Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. I'm Upping My P(Doom) [video] (youtube.com)
    —discuss
  2. A-Mem: Agentic Memory for LLM Agents (arxiv.org)
    —discuss
  3. Ask HN: Finding Communities as an Introvert
    —discuss
  4. 'Things Will Never Be Chill Again':The Doomers Who Shaped the AI Safety Freakout (wsj.com)
    —discuss
  5. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    —discuss
  6. How to Browse and Edit Redis Safely Without `Keys *` (visualeaf.com)
    —discuss
  7. AI can destroy humanity – an illustrated guide (thomasunise.com)
    —discuss
  8. Google, OpenAI and Anthropic plan AI safety body, The Information reports (thenextweb.com)
    —discuss
  9. Cutting LLM tokens on big spreadsheets (kushniarou.com)
    —discuss
  10. Crown 0.65 (crownengine.org)
    —discuss
  11. I made a digital back for the Mamiya Press (medium format CCD) (youtube.com)
    —discuss
  12. Unions Video Game Workers at Blizzard Won First Union Contracts (jacobin.com)
    —discuss
  13. Enter Cybercab (austinvernon.site)
    —discuss
  14. Show HN: OpenAPPA – deterministic AI guardrails that don't break agents (openappa.com)
    4comments
  15. Kafka for .NET developers Part 1 [video] (youtube.com)
    —discuss
  16. Think of Motivation as Something You Earn (justinmath.com)
    —discuss
  17. Show HN: I turned my team's coding-agent history into a knowledge graph (github.com/motif-labs)
    —discuss
  18. Argentina's monthly inflation went from 25.5% in Milei's first month to 1.7% (twitter.com/rothmus)
    1comments
  19. How to find your perfect pillow – according to an expert (bbc.co.uk)
    —discuss
  20. Kleptoparasitism (Food Stealing) in Cetaceans (smithsonianmag.com)
    —discuss
  21. EmDash 1.0: an open source CMS for Astro (emdashcms.com)
    —discuss
  22. EmDash 1.0: the stable CMS with a secure plugin registry (cloudflare.com)
    —discuss
  23. Illusory Dunning-Kruger Effect and Reciprocal Fits (jslandy.com)
    —discuss
  24. Postgres – Don't Do This (postgresql.org)
    —discuss
  25. Show HN: Jevpipe – a fast System 1 for AI agents, as a Unix pipe (github.com/fabianboth)
    2comments
  26. simdjson 5.0.0 (github.com/simdjson)
    —discuss
  27. Ozone will warm planet more than first thought (reading.ac.uk)
    1comments
  28. Native Rust on Cloudflare Workers via Emscripten (cloudflare.com)
    —discuss
  29. Proton Mail confirmed and paid a bounty for a spoofing bug, then left it unfixed (github.com/alonsovidales)
    —discuss
  30. Forge: The open source pipeline for generating SDKs, CLIs, docs, and more (cloudflare.com)
    —discuss

Show HN: I emulated Roborock's cloud so my vacuum works without internet

1 pointsby 43m agogithub.com
0 comments
Hi! I maintain the python-roborock library and the Roborock integration in Home Assistant.

Roborock vacuums use a local protocol for direct commands, but they still route all map data strictly through the cloud (even though the map is stored locally). Even worse, if you try to block the vacuum from accessing the internet on your router, it will constantly reboot its Wi-Fi connection trying to re-establish a cloud connection, meaning you can't rely on just using a private local connection.

I built a self-hostable version of Roborock's cloud: https://github.com/Python-roborock/local_roborock_server

It works without having to open the device or root it, taking advantage of a couple of quirks during the onboarding process:

1) The vacuum has api-%s.roborock.com baked into its firmware. It injects the region directly into the string and this is the first exploit we take advantage of. The app will send in your region as a two letter code, e.g. 'us', 'eu', 'cn'. We send in a full URL ending with a '/' (e.g. 'example.com/'). The vacuum then treats "api-example.com" as the host and the rest as the URL path(e.g. 'api-example.com/.roborock.com'), directing its traffic to your server so long as there is a valid HTTPS certificate on that domain.

2) The second part of the handshake requires encrypting a message via a public key that is stored on Roborock's cloud where the private key pair is on the vacuum. We are able to reverse engineer the public key as the robot sends signatures with its message. Because of how RSA works, each signature is mathematically tied to the secret public key plus some extra noise. By gathering a few signatures across multiple onboarding attempts and taking their greatest common divisor, the noise cancels out and cleanly isolates the vacuum's actual public key which allows the server to encrypt its response and complete the pairing.

I have a full technical write up here: https://python-roborock.github.io/local_roborock_server/tech...

I wanted to share this on HN as I think this points to a very interesting thing that is happening. I have been playing with this idea for years in my head and I have not been able to get it to work (and I am not the only one who had looked into the api-%s avenue). I'm not a cryptography expert and had no idea that the signature exploit was even possible. I was stuck for long enough that I decided to throw the problem at some long-running agents, and they found the greatest common divisor exploit.

IoT companies put most of their security effort into the cloud, since that's what they actually run. The vacuum is just one device on someone's home network, so it gets less attention and corners get cut. I think LLMs that are willing to throw themselves at a problem for hours are going to make stuff like this a lot easier to pull off and a lot more common.

A quiet thread, for now.Start the conversation on HN ↗