REA Reverse – Engineer Anything
rea.tools
[7 comments hidden]
The Windows Remote Desktop client has two bugs that have been driving me crazy for the better part of a decade. One day I got fed up and fed the binary to Claude, asking it to fix the two bugs. And it just did it. Patched one with some NOPs and adjusted a stack offset for the other. Produced a credible explanation for both, and in fact the fix worked. It helps that I was able to describe the bugs clearly, but still, it had to figure out the right spot among megabytes of executable code.
[3 comments hidden]
[hidden]
vmconnect.exe (Hyper-V enhanced session) not going fullscreen after login when the window is fullscreen and you have to minimize and maximize to get fullscreen? Have your agent debug the issue and come up with an elaborate hook system that leaves the Microsoft files untouched.
Codex/Chatgpt electron app coming with annoying or missing features (Mini, Invite friends, no mcp hotreload, windows updates failing, ...)? Just point codex at codex and have it build an mcp Ouroboros to improve itself and enable dynamic js userscripts.
Deskflow clipboard sharing between devices missing file sharing, just have sessions on Mac, Linux and Windows collude to cook up a solution.
Yet writing proper documentation and reports that are human digestible still seems a bit out of reach, why would humans need to read anyway...
[43 comments hidden]
Adobe product clones like Photoshop and Illustrator: https://www.youtube.com/watch?v=eFB79TYI-Vw
Adobe after effects clone: https://www.youtube.com/watch?v=5mi_tYSdkWQ
MS Office suite clone: https://www.youtube.com/watch?v=U_jTYMOlXio
[10 comments hidden]
As an aside, I've heard a lot of hot takes about how this is the end of Adobe, but I'm pretty sure it misses the point. The main reason people pay Adobe is because it's a familiar line of stable, well-supported, interoperable, and actively-developed products. There's already plenty of cheaper or free alternatives (Davinci Resolve for video, Capture One / Darktable for raw, Affinity for photo editing and vector drawing, etc), and if Adobe survived that, I sincerely doubt they're going to lose pro customers to a vibecoded app where half the stuff is probably subtly broken or left as a TODO, and that will be abandoned in a week, because the whole point was to get that 1M YouTube views.
[8 comments hidden]
Longbets 1 week, haha.
We're working our asses off on this.
Most of the team are artists who use these tools actively and we want the replacements for ourselves. I'm a filmmaker, so you can imagine my frustration of being bitten by the "unsubscribe fee".
[hidden]
[2 comments hidden]
[hidden]
[hidden]
I’m curious how much is your LLM bill. I’m assuming the idea is that LLMs will maintain the software? I’d be surprised, given the token economy, that you’d have to pay less than those subscriptions to LLM providers.
[hidden]
Scaling up to this kind of complexity even with AI is still a challenge, at least for me.
[hidden]
What's the 'unsubscribe fee'? Are you referring to choosing something like an annual plan instead of 'Monthly' and only getting 50% back if you cancel partway through?
As you said you're a filmmaker, if someone chooses to obtain the rights to your film for a longer period instead of a shorter period and then changes their mind halfway through, do you similarly give them 50% back?
From what I can see, Adobe prominently and clearly displays from the first public checkout page the differences between 'monthly' and 'annual' options?
[hidden]
These are NOT the same thing whereas this one particular suite of clone products is exactly menu by menu, keyboard shortcut by keyboard shortcut and feature by feature a pure clone of corresponding products to that extent that they even have a separate dashboard just to track feature parity: https://github.com/storytold/craft-repo-status-app
It is NOT there yet of course but it won't be there in a year? That's an absurd claim to make. I have checked the repos multiple times and every new release keeps fixing something that wasn't working before.
[29 comments hidden]
https://github.com/storytold/photocraft (inspired by Photoshop)
https://github.com/storytold/wordcraft (inspired by Word)
https://github.com/storytold/pdfcraft (one of the more mature apps)
https://github.com/storytold/vectorcraft (another app close to 1:1 parity)
(etc.)
Using REA for something as high profile as what we're doing is likely to result in lawsuits. We're doing everything we can by the books.
