frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

My smart sleep mask broadcasts users' brainwaves to an open MQTT broker

https://aimilios.bearblog.dev/reverse-engineering-sleep-mask/
136•minimalthinker•2h ago

Comments

baby_souffle•2h ago
Well that’s a brand new sentence.
amelius•1h ago
But not a beautiful sentence.
bryanrasmussen•2h ago
huh, not sure if life imitates snark and bull https://medium.com/luminasticity/great-products-of-illuminat...

"The ZZZ mask is an intelligent sleep mask — it allows you to sleep less while sleeping deeper. That’s the premise — but really it is a paradigm breaking computer that allows full automation and control over the sleep process, including access to dreamtime."

or if this is another scifi variation of the same theme, with some dev like embellishments.

mrguyorama•14m ago
That is the premise of HypnoSpace Outlaw, a neat game about 90s internet nostalgia and scifi.
roywiggins•2h ago
cyberpunk
morkalork•2h ago
>Since every device shares the same credentials and the same broker, if you can read someone's brainwaves you can also send them electric impulses.

Amazing.

intellirim•2h ago
This is exactly why we need audit trails for connected devices. Users have no visibility into what data is being sent where. The fact that brainwave data is broadcast to an open broker without user knowledge is a governance failure, not just a security bug.
plagiarist•1h ago
It is a governance failure.

It is also technically a user failure to have purchased a connected device in the first place. Does the device require a closed-source proprietary app? Closed-source non-replaceable OS? Do not buy it.

brabel•7m ago
Very few options available, if any, if you actually do that. The IoT market is unfortunately small and dominated by vendors that don’t want at all an open ecosystem. That would hinder their ability to force you to pay for a subscription which is where all the money is.
ai-x•26m ago
There should be two separate lines of products. One in which privacy is priority and adheres to government regulations (around privacy) and probably costs 2x and one with zero government intervention (around privacy) which costs less and time-to-market is faster.

I don't want a few irrationally paranoid people bottlenecking progress and access to the latest technology and innovation.

I'm happy to broadcast my brainwaves on an open YouTube channel for the ZERO people who are interested in it.

selkin•20m ago
otoh: the non regulated should cost more.

It’s kinda like “qualified investors” - you want to make sure people who are wiling to do something extremely stupid can afford it and acknowledge their stupidity.

We don’t need regulation to protect those that can afford to buy protection: we need it for those who can’t.

tgv•12m ago
Explain how sending EEG recordings is progress. And why faster access to the latest tech is always good, for everyone.
basedrum•1h ago
Name the company, hiding it is irresponsible
brabel•6m ago
It’s probably safe to assume they are all like that.
dnw•1h ago
I would love to see the prompt history. Always curious how much human intervention/guidance is necessary for this type of work because when I read the article I come away thinking I prompt Claude and it comes out with all these results. For example, "So Claude went after the app instead. Grabbed the Android APK, decompiled it with jadx." All by itself or the author had to suggest and fiddle with bits?
minimalthinker•1h ago
Very little intervention tbh. I will try to retrieve it and post.
selkin•23m ago
By default, Claude code keeps session history (as jsonl files in ~/.claude).

It’s wasteful not to save and learn from those.

cyanydeez•1h ago
Really is a derth of livestreams demostrating these things. Youd think if thetes so much Unaided AI work people would stream it.
Aurornis•1h ago
Kickstarter is full of projects like this where every possible shortcut is taken to get to market. I’ve had some good success with a few Kickstarter projects but I’ve been very selective about which projects I support. More often than not I can identify when a team is in over their heads or think they’re just going to figure out the details later, after the money arrives.

For a period of time it was popular for the industrial designers I knew to try to launch their own Kickstarters. Their belief was that engineering was a commodity that they could hire out to the lowest bidder after they got the money. The product design and marketing (their specialty) was the real value. All of their projects either failed or cost them more money than they brought in because engineering was harder than they thought.

I think we’re in for another round of this now that LLMs give the impression that the software and firmware parts are basically free. All of those project ideas people had previously that were shelved because software is hard are getting another look from people who think they’re just going to prompt Claude until the product looks like it works.

lr4444lr•1h ago
At this point, I trust LLMs to come up with something more secure than the cheapest engineering firm for hire.
minimalthinker•1h ago
this.
lukan•51m ago
And the cheapest engineering firm won't use LLMs as well, wherever possible?
TheRealPomax•46m ago
fun fact, LLMs come in cheapest and useless and expensive but actually does what's being asked, too.

