<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tkems</title><link>https://news.ycombinator.com/user?id=tkems</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 07 Apr 2026 05:57:38 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tkems" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tkems in "My Journey to a reliable and enjoyable locally hosted voice assistant (2025)"]]></title><description><![CDATA[
<p>One that I have been experimenting with is using analog phones (including rotary ones!) to act as the satellites. I live in an older home and have phone jacks in most of the rooms already so I only had to use a single analog telephone adapter. [0] The downside is I don't have wake word support, but it makes it more private and I don't find myself missing my smart speakers that much. At some point I would like to also support other types of calls on the phones, but for now I need to get an LLM hooked up to it.<p>[0] <a href="https://www.home-assistant.io/voice_control/worlds-most-private-voice-assistant" rel="nofollow">https://www.home-assistant.io/voice_control/worlds-most-priv...</a></p>
]]></description><pubDate>Mon, 16 Mar 2026 16:29:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47401149</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=47401149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47401149</guid></item><item><title><![CDATA[New comment by tkems in "Suspension of inbound parcels from China and Hong Kong"]]></title><description><![CDATA[
<p>I can confirm that Aliexpress doesn't allow me to checkout with a USA address and states that items can't be shipped to my region. -edit: Since this post it seems that I can order items again? Very odd.</p>
]]></description><pubDate>Wed, 05 Feb 2025 01:54:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=42942513</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=42942513</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42942513</guid></item><item><title><![CDATA[New comment by tkems in "FTC takes action against GoDaddy for alleged lax data security"]]></title><description><![CDATA[
<p>I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wouldn't they want their customers to be more secure by default? To me it just reeks of money-grabbing for people that are none the wiser.</p>
]]></description><pubDate>Tue, 28 Jan 2025 15:57:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=42853776</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=42853776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42853776</guid></item><item><title><![CDATA[New comment by tkems in "Installed an open source garage door opener, and I'm loving it"]]></title><description><![CDATA[
<p>From what I've read, myQ is pretty locked down and doesn't support local control (outside of a HomeKit device that I think is no longer supported).<p>I would guess that the cert pinning would prevent such MITM attack, but I could be wrong. I'm not a huge fan of Chamberlain and myQ since they are so against 3rd party use of their products [0].<p>[0] <a href="https://www.home-assistant.io/blog/2023/11/06/removal-of-myq-integration/" rel="nofollow">https://www.home-assistant.io/blog/2023/11/06/removal-of-myq...</a></p>
]]></description><pubDate>Fri, 15 Nov 2024 21:23:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=42151261</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=42151261</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42151261</guid></item><item><title><![CDATA[New comment by tkems in "MicroPython on Flipper Zero"]]></title><description><![CDATA[
<p>Yes, RF (radio frequency) remotes I've seen include my garage door opener, some overhead fans in bedrooms, gates, remote outlet/light controllers.</p>
]]></description><pubDate>Fri, 20 Sep 2024 00:43:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=41597748</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=41597748</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41597748</guid></item><item><title><![CDATA[New comment by tkems in "MicroPython on Flipper Zero"]]></title><description><![CDATA[
<p>I would check out the Unleashed firmware [1]. I've had pretty good luck with it so far.<p>[1] <a href="https://github.com/DarkFlippers/unleashed-firmware">https://github.com/DarkFlippers/unleashed-firmware</a></p>
]]></description><pubDate>Thu, 19 Sep 2024 20:33:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=41596113</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=41596113</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41596113</guid></item><item><title><![CDATA[New comment by tkems in "MicroPython on Flipper Zero"]]></title><description><![CDATA[
<p>As someone in cybersecurity, it is handy as a low frequency RFID reader as Android phones only support higher frequency. Having something compact and in a single unit (compared to a Proxmark) makes it easier to 'grab-n-go'. It is neat to show people how insecure common access control systems are.<p>I've also used it as a universal remote more than a few times on devices that didn't come with a remote. The App running on a phone makes it somewhat easy to transfer new remote templates to the Flipper over Bluetooth.<p>It also comes in handy as a serial adapter as it has GPIO pins you can connect to things (UART headers).<p>The RF transceiver is also cool to capture RF remotes (garage doors, overhead fans, etc.) and replay them.</p>
]]></description><pubDate>Thu, 19 Sep 2024 20:30:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=41596086</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=41596086</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41596086</guid></item><item><title><![CDATA[Unmasking Vulnerabilities in Cheap IoT Cameras from One Chinese Manufacturer]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.trevorkems.com/operation-big-brother-iot-camera/">https://www.trevorkems.com/operation-big-brother-iot-camera/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41593048">https://news.ycombinator.com/item?id=41593048</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 19 Sep 2024 15:42:16 +0000</pubDate><link>https://www.trevorkems.com/operation-big-brother-iot-camera/</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=41593048</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41593048</guid></item><item><title><![CDATA[New comment by tkems in "Reverse-Engineering an IP Camera (2019)"]]></title><description><![CDATA[
<p>This is a great run down of the process to extract the firmware from these types of devices without desoldering the flash. I've done a fair amount of reverse engineering and a lot of devices have similar vulnerabilities.<p>I think more time needs to be spent looking into these commonly used, cheap IoT devices and educating consumers on the risks of using a poorly secured device on their network.<p>The upside of these vulnerabilities is that you can run your own code on these! 'Declouding' is great as it can extend the lifetime of these devices and make using them more private.</p>
]]></description><pubDate>Wed, 17 Jul 2024 15:42:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=40987103</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=40987103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40987103</guid></item><item><title><![CDATA[New comment by tkems in "Reverse engineering Ticketmaster's rotating barcodes"]]></title><description><![CDATA[
<p>With Google Wallet (the only one I have at the moment), it is not static for the ticket. It has a NFC and barcode option. The barcode changes every 15 seconds for me.</p>
]]></description><pubDate>Mon, 08 Jul 2024 16:42:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=40906936</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=40906936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40906936</guid></item><item><title><![CDATA[New comment by tkems in "Reverse engineering Ticketmaster's rotating barcodes"]]></title><description><![CDATA[
<p>I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.</p>
]]></description><pubDate>Mon, 08 Jul 2024 16:36:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=40906885</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=40906885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40906885</guid></item><item><title><![CDATA[New comment by tkems in "Flock Safety is the biggest player in a city-by-city scramble for surveillance"]]></title><description><![CDATA[
<p>One issue I have with the Flock cameras installed in my city is that they are installed on public land (right next to the road) and paid for with tax dollars.</p>
]]></description><pubDate>Wed, 01 May 2024 16:22:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=40225423</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=40225423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40225423</guid></item><item><title><![CDATA[New comment by tkems in "Flock Safety is the biggest player in a city-by-city scramble for surveillance"]]></title><description><![CDATA[
<p>One of the Flock cameras was installed in my city nearby where I live. Once I noticed it, I thought it was a red light camera at first since it was near an intersection.<p>I did some research on them and found that they are completely wireless (cellular network most of the time) and powered by a 65w solar panel. Since they capture every license plate that passes by, I wasn't thrilled it was a private company keeping the data, even if they say they only keep it for 30 days.<p>I did a FOIA request with my city to see how many are in use and their locations to share with my community. I also plan on asking why my city thinks it is a good use of tax dollars. I think it should be a requirement for cities to disclose their use since it is a private company installing private equipment (and a camera at that!) on public land to monitor the public.</p>
]]></description><pubDate>Wed, 01 May 2024 16:19:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=40225373</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=40225373</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40225373</guid></item><item><title><![CDATA[New comment by tkems in "Ask HN: Should Banks Phish Their Own Customers"]]></title><description><![CDATA[
<p>If banks would spend money on this and not enabling support for hard to phish MFA options like hardware keys (FIDO2), I would change banks.<p>We have solutions to most of the phishing attacks, but most people find them hard to use or don't want to use them as they are seen as not important. I've made comments to several companies that SMS or TOTP based MFA is not phish-proof and that they need to implement something stronger, but it often is ignored.</p>