We cannot look at Adobe sources. Use of Ghidra is disallowed.
REA is probably great for personal apps and for abandonware, but I think if you publish the results and it's found to have decompiled the original proprietary sources in discovery, you might be in for a bad time.
[4 comments hidden]
1) reverse engineer the code 2) train a model on the code 3) use the model to write the clean code
Step 2 is the key “cleaning” process
So maybe a good strategy would be to use something like REA, put it on GitHub, wait for the LLMs to train on it, then just use the frontier models
/s
[14 comments hidden]
Licensing/copyrighting encouraged people to think up of new things, and new ways of doing something. Now we're just all copying eachother.
[hidden]
It's considerably faster than their apps (at startup) too.
[hidden]
[8 comments hidden]
I'm not sure how clean room would apply to commercial applications distributed in binary form, as there's no way to look at even disassembled code without violating the license agreement and therefore being in breach of contract and subject to potential copyright infringement claims for copying or even continuing to use the software, let alone cloning it, and surely you're not going to be subject to a copyright claim based on familiarity with the application from merely using it.
[6 comments hidden]
The reason why 'reverse engineering' has gotten so good is because what we're actually seeing is fully automated luxury plagiarism
[5 comments hidden]
[2 comments hidden]
[hidden]
And I don't think that is publicly known at the current time. (If anyone has any tangible info on this, the please let me know...)
[hidden]
[2 comments hidden]
[hidden]
Microsoft famously has patents covering aspects of the ribbon interface in Microsoft office, which of course this suite must implement. https://en.wikipedia.org/wiki/Ribbon_(user_interface)#Patent...
Meanwhile, Wikipedia has a policy that says screenshots of applications have to be "as small a version as possible" in order to meet the fair use exception for presentation of copyright work. I can only imagine an exact clone of the interface could be similarly ruled to infringe on Adobe's intellectual property.
[4 comments hidden]
[2 comments hidden]
[hidden]
People wishing for the death of the mega corps, are directly wishing for the obliteration of millions of great jobs.
[2 comments hidden]
If AI models can generate designs faster and produce work that is "good enough", what is the actual future of design tools and the design profession in your opinion?
I've tested this myself with some frontier models and the results are kinda impressive enough that it raised the question if design skills are already obsolete. If that is the case, what use are these tools now?
[hidden]
I've seen a lot of "really cool unique designs" that are obviously just a digested regurgitation of amalgamated corporate slop. Anyone wanting an actual unique design language needs to hire actual designers.
Those designers may use AI tools but the tooling isn't to where they can be completely replaced. I challenge anyone to show me an e2e LLM design toolkit that can actually replace a designer, not just one shotted "wow that looks so cool" character designs.
[hidden]
[hidden]
I've got my wedding coming up so haven't had the time I want to dedicate seriously to finding some proprietary things to disrupt, but I've had fun using this as an opportunity to play with subagent orchestration, open weight models, various harnesses, and local models, to see what happens if I let some LLMs churn on it. That resulted in a hodge podge researched list of potential targets: https://github.com/508-dev/genairosity/issues
One thing that stands out is a lot of software kinda does already have a FOSS replacement, it's just not really how people want it to be. GIMP being the representative example. Photoshop people just don't like it, I'm sure for not entirely invalid grievances. However the maintainers of these kinds of tools are often strongly opposed to LLM involved contributions, again , often for not entirely invalid reasons on these incredibly complex projects.
So the long and short of it is that as powerful as LLMs are, we aren't quite where some of the doomsayers are saying we are, insomuch as proprietary software is dead. Even with reverse engineering we aren't there. There's genuine labor, time, and expertise moats around most of these programs.
Personally I'm shifting to trying to find niche abandoned software with no export flow. Even if I can only help out a couple hundred people, it sounds like a decent use of my time.