So, will they? Probably. Can you trust the kind of LLM that you would use to do a better job than the cheapest firm? Absolutely.

Aurornis•50m ago
The cheapest engineering firms you hire are also using LLMs.

The operator is still a factor.

jama211•21m ago
Yeah, but they’ll add another layer of complexity over doing it yourself
SubiculumCode•1h ago
How about complaining that brain waves get sent to a server? I'm a neuroscientist, so I'm not going to say that the EEG data is mind reading or anything, but as a precedent, non privacy of brain data is very bad.
amarant•1h ago
How useful could something like this be for research? I'm not a neuroscientist so I have no clue, but it seems like the only justification I can think of..
AnimalMuppet•27m ago
If they're taking patient data for research without permission, they are not ethical researchers.
minimalthinker•25m ago
I believe they use it for sleep tracking
brabel•24m ago
Not a neuroscientist either but I would imagine that raw data without personal information would not be useful for much. I can imagine that it would be quite valuable if accompanied with personal data plus user reports about how they slept each night, what they dreamed about if anything, whether it was positive dreams or nightmares etc. And I think quite a few people wouldn’t mind sharing all of that in the name of science, but in this case they don’t seem to have even tried to ask.
minimalthinker•46m ago
I would presume data privacy laws already have good precedent for health data?
baby_souffle•22m ago
> I would presume data privacy laws already have good precedent for health data?

Google for a list of all the exceptions to HIPPA. There are a lot of things that _seem_ like they should be covered by HIPPA but are not...

minimalthinker•20m ago
Interesting...
freedomben•20m ago
Only for "covered entities" under HIPAA (at least in the US)
bobim•1h ago
Won't they sue for the reverse engineering?
speedgoose•1h ago
Remember that the S in IoT stands for Security.

I have deployed open MQTT to the world for quick prototypes on non personal (and healthcare) data. Once my cloud provider told me to stop because they didn’t like it, that could be used for relay DDOS attacks.

I would not trust the sleep mask company even if they somehow manage to have some authentication and authorisation on their MQTT.

throw876987696•33m ago
Without a brand name, how can we verify this is real?
ohyoutravel•25m ago
Without any skin in the game with your username, why should we take anything you say seriously?
digiown•20m ago
As an aside, it seems cool that the bar to reverse engineering has lowered from all the LLMs. Maybe we'll get to take full control of many of these "smart" devices that require proprietary/spyware apps and use them in a fully private way. There's no excuse that any such apps solely to interact with devices locally need to connect to the internet, like dishwasher.

https://www.jeffgeerling.com/blog/2025/i-wont-connect-my-dis...

autoexec•11m ago
This guy bought an internet connected sleep mask so it's not surprising that it was collecting all kinds of data, or that it was doing it insecurely (everyone should expect IoT anything to be a security nightmare) so to me the surprising thing about this is that the company actually bothered to worry about saving bandwidth/power and went through the trouble of using MQTT. Probably not the best choice, and they didn't bother to do it securely, but I'm genuinely impressed that they even tried to be efficient while sucking up people's personal data.
SilentM68•7m ago
Interesting project. Here's a thought which I've always had in the back of my mind, ever since I saw something similar in an episode of Buck Rogers (70s-80s)! Many people struggle with falling asleep due to persistent beta waves; natural theta predominance is needed but often delayed. Imagine an "INEXPENSIVE" smart sleep mask that facilitates sleep onset by inducing brain wave transitions from beta (wakeful, high-frequency) to alpha (8-13 Hz, relaxed) and then theta (4-8 Hz, stage 1 light sleep) via non-invasive stimulation. A solution could be a comfortable eye mask with integrated headphones (unintrusive) and EEG sensors. It could use binaural beats or similar audio stimulation to "inject" alpha/theta frequencies externally, guiding the brain to a tipping point for abrupt sleep onset. Sensors would detect current waves; app-controlled audio ramps from alpha-inducing beats to theta, ensuring natural predominance. If it could be designed, it could accelerate sleep transition, improve quality, non-pharmacological.

