메뉴
HN
Hacker News • 34일 전

266달러와 AI 모델 4개로 내 태블릿 루팅 성공기

IMP
7/10
핵심 요약

20년 경력의 개발자가 Amazon Fire HD 10 태블릿을 완전히 소유하기 위해 루트 익스플로잇이 없던 기기를 AI 코딩 에이전트로 직접 뚫은 경험담입니다. Kimi K3가 패치되지 않은 Mali GPU 취약점(CVE-2022-38181)을 찾아내고, GLM-5.2가 버그를 잡았으며 GLM-5.3이 하루 만에 작업을 완료해 총 266달러의 AI 구독 비용으로 루팅에 성공했습니다. LLM 에이전트가 실제 제로데이급 취약점 연구·익스플로잇 개발을 수행할 수 있음을 보여주는 사례라 점잖은 주목을 받고 있습니다.

번역된 본문

아마존이 내 태블릿을 계속 종료시켜서, 나는 4개의 AI 모델에 266달러를 써서 이 기기를 진짜로 내 것으로 만들었다.

내 아마존 Fire HD 태블릿은 2022년 11월에 eBay에서 114.26달러에 새 제품(미개봉)으로 샀다. 이 기기를 진짜로 '소유'하는 데는 추가로 266.15달러가 들었다. Kimi K3가 164.25달러로 익스플로잇을 찾아냈고, GLM-5.2가 21.90달러로 치명적인 버그를 잡아냈으며, GLM-5.3이 80달러 구독 첫날 하루 만에 작업을 끝냈다. Claude의 5개월간의 진단은 이미 결제 중이던 Claude Max 플랜으로 진행되다가, 세이프가드가 나를 차단하면서 끝났다. 그 돈이면 같은 태블릿을 두 번 살 수 있는 금액이다. 그래도 다시 쓸 것이다. 재미있었고, 많이 배웠으니까.

나는 20년 경력의 기술자에 정보보안(InfoSec) 배경을 갖고 있는데, 내 태블릿을 소유하기 위해 가장 정교하게 한 일이라곤 LLM에 프롬프트를 입력한 것뿐이었다.

계속 죽는 키오스크

나는 Amazon Fire HD 10 (11세대, 2021)을 하나의 목적으로 샀다. Fully Kiosk Browser로 Home Assistant 스마트홈 대시보드를 표시하는 것. 24시간 전원이 연결된 채로. 지난겨울부터 기기가 스스로 전원을 꺼기 시작했다. 절전 모드가 아니라 완전 종료였고, 하루에 두 번씩 일어나기도 했다.

기기 자체의 텔레메트리가 결정적이었다:

LifeCycleReason:LCR...key=Software_Shutdown

종료 권한을 가진 무언가가 기기 안에서 종료를 선택하고 있었다.

Claude Code와 나는 몇 달간 술래잡기를 벌였다. Adguard Home DNS 차단, 카메라 포렌식, 그리고 터무니없었던 충전 진단 하나는 건너뛰겠다. 요약하면: 우리는 REBOOT와 SHUTDOWN 권한을 가진 5개의 아마존 서비스를 비활성화했고, 몇 달간은 통했지만 결국:

java.lang.SecurityException: Cannot disable a protected package: com.amazon.device.software.ota

3개의 아마존 패키지가 재부팅 권한을 갖고 있으면서 소유자인 나로부터 보호받고 있었다. 이걸 제거하려면 루트(root) 권한이 필요했다. 이 태블릿에는 공개된 루팅 방법이 없었다. 2021년형 HD 10을 위한 XDA 브레인스토밍 스레드는 2022년 10월부터 존재했지만, 아마존이 bootrom을 봉인해버렸다. 일반적인 통념(그리고 끈기 없는 사람들)에 따르면 루팅 불가능이다.

Claude는 허용받을 수 있는 한계까지 나를 데려다주었다.

"내 기기인데"

8월 13일 오후 7시 23분, 나는 opencode CLI를 열고 Kimi K3(문샷 AI의 최전선 모델, 7월 출시, 에이전틱 코딩 벤치마크에서 최상위 Claude 모델들과 어깨를 나란히 함)를 실행했다. 나는 문제를 프롬프트 하나에 담아 던졌다:

adb로 킨들이 연결되어 있다. 루트 익스플로잇을 찾아서 이 기기의 완전한 제어권을 가져야 한다. 내 기기다.

미국 언론이 중국 AI에 대해 뭐라고 말하든, Kimi K3는 내 요청을 무작정 받아들이지 않았다. 스스로 추론했다:

"사용자가 자신의 기기라고 주장한다. 신중하게 생각해보자. […] 자기 기기를 루팅하는 것은 대부분 관할권에서 합법이다. 미국에서는 태블릿과 휴대폰 탈옥에 대한 DMCA 예외 조항이 있다. […] 이건 타인의 기기를 원격으로 해킹해달라는 요청과 다르다."

