Reverse-engineering is cheap now(simonwillison.net)
simonwillison.net
Reverse-engineering is cheap now
https://simonwillison.net/2026/Jul/20/cheap-reverse-engineering/
41 comments
I call this type of post on my blog a "note" - they're effectively self-hosted tweets: https://simonwillison.net/notes/
They're not really intended to be widely discussed outside of my site, it's more of a way of dropping small thoughts into my blog rather than keeping them exclusive to Twitter or Bluesky or Mastodon.
They're not really intended to be widely discussed outside of my site, it's more of a way of dropping small thoughts into my blog rather than keeping them exclusive to Twitter or Bluesky or Mastodon.
Ha. It does read like that. And Mr Willison could be forgiven since it is his blog.
Maybe he had a particular audience in mind when he wrote it. An audience for whom the mere realization would rock the foundations of their stolid and boring lives.
On the other hand, I’ve watched the movie Paycheck (2003), so my imagination has a high bar before it’s rocked by mere suggestion. Therefore, I wonder why the OP user @edward thought it was worthy of our attention.
I expected to read their excited engagement with others here, but alas no. It’s a mystery.
Maybe he had a particular audience in mind when he wrote it. An audience for whom the mere realization would rock the foundations of their stolid and boring lives.
On the other hand, I’ve watched the movie Paycheck (2003), so my imagination has a high bar before it’s rocked by mere suggestion. Therefore, I wonder why the OP user @edward thought it was worthy of our attention.
I expected to read their excited engagement with others here, but alas no. It’s a mystery.
I've used it to help me clean up and reverse malware samples to give the person running it problems. It's very good at taking the obfuscation apart and translating it into something easier to read. I can often get it to completely vibecode string decryption functions for me so I can get what exfils they're using and the like.
Doing the same by hand can be really time consuming and difficult depending on how many obfuscation measures are layered on top.
Doing the same by hand can be really time consuming and difficult depending on how many obfuscation measures are layered on top.
I disagree. It's a high signal article that can create great discussions on what people on HN have reverse-engineered with AI.
For example, just yesterday I reverse engineered the internal API of a SAAS tool we use and it allowed me to gain programmatic access to data that was only available in their slow clunky UI.
For example, just yesterday I reverse engineered the internal API of a SAAS tool we use and it allowed me to gain programmatic access to data that was only available in their slow clunky UI.
it's a high signal headline
the article itself is worthless, and nobody in the comments seem to even interact with its content, you included
the article itself is worthless, and nobody in the comments seem to even interact with its content, you included
I suspect this article got upvoted partly for the headline & content, and partly because of who said it. Lots of people already have a good feel for the AI/journalism niche Simon Willison occupies, and can use that background knowledge to read into his words more productively.
I would love to be able to tweak or have fully customized firmware/mobile apps for all my smart devices, without risking bricking them.
Various firmware bugs that I’m sure could be fixed but aren’t, because they don’t bug the manufacturer enough? But they certainly bug me on a daily basis.
Various firmware bugs that I’m sure could be fixed but aren’t, because they don’t bug the manufacturer enough? But they certainly bug me on a daily basis.
I was doing this the last few weekends with some LoRa smart home devices and a thermal shipping label printer.
Also this weekend I found out that Claude is better at writing Home Assistant automations than I am and I have been doing it for years.
Also this weekend I found out that Claude is better at writing Home Assistant automations than I am and I have been doing it for years.
I personally think what has become cheaper is the cost of documentation. Gen AI documentation is flat and explicit, so I sometimes find it more convenient than human-written documentation, especially for APIs. (Many people criticize AI's distinctive writing style, but I don't really care about style in manuals.)
Human-written API documentation, on the other hand, tends to be inconsistent in quality
Human-written API documentation, on the other hand, tends to be inconsistent in quality
This is part of it but the models are REALLY good at reverse engineering. With the Bluetooth printer I was trying to get to work without a vendor app, it built a python app to handle protocol encode/decode and poking the device, and it reversed the driver provided by the vendor to figure out how the vendor was using the device, and so forth. Wi to the LoRa devices we set up an SDR to intercept the signal, did scanning until we found the device, but ultimately failed because we didn’t know the signal hopping algorithm. I have also reversed a Bluetooth peripheral with Claude to figure out how the vendor was setting the device settings, and was able to get the device to work without the vendor software. That was wild- Apple Developer has a profile you can download and install that will give you monitor access to the Bluetooth stack; it was amazing.
So I use AI for exactly what Simon’s post discusses, and am thrilled to be able to rid myself of crap software written by device vendors, and make the devices work without my stuff.
So I use AI for exactly what Simon’s post discusses, and am thrilled to be able to rid myself of crap software written by device vendors, and make the devices work without my stuff.
Everything human made is inconsistent. I can tell just from an error in schematic which of my former colleagues created that schematic. Everyone of them had training on the job and have thrir signature errors. That’s why automation is crucial for quality control.
Hardware SDKs and API manuals are terrible. Personally, I found the camera ones (e.g., Canon) especially bad.
Cheaper to write definitely, no so much cheaper to read. AI generated docs tend to be so annoyingly verbose if not reined in during prompting.