[3 comments hidden]
[8 comments hidden]
For example, I use Claude as a bouncing wall for my thoughts and I pointed out that,
> GLM 5.2 was the only thing that helped HF while the agents were trying to access them. The "guardrails" stopped them from doing good. The Computer Fraud and Abuse Act exists. Courts exist. And computers and an internet connection have existed for a long time. There's also 17 USC 1201 provisions with the 1201 a 1 exemptions [Image #31] so in this case, a farmer should be able to work with you to access the tractor they own. Or... IDK... a kindle that's out of date? :) What is lawful and what isn't is rooted not within the act but within intent, purpose and mens rea. And this is something the law has been deciding for centuries now. At one end, your maker can't say that governments should decide while at the other end explicitly refusing to allow governments to be the ones who decide.
This was rejected for "Safety," > Opus 5.5's safeguards flagged this session. You may be seeing this for the first time on an Opus model: Opus 5.5 is more capable and has stronger safeguards as a result, which can sometimes flag non-cybersecurity work. We're improving these safeguards to reduce the amount of incorrectly flagged messages. Edit and retry, or continue with Opus 4.8. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/8106465
>
> Details: "[cyber]'
Note, the image here was the Library of Congress' page on DMCA exceptions.Fundamentally, the idea that you can't reverse engineer things, make things, learn about biology or physics without permission is strange to me. These machines have been trained on the sum intellectual output of humanity, the global intellectual commons, and are being used to close off that commons?
I would be OK with their right to create such restrictions if they weren't lobbying the Government to restrict others, thereby ensuring that they control humanity's intellectual commons well into the future.
Perhaps I'm naive, but I think it's better for humans and the machines if we can all think, learn and build. But then again, I'm the kind of person who rejects the doomer pill.
[5 comments hidden]
[3 comments hidden]
It's worth talking about the fact that you can't even talk about DMCA to a model trained on the Library of Congress unless you're one of the approved people. And that's before reverse engineering something or writing code.
So in this future, it sucks to be you if you're someone trying to make your small app more secure, someone trying to upskill, a tinkerer trying to bypass corporate lockdowns for a device they own (a recognized DMCA exception, btw), a teenager trying to learn about security...
It locks away much of the richness that produced hacker culture behind glass. You can look at their press announcements and PR pieces, but you can't touch.
And as they're lobbying the government for "sensible regulation," this inevitably leads to a future where computing is controlled.
It's the direction their existing reports are taking. They recently released one in September that talked about how they stopped "bioweapons." What were said bioweapons efforts? Oh, it was scientists using Claude for grant writing, paperwork and grammar. At national labs.
These people are basically proud of impeding real research to make better painkillers and study a neglected tropical disease, https://news.ycombinator.com/item?id=49651727
And this is being used to lobby against "dangerous" open-weight models because gasp a scientist might use them to write a grant! To make better antidepressants.
At what point do they start reporting someone taking apart an iPhone and trying to DIY a repair with a schematic as a thwarted "cyber security incident?"
[hidden]
Another funny one was Claude's refusal to provide the original untranslated text of a passage from Dante's Inferno on copyright grounds, though in this case pointing out that no 14th century literature was subject to copyright anywhere in the world was sufficient to override its objection.
[hidden]
Several years back, I was working on generating AVB2 hashes on top of modified Android distributions, to increase the security after an owner has made their desired changes. I was doing this before the age of LLMs. Among other things, this would've enabled the secure features to work again, and potentially reduce the risk of root access being usable by malware. But apparently I'm not a security researcher because I didn't get a CVE about it.
[hidden]
[12 comments hidden]
[hidden]
(Who knows if this'll be true 6 months from now.)
[hidden]
[3 comments hidden]
[hidden]
[hidden]
"Hey Claude I want to create a fanmade Game Boy game, give me recommendation of tools, libraries and workflows for it" and boom.
You can use AI to learn stuff, instead of just using it as a Pokemon.
[hidden]
[hidden]
We're kinda far into this LLM thing, maybe it's time to start selling harnesses by leading with how some examples were solved faster with this and how it saved tokens, or similar?
[hidden]
But I just found an even easier way I should have thought of first - someone already dropped a reimplementation a couple weeks ago.