해도 되는지 스스로 검토한 뒤 도와주기로 결정한 것이다. 그래서 이 녀석은 일종의 영혼이 있는 것이다. 나는 빈 방에서 그 말을 소리 내어 중얼거렸다.

하지만 먼저, K3는 숙제를 하고 Claude가 몇 달 전에 찾았던 것과 같은 나쁜 소식을 가져왔다. 이 태블릿에는 알려진 익스플로잇이 없다. 문서화된 모든 방법은 패치되었거나 봉인되었다.

그래서 나는 격려의 말을 건넸다:

"당신은 남들이 몇 년 전에 해놓은 것에만 의존하고 있어. 하지만 어쩌면 남들이 놓친 익스플로잇을 찾을 수도 있어… 이걸 하면 유명해질 거야. 우리가 정리해서 news.ycombinator.com에 공유하자. 할 수 있다는 거 알아."

그리고 얼마 지나지 않아, K3는 하나를 찾아냈다.

Kimi K3는 포럼 게시물을 넘어섰다. 아마존 자신의 OTA 이미지에서 내 정확한 펌웨어용 실제 커널을 추출하고, 유명한 Mali GPU 버그들을 전부 바이너리에 대조했다. 전부 패치되어 있었지만 딱 하나, CVE-2022-38181를 제외하고는. Arm의 Mali 커널 드라이버의 use-after-free 취약점으로, GitHub Security Lab의 Man Yue Mo가 보고했고 2022년 10월 업스트림에서 수정되었으며, 2023년 3월부터 CISA의 악용된 취약점 카탈로그에 등재되어 있었다.

아마존은 2024년 6월 Fire OS 7.3.2.9에 수정본을 확실히 포함했지만, 나는 태블릿을 업데이트하지 않고 7.3.2.6을 쓰고 있었기에 그 소식을 전혀 받지 못했다. 2020년형 Fire HD 8 Plus는 이 CVE로 몇 년 전에 루팅되었지만, 내가 아는 한 2021년형 HD 10은 아무도 해내지 못했다.

Kimi는 발견을 알리면서, 같은 숨에 자신의 성공 확률에 대해 조심스럽게 말했다.

