tweak or have fully customized firmware/mobile apps for all my smart devices, without risking bricking them.

    Various firmware bugs that I’m sure could be fixed but aren’t, because they don’t bug the manufacturer enough? But they certainly bug me on a daily basis.

  • tornikeo 17 hours ago |
    ...if done correctly.

    You can reverse engineer websites at a breathtaking speed if you do it correctly. PeachJam.dev took me approximately 2 months to make, for instance. If I had access to Sol from the start it would likely just take 1 month.

  • rmm 17 hours ago |
    I’ve done this so much. My pool controller. Patio louvres. Fireplace. All these busted apps all controlled using mqtt now to talk to homeassistant for super easy control.
  • captn3m0 17 hours ago |
    I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...

    The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.

  • xnx 15 hours ago |
    I'll be impressed by this trend when someone manages to replace crappy built in TV OS spyware with something more open like Android TV.