Everything I own, owned
https://web.archive.org/web/20260823225933/https://schlarp.c... Comments URL: https://news.ycombinator.com/item?id=49413320 Points: 1314 # Comments: 330
Over the past couple weeks, the author has been conducting agent-driven reverse engineering of various peripherals they have access to. From these devices, they obtained a full plaintext command shell inside their microphone, a webcam whose activity LED can be switched off while in recording mode, and a key light that grants memory writes to anyone on the WiFi network.
Peripherals were found to be excellent targets for agent-reverse engineering due to their small computer nature and data connection to the host, as well as firmware update mechanisms.
The author's process involved obtaining the device's firmware and associated update tool from the manufacturer, then using a reverse engineering environment, specifying goals to Claude Opus 5, and allowing it to work. Goals varied per device but generally aimed to gain better control and understanding of the machine. The author then discussed each device and the results obtained:
1. Insta360 Link webcam: The author discovered that the activity LED could be subverted to prevent alerts, despite the camera running a ThreadX RTOS with vision models for face tracking and gesture detection. By using USB's mass storage mode, arbitrary read/write, and reboot commands, the author was able to fully flash the device without user interaction. The activity LED was successfully disabled by patching the firmware.
2. ASUS ROG Swift PG42UQ monitor: The author began with this monitor, annoyed by the pixel cleaning overlay that appeared occasionally. Claude found that the firmware had minimal protection and allowed for arbitrary write access. By patching the firmware, the author successfully disabled the pixel cleaning warning. Claude also explored the DDC/CI interface, allowing the author to control monitor settings via a shell script.
3. Shure MV7 microphone: Finally, the author examined this microphone, which connects over USB and contains on-device digital volume controls. The firmware was found within the Windows software MOTIV Mix, but Claude was able to obtain it using Wine on Linux. The firmware contained both DSP and MCU components, but did not offer much in the way of interesting attack surfaces.
Written by urgent.news from Hacker News Best's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Everything I own, owned schlarp.com