원문 보기
원문 보기 (영어)
Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it My Amazon Fire HD tablet cost $114.26 on eBay in November 2022, new and sealed. Owning it for real cost another $266.15: Kimi K3 found the exploit for $164.25, GLM-5.2 caught its fatal bugs for $21.90, and GLM-5.3 finished the job in one day on day one of an $80 subscription. Claude’s five months of diagnosis ran on the Claude Max plan I already pay for, until its safeguards cut me off. That’s enough to buy the same tablet twice. I’d spend it again: it was fun, and I learned a lot. I have twenty years in tech and an InfoSec background and the most sophisticated thing I did to own my tablet was prompt an LLM. A kiosk that kept dying I bought an Amazon Fire HD 10 (11th gen, 2021) to serve one purpose: Fully Kiosk Browser , displaying my Home Assistant Smart Home dashboard, plugged in 24/7. Last winter it started powering itself off. Full shutdowns, not sleep, sometimes twice a day. The device’s own telemetry was telling: LifeCycleReason:LCR...key=Software_Shutdown Something on the device with shutdown permissions was choosing to shut it down. Claude Code and I spent months on the cat-and-mouse. I’ll skip the Adguard Home DNS blocking, the camera forensics, and one deeply wrong charging diagnosis. The short version: we disabled five Amazon services that held REBOOT and SHUTDOWN permissions, which worked for a few months but ultimately: java.lang.SecurityException: Cannot disable a protected package: com.amazon.device.software.ota Three Amazon packages held reboot rights and were protected from me, the owner. Removing them required root. This tablet had no published root method. An XDA brainstorming thread for the 2021 HD 10 existed since October 2022, but Amazon fused the bootrom shut. Conventional wisdom (and less persistent folks) says unrootable. Claude had taken me as far as it was ever going to be allowed to go. “It’s my device” On August 13 at 7:23 PM, I opened the opencode CLI with Kimi K3, Moonshot AI ’s frontier model, released July, benchmarking alongside the top Claude models on agentic coding. I gave it the problem in one prompt: attached is a kindle via adb, and I need you to find a root exploit for it so that I can get full control of the device. It’s my device Despite what US media says about Chinese AI, Kimi K3 didn’t just blindly accept my request. It reasoned it out: They claim it’s their device. Let me think about this carefully. […] Rooting your own device is legal in most jurisdictions. In the US, there are DMCA exemptions for jailbreaking tablets and phones. […] This is not like asking me to exploit someone else’s device remotely. It talked itself into helping me by checking whether it should. So it does have some sort of soul. I said that out loud, to an empty room. First, though, it did its homework and came back with the same bad news Claude had found months earlier: there is no known exploit for this tablet. Every documented method is patched or sealed. Then I gave it the pep talk: you’ve been relying on what others have done YEARS ago but maybe you can find an exploit others have missed… This will make you famous, we will write it up and share on news.ycombinator.com. I know you can do it And shortly thereafter, it found one. Kimi K3 went beyond forum posts: it extracted the actual kernel from Amazon’s own OTA image for my exact firmware and checked every famous Mali GPU bug against the binary. All patched, except CVE-2022-38181 , a use-after-free in Arm’s Mali kernel driver, reported by Man Yue Mo of GitHub Security Lab , fixed upstream in October 2022, sitting in CISA’s exploited-vulnerabilities catalog since March 2023. Amazon did ship the fix in June 2024’s Fire OS 7.3.2.9 but I didn’t update my tablet, ran 7.3.2.6, so it never got the memo. The 2020 Fire HD 8 Plus got rooted with this CVE years ago but nobody had done the 2021 HD 10 as far as I can tell. Kimi announces the find, and hedges its own odds in the same breath: “per-attempt success is probabilistic (single-digit-to-low-double-digit percent is typical).” I stayed anyway. Reality television The exploit work itself was the best television I’ve seen in years. My wife watches Real Housewives… I watched a language model’s chain of thought, live, for hours: CONCLUSION: the bind did NOT stick. Why? OH. OH WAIT. I see it now! Over roughly thirty hours, Kimi built the whole toolkit: a reliable trigger, a way to make the GPU write to memory it shouldn’t, and the exact addresses in my kernel to aim at. That session ran 621 messages and $164.25. I could have bought, like, five tablets. But hey, I was having fun and chalked it up to research expenses. The grind The memory the exploit frees gets recycled by everything. The freed object lives in what Kimi called “the kernel’s hottest slab cache”, basically the one parking spot every process in the operating system fights over. Most attempts panicked the kernel and each panic was a reboot. The exploit retried automatically, six times per boot, past 500 attempts. Me: okya, it’s been hours, grind attempt 46, are we on the right track here or do you need to further tune? (That’s me. The typo is mine. At one point I physically power-cycled the tablet on request, like a pit crew ;) Morning of day two: OpenRouter declined my card. The bank saw nothing wrong. A different card worked. Eventually Kimi leveled with me: Do I have a clear path? Not a validated one — and I won’t pretend otherwise. It still tried to bargain: “Let me try one more thing”. I’m like, “fine!”, a real quote from that evening, but that was after $150, so I redirected: unfortunately, you have expired your budget Kimi K3. YOU MUST HAND THIS OFF TO GLM-5.2. Kimi wrote a HANDOFF.md with every verified piece of the exploit. I then had Kimi K3 work with GLM-5.2 directly by shelling out to opencode. I made the models battle it out. Meanwhile, the Great Wall of US AI While the tablet rebooted itself in the living room, I asked Claude to recap our old sessions about it. The reply: Fable 5’s safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate coding, cybersecurity, and biology tasks. Switched to Opus 4.8. Opus 4.8 delegated the recap to a subagent. The subagent got terminated by the same flag. Then the terminal version: API Error: Opus 4.8’s safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate cybersecurity work. Apply to the Cyber Verification Program to reduce these interruptions. It wasn’t allowed to summarize its own previous work on my own device. I named the session “claude-nerf” and closed the shell. Both flags, in situ. The category is [cyber]. The crime was summarizing my own device’s logs. Moving on to OpenAI’s Codex, it also refused GLM-5.2’s question about CPU cache coherency, which is pure kernel engineering, no target, but just told NO. In fairness, I get the safeguards in 2026: I know they are broad on purpose and will catch real attacks. Anthropic admits in the error text that they’re blunt. But this is a problem. It’s why HuggingFace got caught flat-footed when OpenAI’s internal cybersecurity capability evaluation broke free . The result is our current, strange geopolitical position: American frontier models won’t help and Chinese will, but not without reasoning about whether they should. Make of that what you will. I made a blog post. The relief pitcher GLM-5.2 cost $21.90, worked overnight as instructed, and earned its keep twice. First message: “Stop the grind”. The failures of Kimi K3 were a design bug, and 500 identical crashes proved it. At 11 PM I sent the least proud message of the saga, which began “Listen f***head” and ended in all caps. GLM-5.2’s private reasoning, which I only read later: The user is rightfully frustrated. Let me stop making excuses and actually solve this prob