My smart sleep mask broadcasts users' brainwaves to an open MQTT broker

https://aimilios.bearblog.dev/reverse-engineering-sleep-mask/
139•minimalthinker•2h ago•58 comments

Ooh.directory: a place to find good blogs that interest you

https://ooh.directory/
244•hisamafahri•4h ago•82 comments

Show HN: Sameshi – a ~1200 Elo chess engine that fits within 2KB

https://github.com/datavorous/sameshi
111•datavorous_•4h ago•37 comments

Zig – io_uring and Grand Central Dispatch std.Io implementations landed

https://ziglang.org/devlog/2026/#2026-02-13
279•Retro_Dev•9h ago•175 comments

Amsterdam Compiler Kit

https://github.com/davidgiven/ack
8•andsoitis•1h ago•1 comments

Shades of Halftone

https://blog.maximeheckel.com/posts/shades-of-halftone/
60•surprisetalk•4d ago•1 comments

Vim 9.2 Released

https://www.vim.org/vim-9.2-released.php
114•tapanjk•2h ago•47 comments

A Review of M Disc Archival Capability. With long term testing results

http://www.microscopy-uk.org.uk/mag/artsep16/mol-mdisc-review.html
17•1970-01-01•1h ago•14 comments

Ask HN: How to get started with robotics as a hobbyist?

25•StefanBatory•6d ago•16 comments

Show HN: Arcmark – macOS bookmark manager that attaches to browser as sidebar

https://github.com/Geek-1001/arcmark
7•ahmed_sulajman•1h ago•0 comments

Platforms bend over backward to help DHS censor ICE critics, advocates say

https://arstechnica.com/tech-policy/2026/02/platforms-bend-over-backward-to-help-dhs-censor-ice-c...
179•pjmlp•2h ago•78 comments

Show HN: I spent 3 years reverse-engineering a 40 yo stock market sim from 1986

https://www.wallstreetraider.com/story.html
608•benstopics•4d ago•205 comments

Show HN: SQL-tap – Real-time SQL traffic viewer for PostgreSQL and MySQL

https://github.com/mickamy/sql-tap
204•mickamy•13h ago•33 comments

Ars Technica makes up quotes from Matplotlib maintainer; pulls story

https://infosec.exchange/@mttaggart/116065340523529645
405•robin_reala•8h ago•164 comments

Babylon 5 is now free to watch on YouTube

https://cordcuttersnews.com/babylon-5-is-now-free-to-watch-on-youtube/
503•walterbell•1d ago•253 comments

Code Storage by the Pierre Computer Company

https://code.storage/
36•admp•4d ago•23 comments

Stoat removes all LLM-generated code following user criticism

https://github.com/orgs/stoatchat/discussions/1022
23•ashleyn•1h ago•15 comments

What color are your bits? (2004)

https://ansuz.sooke.bc.ca/entry/23
27•tomodachi94•3d ago•8 comments

7zip.com Is Serving Malware

https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-...
47•Alifatisk•3h ago•24 comments

Audiophiles Can't Distinguish Audio Sent Through Copper, Banana or Mud

https://www.tomshardware.com/speakers/in-a-blind-test-audiophiles-couldnt-tell-the-difference-bet...
19•RandomGerm4n•1h ago•9 comments

Cogram (YC W22) – Hiring former technical founders

https://www.ycombinator.com/companies/cogram/jobs/LDTrViN-ex-technical-founder-product-engineer
1•ricwo•11h ago

The Sling: Humanity's Forgotten Power

https://www.slinging.org/
76•jsattler•4d ago•18 comments

Understanding the Go Compiler: The Linker

https://internals-for-interns.com/posts/the-go-linker/
150•valyala•6d ago•39 comments

The World of Harmonics – With a Coffee, Guitar and Synth

https://mynoise.net/vlog.php?ep=20260204
67•gregsadetsky•5d ago•13 comments

How many registers does an x86-64 CPU have? (2020)

https://blog.yossarian.net/2020/11/30/How-many-registers-does-an-x86-64-cpu-have
55•tosh•4h ago•37 comments

How the Little Guy Moved

https://animationobsessive.substack.com/p/how-the-little-guy-moved
98•zdw•5d ago•4 comments

Show HN: Data Engineering Book – An open source, community-driven guide

https://github.com/datascale-ai/data_engineering_book/blob/main/README_en.md
217•xx123122•20h ago•26 comments

The mathematics of compression in database systems

https://www.bitsxpages.com/p/the-mathematics-of-compression-in
36•agavra•4d ago•6 comments

Sound and Practical Points-To Analysis for Incomplete C Programs [pdf]

https://www.sjalander.com/research/pdf/sjalander-cgo2026-pip.pdf
6•st_•5d ago•0 comments

Building a TUI is easy now

https://hatchet.run/blog/tuis-are-easy-now
280•abelanger•1d ago•218 comments