frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

https://www.evilsocket.net/2025/12/18/TP-Link-Tapo-C200-Hardcoded-Keys-Buffer-Overflows-and-Privacy-in-the-Era-of-AI-Assisted-Reverse-Engineering/
87•sibellavia•1h ago

Comments

JaggedJax•30m ago
It's probably fair to assume that most of their other camera models are affected by the same or similar issues. It looks like they pump out quite a few models that I image have similar firmware.

This page[1] lists the C200 as last having a firmware update in October, but also lists the latest version as 1.4.4 while the article lists 1.4.2. It seems like they have pushed other updated in this time, but not these security fixes.

[1]https://community.tp-link.com/us/smart-home/kb/detail/412852

aaronax•26m ago
This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities? There must be many millions sold. Quite handy for some intel agencies.

I assume any Wi-Fi camera under $150 has basically the same problems. I guess the only way to run a security camera where you don't have Ethernet is to use a non-proprietary Wi-Fi <-> 1000BASE-T adapter. Probably only something homebuilt based on a single board computer and running basically stock Linux/BSD meets that requirement.

mlaretallack•25m ago
Very interesting, I had a go with Ghidra and AWS Amazon Q, used it to reverse the video feed on a toy drone. I did not think to look for GhidraMCP, would of made it a lot quicker.
shreddit•21m ago
As soon as i read the author used grok as an ai assistant, i was somehow less interested to keep on reading. Not because of the usage of ai, but the chosen provider. (I don’t know whether grok is just the best choice for this kind of work.)

Is it wrong to judge people for their choice of ai providers?

walterbell•17m ago
Which AI providers have access to real-time Twitter data?
sva_•13m ago
I think when your political views cloud your ability to take in information on an objective level, it might be bad.
wh0thenn0w•12m ago
You can just not like Elon, doesn't have to be political at all.
scotty79•9m ago
It's worth interacting with all models. In my experience, for programming questions grok delivered better answers than ChatGPT (and Claude) often enough that at some point I wasn't sure which model I should be asking first.

Gh-nvim-username-keywords: GitHub -mention Autocomplete in Your Neovim Editor

https://www.joshbeckman.org/blog/practicing/ghnvimusernamekeywords-github-mention-autocomplete-in...
1•bckmn•54s ago•0 comments

Using Pong as a stress test for compiler development

https://www.reddit.com/r/Compilers/s/ld2dR4LnFh
1•azhenley•1m ago•0 comments

Meta is testing a feature that makes you review accounts before following them

https://pbs.twimg.com/media/G8jnJOEWoAAOSB6?format=jpg&name=large
1•3Samourai•3m ago•0 comments

Microsoft made another Copilot ad where nothing works

https://www.theverge.com/report/847056/microsoft-copilot-ai-vision-pc-assistant-christmas-holiday-ad
1•Topfi•4m ago•0 comments

The post-GeForce era: What if Nvidia abandons PC gaming?

https://www.pcworld.com/article/3013044/the-post-geforce-era-what-if-nvidia-abandons-pc-gaming.html
1•pyprism•5m ago•0 comments

Mapping China's Surnames

https://www.andrewstokols.com/blog/460
1•fzliu•7m ago•0 comments

Show HN: Taupy – fast Python desktop apps without Electron

https://github.com/S1avv/taupy
2•s1jor•7m ago•0 comments

Chrome AI Playback: Deligtful, Wild and Disconcerting

https://blog.certisfy.com/2025/12/chrome-ai-playback-deligtful-wild-and.html
1•Edmond•8m ago•0 comments

More is different (1972) [pdf]

https://www.tkm.kit.edu/downloads/TKM1_2011_more_is_different_PWA.pdf
1•andsoitis•9m ago•0 comments

Show HN: Free Spelling Test Generator

https://minform.io/tools/spelling-test-generator
1•eashish93•10m ago•0 comments

Robotics Levels of Autonomy

https://newsletter.semianalysis.com/p/robotics-levels-of-autonomy
1•nowflux•11m ago•0 comments

NetBox 4.5 Beta

https://netboxlabs.com/blog/announcing-the-netbox-4-5-beta/
1•mrmrcoleman•11m ago•0 comments

Show HN: Stickerbox, a kid-safe, AI-powered voice to sticker printer

https://stickerbox.com/
2•spydertennis•14m ago•0 comments

Astrophotography Target Planner: Discover Hidden Nebulas

https://astroimagery.com/techniques/imaging/astrophotography-target-planner/
1•kianN•14m ago•0 comments

Ken MacLeod on the life and work of the late sc-fi legend Iain M. Banks [video]

https://www.youtube.com/watch?v=r7OW6A8XCgg
3•petethomas•18m ago•0 comments

AI's Unpaid Debt: How LLM Scrapers Destroy the Social Contract of Open Source

https://www.quippd.com/writing/2025/12/17/AIs-unpaid-debt-how-llm-scrapers-destroy-the-social-con...
3•birdculture•21m ago•0 comments

React Server Components Explorer

https://overreacted.io/introducing-rsc-explorer/
1•elierotenberg•23m ago•0 comments

Adobe Photoshop Source Code (2013)

https://computerhistory.org/blog/adobe-photoshop-source-code/
1•rbanffy•25m ago•0 comments

Something Big Happened in 1998

https://openpath.quest/2025/something-big-happened-in-1998/
2•coloneltcb•26m ago•0 comments

An Existential Guide To: Making Friends

https://theshadowedarchive.substack.com/p/an-existential-guide-to-making-friends
1•FigurativeVoid•26m ago•0 comments

How PyTorch Generates Random Numbers in Parallel on the GPU

https://blog.codingconfessions.com/p/how-pytorch-generates-random-numbers
1•rbanffy•27m ago•0 comments

When Were Things the Best?

https://thezvi.wordpress.com/2025/12/19/when-were-things-the-best/
1•speckx•30m ago•0 comments

Fine-Tuning Is (Probably) a Trap

https://bits.logic.inc/p/fine-tuning-is-probably-a-trap
3•sgk284•31m ago•0 comments

Pi 5 NAS with Custom Carbon Fibre Panels, Made on the Makera Z1

https://www.the-diy-life.com/pi-5-nas-with-custom-carbon-fibre-panels-made-on-the-makera-z1/
1•todsacerdoti•31m ago•0 comments

Verizon refused to unlock man's iPhone, so he sued the carrier and won

https://arstechnica.com/tech-policy/2025/12/verizon-refused-to-unlock-mans-iphone-so-he-sued-the-...
3•bwoah•31m ago•0 comments

MotionGen

https://motiongen.io/
1•cristoperb•32m ago•0 comments

Show HN: Oiiaioiiiai Generator

https://oiiaoiia.app/
2•minx11•33m ago•0 comments

New Texas Instruments $60B fab will pump out tens of millions chips per day

https://www.tomshardware.com/tech-industry/semiconductors/new-texas-instruments-fab-will-pump-out...
4•rbanffy•34m ago•0 comments

I built a strategic dashboard for live geopolitics, economics,and foreign policy

https://geopoliticsmonitor.com/
2•Zzadda•42m ago•1 comments

Your AI is lying to you.

https://WithTofu.com
5•dayaya•42m ago•4 comments