19 comments

[ 3.3 ms ] story [ 11.8 ms ] thread
I personally think what has become cheaper is the cost of documentation. Gen AI documentation is flat and explicit, so I sometimes find it more convenient than human-written documentation, especially for APIs. (Many people criticize AI's distinctive writing style, but I don't really care about style in manuals.)

Human-written API documentation, on the other hand, tends to be inconsistent in quality

I was doing this the last few weekends with some LoRa smart home devices and a thermal shipping label printer.

Also this weekend I found out that Claude is better at writing Home Assistant automations than I am and I have been doing it for years.

what are some stuff that people are interested in reverse engineering ? ive never done it before but recently got interested after people started porting mario 64 to the playstation.
I started with Lineage 2 - RE the network protocol, building own implementation that could communicate to the server, than fighting with protected binaries (anti-VM, anti-debug). That was interesting.
Don't worry in 5 years you will have bootloader locked washing machines with crypto paired parts. That are protected under DMCA. For your own good and protection of course.
I'm currently writing a compiler (forever garage project) the speed at which Claude is able to debug with gdb what was wrongly generated is insane. I had not much prior expertise so maybe a professional in the field would be able to do it faster, but now people new to the field are able to debug at a very fast pace as well. It looks at ask code generated, understands llvm, can read and instrument gdb, all for 15$ a month
what's the deal with empty half-a-page-of-text posts lately?

is this like the ultimate form of "headline is all you need"?

I came here wanting to see after-action-report of someone actually using Ai or wtvr for reverse-engineering. Instead I got "I heard it was so. The end"

Ha. It does read like that. And Mr Willison could be forgiven since it is his blog.

Maybe he had a particular audience in mind when he wrote it. An audience for whom the mere realization would rock the foundations of their stolid and boring lives.

On the other hand, I’ve watched the movie Paycheck (2003), so my imagination has a high bar before it’s rocked by mere suggestion. Therefore, I wonder why the OP user @edward thought it was worthy of our attention.

I expected to read their excited engagement with others here, but alas no. It’s a mystery.

I've used it to help me clean up and reverse malware samples to give the person running it problems. It's very good at taking the obfuscation apart and translating it into something easier to read. I can often get it to completely vibecode string decryption functions for me so I can get what exfils they're using and the like.

Doing the same by hand can be really time consuming and difficult depending on how many obfuscation measures are layered on top.

I disagree. It's a high signal article that can create great discussions on what people on HN have reverse-engineered with AI.

For example, just yesterday I reverse engineered the internal API of a SAAS tool we use and it allowed me to gain programmatic access to data that was only available in their slow clunky UI.

it's a high signal headline

the article itself is worthless, and nobody in the comments seem to even interact with its content, you included

I suspect this article got upvoted partly for the headline & content, and partly because of who said it. Lots of people already have a good feel for the AI/journalism niche Simon Willison occupies, and can use that background knowledge to read into his words more productively.
I call this type of post on my blog a "note" - they're effectively self-hosted tweets: https://simonwillison.net/notes/

They're not really intended to be widely discussed outside of my site, it's more of a way of dropping small thoughts into my blog rather than keeping them exclusive to Twitter or Bluesky or Mastodon.

Cheap is a relative term. How many people would pay $5 to reverse engineer a device in their home?

There's no way to make a profit off reverse engineering home devices so I expect while this is likely to be one of the most groundbreaking impacts of LLMs, it won't see a ton of adoption until token costs come down.

I would love to be able to tweak or have fully customized firmware/mobile apps for all my smart devices, without risking bricking them.

Various firmware bugs that I’m sure could be fixed but aren’t, because they don’t bug the manufacturer enough? But they certainly bug me on a daily basis.

...if done correctly.

You can reverse engineer websites at a breathtaking speed if you do it correctly. PeachJam.dev took me approximately 2 months to make, for instance. If I had access to Sol from the start it would likely just take 1 month.

I’ve done this so much. My pool controller. Patio louvres. Fireplace. All these busted apps all controlled using mqtt now to talk to homeassistant for super easy control.
I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...

The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.

I'll be impressed by this trend when someone manages to replace crappy built in TV OS spyware with something more open like Android TV.