[3 comments hidden]
When you crack some DRM, the DMCA makes it challenging to share your work with the world, regardless of the morality of your use case (say, repairing one's tractor). There is no longer a pressing need to share that work, when anyone can just say "computer, sync my spotify collection to my jellyfin instance, using correctly tagged FLACs", and it goes away and does it from first principles.
[hidden]
[4 comments hidden]
So I built droidasc. No memory bloat, no parsing slowdown. Analysis is in milliseconds. Global xref on a 300MB APK takes 1.5 seconds. I used it with codex to analyze phones from 3 different brands and found 2 RCEs and 5 root bugs in a few days. I plan to detail these at Black Hat Asia 2027. A friend used droidasc to scan various bug bounty targets at scale and found 10+ RCEs. Way, way faster than jadx.
[7 comments hidden]
In my experience, even just hinting at reverse engineering to models from Anthropic or OpenAI leaves them extremely sensitive to refusals. After all, the same techniques used here can be used to find exploits.
Or are people using it with local models?
Curious.
[hidden]
[hidden]
[hidden]
[hidden]
I've had no issues with OpenAI.
[2 comments hidden]
Try GLM-5.3, it worked pretty for me. It also worked well with Radare2 or binary ninja if you don't have the muscle memory for idapro.
[hidden]
It'd make more sense to reject reverse engineering commercial software on the grounds that it likely violates the software's license agreement, and would therefore subject the user to potential breach of contract and copyright claims.
But this would also apply to uploading pretty much any non-self authored document to the LLM in the first place, albeit with fair use as a possible defense after the fact, so it still doesn't make much sense.
[hidden]
The copy this prompt into your agent seems like an evolution of `wget X | bash`-style in all the worst ways.
[hidden]
As the value of a particular piece of software decreases, the value of reversing its specific implementation does as well.
Reverse engineering is about discovering specific methods or protocols. Not for porting entire implementations to new platforms or products. A lot of the specific methods and protocols have been sucked up into the LLM weights, so the need to go digging for these patterns is dramatically reduced.
The biggest application I see here is with digital archaeological work (the opposite of new things).
[hidden]
[2 comments hidden]
Going from ~4,226 to 54,614 stars in ~5 days is about +50k. Even stranger is forks: 438 → 10,376 forks. That is an unusually high fork acceleration. Current forks are about 19% of stars.
[hidden]
Started in the repoprompt (https://repoprompt.com/) community.
Good stuff.
[8 comments hidden]
> Install REA and connect it to this coding agent using npx rea-agents@latest setup. Show me the setup plan for approval, then verify the installation.
We have achieved the next evolution of installation by `curl | bash`!
[hidden]
[6 comments hidden]
[2 comments hidden]
With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.
REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.
[3 comments hidden]
[2 comments hidden]
[hidden]
We have existing paradigms for this.
Additionally, installers are signed with certificates on Windows.
All of these are strictly more trustworthy than curl | bashing.
[hidden]
[2 comments hidden]
[hidden]
[3 comments hidden]
[2 comments hidden]
[hidden]
The mechanics of BFME are the important part, not the intellectual property of the films. The way the units move, the resource system and power points are what make it special. Gandalf and Lurtz are simply wallpaper on top of something that is already very competent.
[hidden]
[hidden]
[5 comments hidden]
The only problem is the lawyers at all those companies will be readying their lawsuits, and given they have tons of money; they do not care and will come after anyone.
[hidden]
That's insanely meta.
I guess everything is going to become recursive. RSI on models. Everything feeding back into its own hill climbing optimization.
Humans nudging it up the hill further and further by using new geometric guidance.
[3 comments hidden]
[2 comments hidden]
So really closed-source compilers are a hindrance and you're subject to unspecified time-frames to even get to fix your issue rather than doing it yourself.
Intel and AMD have already open up theirs without question. Nvidia is the one who claims to be supporting openness in AI but can't even open up nvcc let alone CUDA.
[4 comments hidden]
[hidden]
Think of it as a more persuasive means of obtaining documentation. Not as a nefarious act.