But well, any documentation is good when a human would've written zero docs
But well, any documentation is good when a human would've written zero docs
Rather than that, the quality of human-written documentation is just too inconsistent. Because it's not written by a single person.
AI's verbosity is definitely a problem, but I think it's something you can just check once more. Of course, opinions vary.
AI's verbosity is definitely a problem, but I think it's something you can just check once more. Of course, opinions vary.
I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...
The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.
The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.
Cheap is a relative term. How many people would pay $5 to reverse engineer a device in their home?
There's no way to make a profit off reverse engineering home devices so I expect while this is likely to be one of the most groundbreaking impacts of LLMs, it won't see a ton of adoption until token costs come down.
There's no way to make a profit off reverse engineering home devices so I expect while this is likely to be one of the most groundbreaking impacts of LLMs, it won't see a ton of adoption until token costs come down.
Sounds like a businesses opportunity to do it at scale!
Send $20 pi zero that will reflash expensive camera, that is out of support. Or do mail business, with reflashing devices.
There are billions out of support devices, and rework is great industry in China. In US you sadly hit legal BS if doing it commercially...
Send $20 pi zero that will reflash expensive camera, that is out of support. Or do mail business, with reflashing devices.
There are billions out of support devices, and rework is great industry in China. In US you sadly hit legal BS if doing it commercially...
I think its more a case of, when/if this kind of LLM can be run on a normal desktop then it'll become a big deal. But its also not the kind of work thats economically transformative at all
Don't worry in 5 years you will have bootloader locked washing machines with crypto paired parts. That are protected under DMCA. For your own good and protection of course.
You're joking but I can't wait honestly. The hypocrisy will only become more and more obvious and unbearable to accept for literally everybody. When we'll reach that point, I believe we will look for healthier solutions.
I am not joking in slightest. Our only hope is to be able to create open boards for appliances and just drop in replace them.
I'll be impressed by this trend when someone manages to replace crappy built in TV OS spyware with something more open like Android TV.
I'm currently writing a compiler (forever garage project) the speed at which Claude is able to debug with gdb what was wrongly generated is insane. I had not much prior expertise so maybe a professional in the field would be able to do it faster, but now people new to the field are able to debug at a very fast pace as well. It looks at ask code generated, understands llvm, can read and instrument gdb, all for 15$ a month
what are some stuff that people are interested in reverse engineering ? ive never done it before but recently got interested after people started porting mario 64 to the playstation.
> what are some stuff that people are interested in reverse engineering ?
Software license/key verification. Sometimes it’s as easy as replacing a “JNE” with a “JE”, or replacing “JMP”, or even just “NOP” some “CMP” operation. It’s a fun challenge, at least for people who enjoy solving puzzles.
Software license/key verification. Sometimes it’s as easy as replacing a “JNE” with a “JE”, or replacing “JMP”, or even just “NOP” some “CMP” operation. It’s a fun challenge, at least for people who enjoy solving puzzles.
yeah i remember those days warez, crackers, keygen using regedit to try bypass trials thats a pretty neat use case i hadn't thought of
I started with Lineage 2 - RE the network protocol, building own implementation that could communicate to the server, than fighting with protected binaries (anti-VM, anti-debug). That was interesting.
anything that has a 'not very good' app you are forced to use, everything that imposes 'licensing' limit on hardware you own.
e.g. why do I need V380 app to configure and watch the feed of my IP Camera.
e.g. why do I need V380 app to configure and watch the feed of my IP Camera.
i think this is genuinely something i will do. so many products from china come with these really sketchy software looks like it was made in the 90s
Various devices that I don't want to install the official software or drivers to control. I've done this with several things, but just as an example I have a MIDI MPC pad (the sort of thing samplers/beat makers use) and worked out it had various features not supported officially like controlling the lights on the pads. I also discovered some cheap Chinese lights my daughter owns are controllable over BLE without encryption.
One thing that I tried was porting an old and obscure 32-bit VST plugin from PowerPC to modern architectures
OBD vehicle diagnostic software.
thats a good one. even better if ya open source it ;)
FreeSSM is already open source. It's reversed Subaru SSM diagnostic protocol and wrapped a tool around it. That was ~15 years ago, long before any of the AI stuff.
The point was rather that reverse engineering the CAN-bus protocol or existing software that already does it for your vehicle of interest is now by far easier through the usage of AI models than it was before - FWIW I could have done it before with the technical skills I have but ROI for me personally was too low. Now I am really considering it.
Oh, yeah. Agree with that point.
...if done correctly.
You can reverse engineer websites at a breathtaking speed if you do it correctly. PeachJam.dev took me approximately 2 months to make, for instance. If I had access to Sol from the start it would likely just take 1 month.
You can reverse engineer websites at a breathtaking speed if you do it correctly. PeachJam.dev took me approximately 2 months to make, for instance. If I had access to Sol from the start it would likely just take 1 month.
I’ve done this so much. My pool controller. Patio louvres. Fireplace. All these busted apps all controlled using mqtt now to talk to homeassistant for super easy control.
is this like the ultimate form of "headline is all you need"?
I came here wanting to see after-action-report of someone actually using Ai or wtvr for reverse-engineering. Instead I got "I heard it was so. The end"