Hacker Newsnew | past | comments | ask | show | jobs | submit | barnas2's commentslogin

That's what I did. Just an esp32 relay board with a tiny screen and a knob. Then I put more esp32 sensors in each room to get individual temps, with HA logic to select which room the thermostat pays attention to. If HA dies for some reason it falls back to a local control and I'm back to the same situation as before, a thermostat that only pays attention to the temperature in the hallway it's installed in. All the boards were flashed with ESPHome.


Nice. I don't have any ESPHome thermostats right now, but I have an ESPHome fridge/freezer temperature monitor. I adopted the same idea: it should integrate with HA when HA is available, but it should be useful even when HA is down. So in addition to exporting the raw temperature to HA, the alert threshold is kept on the device rather than in HA so it can locally compute the alert state. This triggers a directly wired piezo buzzer, in addition to an HA phone notification.

You do have to set the "api: reboot_timeout: 0" if you don't want it to reboot itself every 15 minutes while HA is down. I persisted the alert threshold to flash though so even if it does reboot it comes right back up and works fine.


I built a portable meshtastic terminal using Claude and a Pico 2. It's written 100% of the code in MicroPython and it works great. It even wrote the driver for the E-ink screen I'm using. I built a jig to hold a webcam and the e-ink screen, then had Claude write a script/MCP that takes a photo and crops just the screen out. Then I asked it to figure out a driver, and after a 20 minute loop of taking photos and updating it's driver, it was done.


> Flux.ai offers a PCB design solution

"solution" is an interesting choice. I haven't talked to anyone who tried it and actually got anything useful. It completely failed when I tried using it.


A company called Taalas is working on something like that. Not Opus4.6 quality, but I'm sure they're targeting larger models. Currently they're using a LLama 8B model. It runs at ~17k tokens per second, and you can test it at https://chatjimmy.ai/.


I'm rooting for them HARD but they've been quiet since their last (and only) blog. X and LinkedIn are empty too. I really hope it wasn't a pipe dream.


It starts to be interesting when latency is better than average website.


I’m not sure if this is what you meant, but at 17k t/s, you start to compete with the speed of network calls. You could approach the point of generating an HTML/js/css page faster than some websites can be returned over the network.


When that happens, they will be able to rewrite reality in real time.


The immediate load (less than 200ms on my machine through a slow connection) is quite pleasant, tbh.


That's cool, I just tested it out and it is fast but unfortunately its accuracy is not great.


It's an 8B model. Consider it a proof-of-concept.


As someone who works in security, it's really neat that you were able to discover this with the help of Claude. That being said the "I just opened Cursor again which triggered the malicious package" message is a bit eye opening. Ideally the instant you suspected malware that machine should have been quarantined and your security personnel contacted.


I get why you say this, but real life is messy and the "fog of war" makes situations far less obvious in the moment. The older I get the more I realize how much we need scrappy, can-do people who don't always follow the "rules". Knowing the "rules" and knowing that people follow the "rules" because "that's what your supposed to do" is itself an avenue for malicious actors to exploit.


Clear procedures are the entire point of incident response plans. You follow them because of the fact that your judgement can be compromised in the moment. They re-triggered the malware payload because they decided to just dive in and handle it on their own in the "fog of war". Which would have been avoided entirely if they'd been following the standard advice to quarantine the machine and contact security so that they can investigate properly, with the developer if necessary.

Your final sentence is completely irrelevant. Blind rule adherence can be an avenue for exploit in certain scenarios, but this wasn't a case of a developer being tricked into following a bad rule. They didn't follow a real and very well justified standard practice.

The takeaway is "wow, we got lucky, we should have security people to loop in for this next time" not your weird life philosophy about how rule followers are a problem.


Isn't the entire argument for these based on the fact that people don't have an expectation of privacy in a public place? Not that I'm sure they won't try to make an excuse as to why it's different, but as far as I'm aware, you're allowed to just film in public.


This is not an issue of being filmed in public, this is an issue of not having the choice to opt in or out of the aggregated data harvesting performed by unregulated AI models owned by unregulated for-profit corporations that have no legislative oversight or safeguards.

If a human followed me around in public recording me, went through every frame and highlighted my face, my car, my license plate, dents and scratches that identify my car, where I'm going, what I'm doing, cross referencing that to other public information to build a dossier, I would have a solid case of harassment against that person. That's some stalker shit.


The bills going through Washington's legislature (where the original parent was talking about re: release via public information laws) do try and address this such that the systems aren't massive dragnets of everybody, always but far more targeted, I think.

See, for example, https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bills/Ho... which would carve out:

An agency may access, operate, or use an automated license plate reader system and its associated data only for the following authorized purposes: (a) Any law enforcement agency may use an automated license plate reader system for the purpose of comparing captured automated license plate reader data with: (i) Data on any of the following watch lists maintained by either a federal or Washington state agency: The department of licensing, the state criminal justice information system, the federal bureau of investigation kidnappings and missing persons list, and the Washington missing persons list; or (ii) License plate numbers that have been manually entered into a state or local automated license plate reader system database, upon an officer's determination that the license plate numbers are relevant and material to an investigation of a vehicle that is: (A) Stolen; (B) Associated with a missing or endangered person; (C) Registered to an individual for whom there is an outstanding felony warrant; or (D) Related to or involved in a felony. 33 (b) Any parking enforcement agency may use an automated license plate reader system for the following purposes: (i) Enforcing time restrictions on the use of parking spaces; or (ii) Identifying vehicles on a watch list for impoundment or immobilization under a local ordinance enacted under RCW 46.55.240, provided the list includes only license plates of vehicles subject to that ordinance. (c) An automated license plate reader system may be used as a component of photo toll systems authorized by RCW 47.56.795 or 47.46.105 (d) Any transportation agency may use an automated license plate reader system for the following purposes: (i) Providing real-time traffic information to the public, traffic modeling, and traffic studies such as determining construction delays and route use; and (ii) Enforcing commercial vehicle systems at Washington state patrol enforcement sites and weigh stations.

That said, the only thing that really stops them from being massive dragnets of everybody always would essentially be how they're configured, which obviously can change. I think we've seen enough misuse of systems and tools throughout history that it's worthwhile to be mindful of creating easily misused systems and tools.


>Poker players have intuitive sense of the statistics of various hand types showing up, for instance, and that can be a useful clue as to which build types are promising.

Maybe in the early rounds, but deck fixing (e.g. Hanged Man, Immolate, Trading Card, DNA, etc) quickly changes that. Especially when pushing for "secret" hands like the 5 of a kind, flush 5, or flush house.


> You could make the argument that Patreon isn't much more than a banking app.

Don't give them any ideas.


I'm curious if you tried binwalk? That's usually my goto for mysterious files.


I agree. It would likely have identified the separate deflate and zstd chunks automatically.


Never thought about using that, thanks for the tip!


that is a good one. Will try that next time.


I don't smoke/vape, but I saw some pretty absurd models available recently that really piqued my interest. One had a touchscreen, could run some basic apps, and had wifi/bluetooth support. The other had a d-pad + buttons built in and a few ripoffs of classic games you could play. I bought one of each to start ripping them apart on my work bench and playing with the firmware. Unfortunately I got busy and haven't done much more than look at the internals. They're using some sort of cheap smart watch SoC. It's wild you can get a battery, touchscreen, charging circuit, and a microprocessor for like $12.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: