frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

We have a year to fix security everywhere

https://jyn.dev/a-year-to-fix-security/
76•saikatsg•1h ago•35 comments

I've factored the RSA keys of a Certificate Authority from the 90s

https://mcpherrin.ca/2026/09/07/rsa.html
235•ahlCVA•4h ago•45 comments

My Feed, My Way

https://www.pm.gov.au/media/my-feed-my-way
30•dotcoma•55m ago•13 comments

Mistral raises €3B to make sovereign, open-weight AI the technology frontier

https://mistral.ai/news/mistral-makes-sovereign-open-weight-ai-to-frontier/
26•kuberwastaken•59m ago•4 comments

I tested 10 model/harness combinations on the same Three.js task

https://alvins82.github.io/hangar-harness-model-tests/
33•alvins82•2h ago•12 comments

TALA Is Open-Source

https://d2lang.com/blog/tala-is-open-source/
167•alixanderwang•6h ago•11 comments

How well do agents use test/verification techniques?

https://danluu.com/agentic-testing/
45•vinhnx•3h ago•7 comments

Arm Mali G2-Ultra NX GPU: desktop-class mobile gameplay with AI-native graphics

https://newsroom.arm.com/blog/arm-mali-g2-ultra-nx-ai-native-mobile-graphics
18•Re-Tails•1h ago•9 comments

GamersNexus and LG: Or why rooting your TV is a bad idea

https://leaflet.pub/p/did:plc:yhgc5rlqhoezrx6fbawajxlh/3muwrqenzfk2n
35•drasticactions•2h ago•19 comments

Watch Los Angeles get built, one building at a time (1880–2026)

https://lax-skyline.parcelscope.net/
266•rustywasm•11h ago•136 comments

Jellyfin 12.0

https://jellyfin.org/posts/jellyfin-release-12.0/
247•0xC0ncord•4h ago•91 comments

Extinct Tasmanian tiger's 'snap' unlike any living mammal's bite

https://www.cnn.com/2026/09/02/science/tasmanian-tiger-skull-bite-force
21•cisc•4d ago•3 comments

Navier-Stokes – Tristan Buckmaster [pdf]

https://cims.nyu.edu/~tristanb/statement.pdf
6•procedurecall•23m ago•0 comments

Leaving VMware just got harder after Broadcom pulled VDDK downloads

https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-...
160•josephcsible•9h ago•67 comments

The VMs Powering Mobile Agents (Instinct, Claude Code)

https://rohanadwankar.github.io/posts/platforms.html
9•RohanAdwankar•1h ago•1 comments

John Margolies' photographs of roadside America

https://publicdomainreview.org/collection/john-margolies-photographs-of-roadside-america/
63•duck•4d ago•16 comments

WeatherNext 3

https://deepmind.google/science/weathernext/
294•matthieu_bl•4d ago•68 comments

Understanding Computer Memory Architecture and SSD Internals

https://codingpirate.com/understanding-computer-memory-architecture-ac9320110787
7•Deeptiman•1d ago•1 comments

Scientists observe Einstein's gravity in the quantum world

https://www.ox.ac.uk/news/2026-08-28-scientists-observe-einsteins-gravity-in-the-quantum-world
197•mudil•3d ago•47 comments

216M Spy TVs – The LG Smart TV Problem [video]

https://www.youtube.com/watch?v=6IFVTcM28KA
674•treve•1d ago•862 comments

Trusting-Trust Attack against an Entire Linux Distribution

https://arxiv.org/abs/2607.24888
189•signa11•2d ago•40 comments

There's a new "Google Jail" for independent wikis

https://weirdgloop.org/blog/google-jail
25•pizzaiolo•4h ago•5 comments

Colorlight 5A-75B: A dive into a popular low-cost ECP5 (FPGA) development board

https://blog.yosyshq.com/p/colorlight-part-1/
26•gregsadetsky•3d ago•6 comments

Show HN: Jigsaw Haiku

https://jigsawhaiku.com/
79•windowshopping•3d ago•27 comments

Everything is free now, so why not a floating orb in my IDE

https://eighttrigrams.net/post/79
18•eighttrigrams•2d ago•8 comments

Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon

https://github.com/Sadpainy/Stuxnet
144•CMDDestory•7h ago•46 comments

Some more thoughts on random_page_cost

https://vondra.me/posts/some-more-thoughts-on-random-page-cost/
16•blueshoess•3d ago•1 comments

Emacs Bedrock 2.0

https://lambdaland.org/posts/2026-09-06-bedrock-v2/
83•ashton314•9h ago•8 comments

Caltech Mathathon – first hackathon ever devoted to research level mathematics

https://mathathonchallenge.com/index.html
253•astroanax•20h ago•89 comments

This Month in Ladybird – August 2026

https://ladybird.org/newsletter/2026-08-31/
217•exploraz•3d ago•53 comments
Open in hackernews

GamersNexus and LG: Or why rooting your TV is a bad idea

https://leaflet.pub/p/did:plc:yhgc5rlqhoezrx6fbawajxlh/3muwrqenzfk2n
33•drasticactions•2h ago

Comments

badsectoracula•34m ago
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P

Krutonium•30m ago
I'm pretty sure they DID mention that they can remotely flip settings. So that's a thing for sure.
jaimex2•16m ago
That would be against Youtubes terms, the video would get pulled.
Arcuru•16m ago
demonstrate != explain?
supriyo-biswas•9m ago
They do show using https://github.com/raws0kil/jsbro-autoroot to get root access. For anyone interested, that pointer is enough, I guess.
bob1029•30m ago
> What am I meant to take away from this? If you look at other IoT devices, they’re going to show the same thing. But here it’s presented as bad. Why?

The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.

Retr0id•30m ago
> If you root or jailbreak your devices, you've, by their very nature, broken their security.

> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.

The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)

froddd•21m ago
Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?
Retr0id•18m ago
The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. There are also more up-to-date rooting tools beyond rootmy.tv.

The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.

rickdeckard•9m ago
> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining.

But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

rickdeckard•12m ago
Thanks for the write-up, it reflects my own impression of the video.

The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.

They should have decided to set the focus on a specific area and then present every finding around that, i.e.:

1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.

2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.

3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.

All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.

If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...

LoganDark•11m ago
They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.
fulafel•11m ago
Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?
ChrisArchitect•7m ago
Related:

216M Spy TVs – The LG Smart TV Problem [video]

https://news.ycombinator.com/item?id=49592375

lovich•7m ago
> Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an unmodified device.

> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

What is this authors point?

LG doesn’t need a root exploit to get this info because they made the fucking thing.

I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.

Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?

taylorfinley•3m ago
This reads like a PR crisis management firm planted article. it probably isn't, but it reads like one. It muddies the waters with vague implications and suggests we cannot infer anything from encrypted packets. If your screen is showing content sourced over HDMI and the packets are heading to the ACR endpoint, I think it's safe to infer HDMI is being ACR'd.
Retr0id•7m ago
Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.
LoganDark•18m ago
I read the documentation and it appears that the only reason it doesn't still work is because development was "postponed for a few months" back in 2021. Presumably there is still the possibility of exploits on the latest versions, it's just nobody's bothered yet.