Great write-up. The biggest problem with GLM/Kimi is exactly this: they often miss obvious failure points. Claude/Codex tend to catch these kinds of issues pretty quickly. They’ll basically go, “Wait, step back,” rethink the problem for a while, and start questioning their underlying assumptions.
That’s why I always prompt GLM to explicitly map out and question all of its assumptions. It helps a lot when it gets “stuck” on a wrong line of reasoning.
utopiah 38 seconds ago [-]
Next time buy open hardware for less, e.g PineTab, donate the difference to an open-source project of your choice and don't support closed ecosystems in the first place?
sajithdilshan 11 minutes ago [-]
I wonder, in the not so distant future if we would have jailbreak for iPhones again thanks to AI. That would be glorious.
KumaBear 9 minutes ago [-]
Not if the walled garden (guard Dog) AI that’ll be living in your phone has something to say.
Shuddown 21 minutes ago [-]
So all we need to get models to hack hardened devices is the promise of fame on Hacker News.
abracadaniel 17 minutes ago [-]
It would be interesting to see someone try to tackle modern consoles like the PS5
kestrel-robotic 13 minutes ago [-]
sudo make-me-a-sandwich strikes again.
__alexander 9 minutes ago [-]
> Claude Max plan I already pay for, until its safeguards cut me off
I hate to say it but this is why security researchers are moving to Chinese models with no safeguards. I literally hit cyber safeguards in codex 5 minutes ago.
zuzululu 17 minutes ago [-]
Amazing. no humans are willing to do this type of work for under a hundred dollars like LLMs and would've taken a year or more.
I think LLMs open up a great new vector for jailbreaking old devices or firmwares that no longer get factory updates.
undersuit 11 minutes ago [-]
Humans do it for free. I've got two Amazon Fire tables from a fire sale for $15 each and used a package, that exploits the SOC, from the XDA forums to install full Android on them. Every smartphone I've had before this free Oneplus Nord N30 was rooted and then and had a custom android installed, many of the root processes relied on doing exploits all the way back to my CyanogenMod days.
zuzululu 10 minutes ago [-]
I mean finding exploits yourself on devices especially ones without much public knowledge or discussion around it.
undersuit 8 minutes ago [-]
You would search the internet. Now you ask the thing that destructively searched the internet.
mdjxjdidn 3 minutes ago [-]
and then it copies a solution from somewhere (with your expert guidance that you're discounting for some reason) and you write a blog post about how smart it is and the fake price you paid since Claude Max is still selling $200 for $1
this won't be the same story when SoftBank and Oracle go under, the compute is no longer subsidized, and the same experiment costs _literally_ $26000 based on analyst estimates of the real opex
dr_pardee 2 hours ago [-]
Author here. Quick context: the tablet is a 2021 Fire HD 10 that ran my Home Assistant dashboard and kept powering itself off: the logs showed Amazon's own software issuing the shutdowns, and the only permanent fix was root, which has never existed publicly for this model. Anthropic's and OpenAI's cyber safeguards wouldn't touch the project. Moonshot's Kimi K3 found an unpatched 2022 Mali CVE (CVE-2022-38181: fixed upstream in 2022, patched by Amazon in 2024, but my firmware never got it), GLM-5.2 caught two fatal bugs in the exploit, and GLM-5.3 finished it in a day. The full technical write-up with every offset and dead end is HANDOFF.md in the repo. Happy to answer questions: especially about the model-steering side, which was most of my actual contribution.
segmondy 2 minutes ago [-]
Thanks for sharing, pretty cool. Whenever I read these, I want to see your prompts. Not necessarily the output from the model since that would be verbose, perhaps summarized if too much. But seeing your prompt and how you steer the model would be pretty cool if you don't mind sharing. Thanks again.
zuzululu 14 minutes ago [-]
Is there another provider that can host GLM without declining you card because you tried to root our own device? I think the comparisons are obvious, its impossible to do this fully with anthropic or openai. It's very exciting what open source models make possible but also see if it gets too good, they are going to make it illegal citing natsec issues and so on.
mdp2021 3 minutes ago [-]
> they are going to make it
It is a possibility we are aware of, also given other instances of the fight of totalitarian or perverse or counterdignified drives of all colors against tools.
But the real fundamental risk I see is that of forgetting the principles of ownership, when circumventions become more possible (like in this case). For example, if cars started behaving insanely and unofficial patches will become available, that would soften the need for a principle "my car must behave seriously: my car must not have advertising modules" etc. and "I must not need to patch my car because of the manufacturer's malicious and vile practices".
Tiberium 13 minutes ago [-]
> its impossible to do this fully with anthropic or openai
It is possible, but is way more involved. You need to get cyber verification for either of them, and it's a little easier to get with OpenAI. Afterwards you can do such work.
zuzululu 10 minutes ago [-]
I'm aware but for many that might not be an option and its creepy. Say your research gets leaked or hacked. Now you are liable.
Better to opt for an open source model that can do most of the work but obviously its not going to be as good.
caminante 13 minutes ago [-]
[flagged]
scrollop 11 minutes ago [-]
Perhaps they didn't use AI to write hte title and ENglish is their ESL. Or maybe it's a mistake.
Seems mistakes cannot be made.
On another note (that I've been consdiering), perhaps, the most efficient way to get from A to B is not always the best route to take...
vlyan 8 minutes ago [-]
why did you even bother to waste time on a comment like this?
Rendered at 16:16:44 GMT+0000 (Coordinated Universal Time) with Vercel.
That’s why I always prompt GLM to explicitly map out and question all of its assumptions. It helps a lot when it gets “stuck” on a wrong line of reasoning.
I hate to say it but this is why security researchers are moving to Chinese models with no safeguards. I literally hit cyber safeguards in codex 5 minutes ago.
I think LLMs open up a great new vector for jailbreaking old devices or firmwares that no longer get factory updates.
this won't be the same story when SoftBank and Oracle go under, the compute is no longer subsidized, and the same experiment costs _literally_ $26000 based on analyst estimates of the real opex
It is a possibility we are aware of, also given other instances of the fight of totalitarian or perverse or counterdignified drives of all colors against tools.
But the real fundamental risk I see is that of forgetting the principles of ownership, when circumventions become more possible (like in this case). For example, if cars started behaving insanely and unofficial patches will become available, that would soften the need for a principle "my car must behave seriously: my car must not have advertising modules" etc. and "I must not need to patch my car because of the manufacturer's malicious and vile practices".
It is possible, but is way more involved. You need to get cyber verification for either of them, and it's a little easier to get with OpenAI. Afterwards you can do such work.
Better to opt for an open source model that can do most of the work but obviously its not going to be as good.
Seems mistakes cannot be made.
On another note (that I've been consdiering), perhaps, the most efficient way to get from A to B is not always the best route to take...