]]></description><pubDate>Thu, 28 Mar 2024 16:08:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=39853361</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39853361</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39853361</guid></item><item><title><![CDATA[New comment by tkems in "Class Action Against General Motors LLC, OnStar LLC, LexisNexis Risk Solutions [pdf]"]]></title><description><![CDATA[
<p>Wow, I just submitted the consumer disclosure report this morning after finding out about it from somewhere else. I am VERY interested to see if anything is reported from my car since I don't have any of the addons/monthly fees.</p>
]]></description><pubDate>Fri, 15 Mar 2024 00:33:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=39710744</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39710744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39710744</guid></item><item><title><![CDATA[New comment by tkems in "Reverse engineering a car key fob signal"]]></title><description><![CDATA[
<p>This sounds like HomeLink and is indeed more complex. My understanding of it is that they partner with lots of companies to support their rolling/fixed codes and remotes so that they can be paired to your garage door.<p>I linked this in a sub comment, but the largest garage door maker in the US is Chamberlain [0] (which owns a ton of other brands) and uses known rolling code algorithms that can be decoded. [1]<p>[0] <a href="https://www.chamberlain.com/" rel="nofollow">https://www.chamberlain.com/</a>
[1] <a href="https://github.com/argilo/secplus">https://github.com/argilo/secplus</a></p>
]]></description><pubDate>Thu, 14 Mar 2024 16:40:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=39706109</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39706109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39706109</guid></item><item><title><![CDATA[New comment by tkems in "Reverse engineering a car key fob signal"]]></title><description><![CDATA[
<p>The largest garage door manufacture in the US uses the Security+ and Security+ 2.0 algorithms that are rolling, but can be fairly trivially decoded to gain the serial number and rolling value of a remote. [0] This is how the flipper zero decodes remotes for playback later.<p>[0] <a href="https://github.com/argilo/secplus">https://github.com/argilo/secplus</a></p>
]]></description><pubDate>Thu, 14 Mar 2024 16:36:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=39706057</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39706057</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39706057</guid></item><item><title><![CDATA[New comment by tkems in "FCC rules AI-generated voices in robocalls illegal"]]></title><description><![CDATA[
<p>I would say that money is the root of the problem. I think that most VOIP providers don't want to loose out on unencrypted traffic (both legitimate and spam).<p>Also, why do I seem to always get spam from a few providers? And why aren't we holding them accountable?</p>
]]></description><pubDate>Thu, 08 Feb 2024 18:47:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=39305859</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39305859</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39305859</guid></item><item><title><![CDATA[New comment by tkems in "FCC rules AI-generated voices in robocalls illegal"]]></title><description><![CDATA[
<p>This was my thought too. While I do think going after this kind of scam is a good first step, I don't see overseas operators not using this any less. Most spam calls I get don't follow the do not call list, why would they follow this either?<p>I think the FCC needs to step up and have a hard deadline for STIR/SHAKEN with fines for operators who don't comply. That is the only way, IMHO, that the VOIP operators will take it seriously.</p>
]]></description><pubDate>Thu, 08 Feb 2024 18:43:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=39305793</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39305793</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39305793</guid></item><item><title><![CDATA[New comment by tkems in "DEF CON 32 Was Canceled. We Un-Canceled it"]]></title><description><![CDATA[
<p>I find this strange but not surprising. I've heard of speed bumps in the past related to 'hackers in town' and I wouldn't be surprised if it comes out later that it had something to do with it, even if unfounded. I think overall, having that many 'hackers' in town makes people overly paranoid.<p><tinfoil hat> I wonder if the ransomware incident last year played a role in this decision? [0] I'm guessing they wouldn't announce it for fear of boycott, but who knows. </tinfoil hat><p>[0] <a href="https://www.cnbc.com/2023/09/14/caesars-paid-millions-in-ransom-to-cybercrime-group-prior-to-mgm-hack.html" rel="nofollow">https://www.cnbc.com/2023/09/14/caesars-paid-millions-in-ran...</a></p>
]]></description><pubDate>Mon, 05 Feb 2024 03:47:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=39257074</link><dc:creator>tkems</dc:creator><comments>https://news.ycombinator.com/item?id=39257074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39257074</guid></item></channel></rss>