Top
Best
New

Posted by dr_pardee 11 hours ago

I spent $266 and four AI models to own my tablet. GLM-5.3 finished it in a day(ericpardee.github.io)
612 points | 266 commentspage 6
baist0 7 hours ago|
He ate shit twice: when he bought an Amazon product and when he spent money to fix it.
fn-mote 7 hours ago|
He’s on the front page of HN so I’d say he got his money’s worth.
rzzzt 6 hours ago||
Being on front page pays?
cobar 6 hours ago||
Front page of Hacker News seems like a good bucket list item. And not a bad thing to have on your resume either.
kmeisthax 9 hours ago||
> Is it legal? In the US, yes: the Librarian of Congress’s 2024 DMCA exemptions (in effect through October 2027, next rulemaking already underway) cover rooting tablets you own to remove unwanted software. My device, my risk, my API bill. Nobody else’s hardware was ever touched.

For you, yes, prompt kiddie rooting your own device is legal. In fact, it's one of the only things I actually want AI to do, because breaking DRM is a bullshit job[0] and shouldn't exist. AI deals in bullshit, so it's very poetic to use AI to destroy its own bullshit. However, from the point of view of the model provider, there are very specific legal risks to letting someone vibe code their own jailbreaks, especially if a model is already cloud-hosted and heavily regulated. Allowing hacking on your own devices could be construed as trafficking in circumvention tools, so offering that capability to randos opens Anthropic up to another billion-dollar lawsuit.

I could see this being another thing that gets put behind Trusted Access programs. Corellium was able to get away with offering cloud-hosted virtual iOS devices, using an OS they don't own, because DMCA 1201 has an explicit carveout for security research. But "make my device stop doing this thing I don't want" isn't security research, so a lot of prompt kiddie jailbreak uses become legally fraught again.

[0] In the same Graeberian sense that all military officials are staffing bullshit jobs - it is a job that exists solely to undo some other job.

root_axis 9 hours ago||
Ok, now try it with an iPad
dr_pardee 11 hours ago||
Author here. Quick context: the tablet is a 2021 Fire HD 10 that ran my Home Assistant dashboard and kept powering itself off: the logs showed Amazon's own software issuing the shutdowns, and the only permanent fix was root, which has never existed publicly for this model. Anthropic's and OpenAI's cyber safeguards wouldn't touch the project. Moonshot's Kimi K3 found an unpatched 2022 Mali CVE (CVE-2022-38181: fixed upstream in 2022, patched by Amazon in 2024, but my firmware never got it), GLM-5.2 caught two fatal bugs in the exploit, and GLM-5.3 finished it in a day. The full technical write-up with every offset and dead end is HANDOFF.md in the repo. Happy to answer questions: especially about the model-steering side, which was most of my actual contribution.
segmondy 9 hours ago||
Thanks for sharing, pretty cool. Whenever I read these, I want to see your prompts. Not necessarily the output from the model since that would be verbose, perhaps summarized if too much. But seeing your prompt and how you steer the model would be pretty cool if you don't mind sharing. Thanks again.
terrut 9 hours ago|||
This is very inspiring. I have the old Kindle Keyboard that was recently discontinued. There are trivial workarounds and existing alternative OSes to get new books on it already, but it might be fun to ask Deepseek if it can help me make something bespoke.
segmondy 7 hours ago|||
I wonder if you started with GLM5.3, how fast and cheap would it have been? Or did it really need the combo of K3 and GLM5.3
voicedYoda 9 hours ago|||
Thank you for sharing this story.

By chance, would you mind sharing your prompts?

zuzululu 9 hours ago|||
Is there another provider that can host GLM without declining you card because you tried to root our own device? I think the comparisons are obvious, its impossible to do this fully with anthropic or openai. It's very exciting what open source models make possible but also see if it gets too good, they are going to make it illegal citing natsec issues and so on.
Tiberium 9 hours ago|||
> its impossible to do this fully with anthropic or openai

It is possible, but is way more involved. You need to get cyber verification for either of them, and it's a little easier to get with OpenAI. Afterwards you can do such work.

anomalousblob 8 hours ago|||
It might be possible to do it fully, but you sure will lose a lot of time hand holding Claude to make it believe it's not doing anything too nefarious.

I have valid cyber verification with Claude (they approved it super fast, in ~2 hours after applying)

It still blocks and stops pretty much all the time because of rail guards. Specially since the release of Opus 5. I do believe when Anthropic asks during the verification process "what will you use this for", that they somehow use that info during the chat to decide whether to block or not the request.

So you might be able to do one thing in cyber, but not another one. I seem to be able to research and reverse binaries with Claude, most of the time, and if I phrase my questions in certain ways. However, any kind of code developing that could be tangentially related to malware is blocked, for me.

I am seriously considering switching to GLM or another Chinese vendor, even after being cyber verified on Claude. The routine blocks I face on the tasks that I applied to the program (reverse engineering, exploit dev) are enough to make me think its better to move ship.

zuzululu 9 hours ago|||
I'm aware but for many that might not be an option and its creepy. Say your research gets leaked or hacked. Now you are liable.

Better to opt for an open source model that can do most of the work but obviously its not going to be as good.

mdp2021 9 hours ago||||
> they are going to make it

It is a possibility we are aware of, also given other instances of the fight of totalitarian or perverse or counterdignified drives of all colors against tools.

But the real fundamental risk I see is that of forgetting the principles of ownership, when circumventions become more possible (like in this case). For example, if cars started behaving insanely and unofficial patches will become available, that would soften the need for a principle "my car must behave seriously: my car must not have advertising modules" etc. and "I must not need to patch my car because of the manufacturer's malicious and vile practices".

vlyan 9 hours ago|||
>if it gets too good, they are going to make it illegal citing natsec issues and so on.

would be amusing to watch it happen while the second coming of the austrian painter is still in power. the media who fearmongered with sci-fi skynet tropes for the past 3 years will have no choice but to condemn the move.

fwip 6 hours ago||
If your Kindle was plugged in the whole time (as you might with a HA dash), my guess would be the shutdowns are battery related, to avoid degradation or possible fire. Consider removing the battery if you haven't already.
luciana1u 8 hours ago||
[dead]
sebstefan 5 hours ago||
[dead]
caminante 9 hours ago||
[flagged]
scrollop 9 hours ago||
Perhaps they didn't use AI to write hte title and ENglish is their ESL. Or maybe it's a mistake.

Seems mistakes cannot be made.

On another note (that I've been consdiering), perhaps, the most efficient way to get from A to B is not always the best route to take...

vlyan 9 hours ago||
why did you even bother to waste time on a comment like this?
axiomcle 7 hours ago||
[flagged]
linkregister 7 hours ago|
There's no prohibition on submitting LLM-written articles. There is a rule against machine-written comments.