frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

When hardware goes end-of-life, companies need to open-source the software

https://www.marcia.no/words/eol
151•Marciplan•2h ago

Comments

walterbell•2h ago
Is there an RSS feed?
herf•1h ago
Most systems now "fail closed" because they are based on a code signing chain of trust that has no exceptions. It would be better if some portion of these systems were made to "fail open" - you don't want a botnet to take over in this situation but you should be able to delegate code signing duties to a new party when the original one goes under or stops supporting a device.
ktallett•1h ago
This is where I hope EU do their magic
m463•1h ago
I think bose did a wise thing with their speakers. Turns "company makes my purchase worthless" to "my purchase now has open source software".

...although it could be "no more product support, talk to random people on github"

actually, don't know why there couldn't be legislative or tax support for these kinds of things.

irjustin•1h ago
> tax support for these kinds of things

What are you hoping for with tax support?

m463•21m ago
write-off product if open sourced, or make it charitable or ...

nevermind, government rarely does this right.

wmf•1h ago
Dumping responsibility on "the community" could backfire in a big way. It sounds good at small scale but it becomes a form of entitlement if the whole industry does it.
wang_li•57m ago
It’s pointless anyway because there is always someone in the community who comes along and rips out support for old hardware. Because, you know, EOL, doesn’t matter that it’s a stationary target.
kogepathic•1h ago
> What I am asking for: publish a basic GitHub repo with the hardware specs and connection protocols. Let the community build their own apps on top of it.

This concept works fine for the author's example of a kitchen scale, but fails when the device in question is something like a router that has secure boot with one key burned into e-fuses.

In that case we need both open software and a requirement that the manufacturer escrow signing keys with someone so that after EOL any software can be run.

Aurornis•46m ago
Forcing the release of signing keys would be a security disaster. The first person to grab the expired domain for the auto update server for a IoT device now gets a free botnet.

The only real way to make devices securely re-usable with custom firmware requires some explicit steps and action to signal that the user wants to run 3rd-party firmware: A specific button press sequence is enough. You need to require the user to do something explicit to acknowledge that 3rd-party software is being installed, though.

Forcing vendors to release their security mechanisms to the public and allow anyone to sign firmware as the company is not what you want, though.

Retr0id•35m ago
The OTA firmware update keys ideally shouldn't be the same as the secure boot keys.
kogepathic•7m ago
> Forcing the release of signing keys would be a security disaster.

Have you seen the state of embedded device security? It is already an unmitigated disaster.

> Forcing vendors to release their security mechanisms to the public and allow anyone to sign firmware as the company is not what you want, though.

Yes, it is what I want. I am perfectly aware of the potential downsides and what I am proposing is worth it. In our current era of enshittification, vendor pinky promises to implement a user-bypass in their signed boot chain is not good enough. Look at the Other OS controversy on the PS3 if you want an example of this in practice.

> The only real way to make devices securely re-usable with custom firmware requires some explicit steps and action to signal that the user wants to run 3rd-party firmware: A specific button press sequence is enough. You need to require the user to do something explicit to acknowledge that 3rd-party software is being installed, though.

The vendor has implemented an internal pad on the laser-welded, weather sealed, IP-rated smart watch that must be shorted to disable secure boot. Opening the device to access this will essentially destroy it, but we preserved the vendor's secure boot signing keys so missioned accomplished!

razighter777•28m ago
How about just allowing key enrollment with a physical button?
kogepathic•12m ago
This is very much not an option on most embedded devices. They allow one key to be burned once.

IIRC, a certain Marvell SoC datasheet says multiple key slots are supported, but the boot ROM only supports reading the first entry (so really, only one key is supported).

Aurornis•1h ago
> Now, I'm not asking companies to open-source their entire codebase. That's unrealistic when an app is tied to a larger platform. What I am asking for: publish a basic GitHub repo with the hardware specs and connection protocols. Let the community build their own apps on top of it.

The actual proposal in this blog doesn’t make much sense. Having the specs of a device isn’t going to change much because they can be determined by anyone examining the PCB. Most devices don’t have a simple connection protocol, like the Spotify Car Thing used as an example.

palata•49m ago
I understand the idea as "provide what is necessary for someone to reuse the hardware". Just the bare minimum, like how to flash a firmware and a minimal firmware.

Now for many products, nobody would spend the time needed to make it actually work, but for some it may be nice.

But I agree that it is more complicated than it seems, and realistically that would be on a case by case basis.

buildbot•15m ago
Honestly between the ability to flash firmware, interface specs, and maybe PCB schematics that should be enough to use an old device for a motivated individual.

My personal pet example of this is old cameras, lenses, and digital backs. Plenty of great hardware out there that currently requires very extensive reverse engineering to use that would be made a lot easier with firmware & schematics.

gregsadetsky•1h ago
One great example/case for this would be Aura Frames (recommended to me by a few folks here when I posted an Ask HN) [0]

If the company disappears... what happens to the devices and the cloud storage?

I've been really enjoying the product (it's really well done, the mobile app works perfectly well) but it's a scary thought.

I also found this Reddit thread [1] with some language from the company supposedly saying they would do their best to launch alternative tooling if they disappeared, but I can't find this language anywhere else online.

[0] https://news.ycombinator.com/item?id=45341781

[1] https://www.reddit.com/r/homeautomation/comments/1b8vei3/wha...

baaron•42m ago
I have had an itch to disect an Aura frame and do something akin to the Tonie Box jailbreak. But I am too afraid of being responsible for bricking our frame and I can't justify spending the money on one just for R&D.
gregsadetsky•2m ago
If you’re confident that you can reverse it, happy to throw $50 at this. It would be extremely great if you did this.

Anybody else want to crowdfund? :)

P.s. if you end up absolutely bricking it, but at least get one great blog post out of it, it’s still worth it ha

lacker•59m ago
In my experience, whenever you mandate open source software, you get software so unusable that it might as well be closed-source. Like, it doesn't compile, and they ignore all bug reports.
tonyhart7•47m ago
if EOL hardware become open source and community can support it then community would extend that EOL product and making it extensively harder for older customer to buy new product

I love to see this future but knowing this, company would never do this

palata•47m ago
I totally agree with the frustration of having hardware I would like to keep using but can't because it got EOL. Like a smart speaker or something.

But I don't know if there is a pragmatic way to approach that. I mean, I could also say "it should be illegal to produce e-waste", but what does that mean and how do we actually do it?

cogman10•36m ago
If you aren't looking at capturing 100% ewaste, then simple laws around liability and penalties for reduced functionality is all you'd need.

Simple things like "if an electronic device, through no fault of the owner, can no longer perform it's main function, then the owner is due a full refund. A company may escape the refund by placing all software required to run the product in the public domain."

It'd miss cases like fly by night companies, but you could catch big players like google disabling their thermostats for non-hardware reasons.

fermuch•15m ago
The only thing you'd achieve doing that is to change the "main function" of a device to somethings silly, like a thermostat being sold as an art decor with the optional additional of functioning as a thermostat too.
hsbauauvhabzb•29m ago
Where does it end, should EOL windows be open sourced because some software/games/hardware do not work on newer windows versions?

Open source windows 10 would cannibalise Microsoft’s long term objectives.

ezst•12m ago
If that's one way to get to Microsoft abusive planned obsolescence and absurd e-waste, I take it
godzillabrennus•10m ago
Given that Microsoft currently intends to productize Windows users' data to build AI that replaces their users' jobs, it seems reasonable to cannibalize those long-term objectives...
Retr0id•41m ago
> And here's the thing: with vibe-coding making development more accessible than ever, this isn't just for hardcore developers anymore. Regular users can actually tinker with this stuff now.

Have you tried pointing an LLM agent at a decompiled apk? It could probably write you protocol docs for it.

natas•37m ago
"EOL hardware should mean open-source software"

It is if you buy carefully: I don't buy hardware that can't be used with linux or whatever I deem necessary. And then, there's the car...

ellisd•24m ago
Dear EU Santa, please force Meta to open source the Facebook Portal as well so I can repurpose relatively decent hardware for something useful and fun, rather than e-waste.
protocolture•11m ago
I actually think this is a great idea. Not even for "Open Source".

Can you imagine if UBNT had to open source its EOL boot chain, so that Cambium was legally entitled to roll its firmware for old Unifi kit? And Vice Versa?

The result might not be "Old hardware supported by the community" the result might be "Eternal product updates so we can legally prevent Cambium from taking our customers"

bigfatkitten•2m ago
Open source isn’t going to happen on any real scale, because pretty much any non-trivial commercial product is going to have a ton of third party IP that the manufacturer has no right to give you.

What manufacturers should be required to do, at a minimum, is remove any impediment to you running whatever alternative software you choose.

A 40-line fix eliminated a 400x performance gap

https://questdb.com/blog/jvm-current-thread-user-time/
100•bluestreak•2h ago•22 comments

Every GitHub object has two IDs

https://www.greptile.com/blog/github-ids
82•dakshgupta•9h ago•8 comments

The $LANG Programming Language

57•dang•1h ago•6 comments

vLLM large scale serving: DeepSeek 2.2k tok/s/h200 with wide-ep

https://blog.vllm.ai/2025/12/17/large-scale-serving.html
20•robertnishihara•9h ago•0 comments

Are two heads better than one?

https://eieio.games/blog/two-heads-arent-better-than-one/
109•evakhoury•9h ago•24 comments

The Tulip Creative Computer

https://github.com/shorepine/tulipcc
186•apitman•8h ago•38 comments

Sei (YC W22) Is Hiring a DevOps Engineer (India/In-Office/Chennai/Gurgaon)

https://www.ycombinator.com/companies/sei/jobs/Rn0KPXR-devops-platform-ai-infrastructure-engineer
1•ramkumarvenkat•40m ago

AI Generated Music Barred from Bandcamp

https://old.reddit.com/r/BandCamp/comments/1qbw8ba/ai_generated_music_on_bandcamp/
561•cdrnsf•7h ago•433 comments

When hardware goes end-of-life, companies need to open-source the software

https://www.marcia.no/words/eol
151•Marciplan•2h ago•33 comments

No management needed: anti-patterns in early-stage engineering teams

https://www.ablg.io/blog/no-management-needed
69•tonioab•6h ago•116 comments

The truth behind the 2026 J.P. Morgan Healthcare Conference

https://www.owlposting.com/p/the-truth-behind-the-2026-jp-morgan
15•abhishaike•7h ago•1 comments

Japan's Skyscraper Factories (2021)

https://www.construction-physics.com/p/japans-skyscraper-factories
37•Pikamander2•6d ago•1 comments

We can't have nice things because of AI scrapers

https://blog.metabrainz.org/2025/12/11/we-cant-have-nice-things-because-of-ai-scrapers/
260•LorenDB•3h ago•147 comments

Show HN: Microwave – Native iOS app for videos on ATproto

https://testflight.apple.com/join/cVxV1W3g
9•sinned•8h ago•0 comments

How to make a damn website (2024)

https://lmnt.me/blog/how-to-make-a-damn-website.html
137•birdculture•8h ago•47 comments

Show HN: Nogic – VS Code extension that visualizes your codebase as a graph

https://marketplace.visualstudio.com/items?itemName=Nogic.nogic
65•davelradindra•6h ago•25 comments

Scott Adams has died

https://www.youtube.com/watch?v=Rs_JrOIo3SE
740•ekianjo•10h ago•1219 comments

A deep dive on agent sandboxes

https://pierce.dev/notes/a-deep-dive-on-agent-sandboxes
29•icyfox•1d ago•7 comments

Revup: Upload once to create multiple, relative GitHub PRs

https://github.com/Skydio/revup
6•krosaen•8h ago•2 comments

Is it a joke?

https://novalis.org/blog/2025-11-06-is-it-a-joke.html
17•luu•3h ago•2 comments

A university got itself banned from the Linux kernel (2021)

https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source
59•italophil•6h ago•41 comments

My first paper: A practical implementation of Rubiks cube based passkeys

https://ieeexplore.ieee.org/document/11280260
43•acorn221•6d ago•17 comments

The insecure evangelism of LLM maximalists

https://lewiscampbell.tech/blog/260114.html
173•todsacerdoti•2h ago•166 comments

Terra - A rolling-release Fedora repository

https://terra.fyralabs.com/
11•doodlesdev•3h ago•3 comments

Let's be honest, Generative AI isn't going all that well

https://garymarcus.substack.com/p/lets-be-honest-generative-ai-isnt
110•7777777phil•7h ago•119 comments

Inlining – The Ultimate Optimisation

https://xania.org/202512/17-inlining-the-ultimate-optimisation
44•PaulHoule•4d ago•18 comments

Show HN: AsciiSketch a free browser-based ASCII art and diagram editor

https://files.littlebird.com.au/ascii-sketch.html
14•schappim•3h ago•4 comments

Running Lean at Scale

https://harmonic.fun/news#blog-post-lean
55•eab-•3h ago•3 comments

Influencers and OnlyFans models are dominating U.S. O-1 visa requests

https://www.theguardian.com/us-news/2026/jan/11/onlyfans-influencers-us-o-1-visa
344•bookofjoe•8h ago•247 comments

Why Real Life is better than IRC (2000)

https://everything2.com/node/e2node/Why%20Real%20Life%20is%20better%20than%20IRC
49•themaxdavitt•4d ago•41 comments