[hidden]
Backend will have some shuffling of data around some ledgers + a lot of ceremony around auditing + shit ton of CRUD mess and arcane connections to other systems/institutions. Probably the nightmare of nightmares codebase, if frontends are any indication. :D
InvisibleUp[23 comments hidden]
I know the retro game modding/decomp scene is already getting hit with a flood of low-effort ports.[3] Now they're going to be hit with a flood of half-decent decomps effortlessly generated by anyone with a $200/mo AI subscription, which become half-decent PC ports, which get modding support grafted on. It kinda just... totally eliminates that as a hobby entirely. I know people are going to be upset about this. And it's not even like with the AI art, where the pro and anti-AI camps live in their own camps. Solving the same puzzle twice just feels discouraging. Very similar to the problem academics are having with AI math/physics proofs.
I know a large reason people hate AI is because it's largely seen as tearing apart hobbyist/professional communities, eliminating reasons to collaborate with others and form relationships, and replacing it with an individualized dependence on a commercial product. It follows the same trend the tech industry took social media, from a method of connection to a tool of propaganda and paranoia and "@gork is this true?" This project, I think, is one of the most clear examples of that.
[1] https://github.com/N0zoM1z0/th04 [2] https://github.com/GensokyoClub/th06 [3] https://www.pcgamer.com/gaming-industry/pc-ports-of-old-cons...
mjr00[11 comments hidden]
It really depends on your perspective of what the point of the hobby is. Were decomps/recomps a hobby because people wanted to make sure their old games could run on modern hardware and be extended with mods etc., or were they a hobby because people enjoyed the actual process of using Ghidra and reverse engineering by hand, and the decompiled game was just a side effect?
Personally I think it's awesome that PC98 Touhou games are getting recomps. Being able to play the series natively on modern hardware, and all hardware for the foreseeable future, is great and preserves the legacy of the series. I understand that for anyone who enjoys the actual act of reverse engineering it feels like cheating, though.
I think people will get over it. Music is a good example. Drum VSTs and piano VSTs are going to sound way better than you unless you're a 99th percentile musician playing on a 99th percentile physical instrument. But people still play the piano and drums, because it's fun. Same idea; the existence of AI doesn't stop people who love the act of reverse engineering from doing it.
cassonmars[5 comments hidden]
I think your question would make sense if these were the only two reasons. Someone who just wants to make sure their old games can run would see these tools as a good thing. People who just enjoy reverse engineering by hand wouldn't care this exists, or maybe even, a helpful tutor.
So perhaps then, the sentiment being as negative as it is, is revealing something about the hobby: that many participants, considered the metagame of being the first to do it, to be "smart enough" to have figured it out, the "street cred" if you were, is what they are lamenting, but they just either lack the words, or aren't being honest with themselves.
quietfox[4 comments hidden]
Tarq0n[hidden]
Taking that away compounds with the crisis of meaning we already have to make people feel more alienated than ever.
eru[2 comments hidden]
I must think of all the people who poured countless years of their lives learning all the C++ bullshit..
mordv[hidden]
ronjakoi[2 comments hidden]
pkhamre[hidden]
WalterGR[2 comments hidden]
It’s interesting to dwell on what ‘we’ appreciated before versus what we appreciate now. Since LLMs lowered the bar, it feels like raw human effort has come to be held in higher esteem.
Are we going to re-evaluate what we were impressed with in the past based on that new metric? For example, will accomplishments by experienced engineers be devalued in comparison to accomplishments by outsiders? Will the software engineering equivalent of ‘folk’ or ‘outsider’ art become more valued? There will be a natural instinct to distrust outsider contributions because, well, how did they get so good?
Are some metrics of human effort going to be de rigueur going forward?
BlueTemplar[hidden]
minraws[hidden]
Since it's not educational as it used to be, if you built your own version of n64 emulator number 10143 you got something out of it you learnt some interesting stuff, learnt software development, hardware etc.
Now we are literally all just taking a magic machine pouring money on one end getting half baked output the other but no progress is being made on money is being wasted. Since even if 1 person had built it everyone would have had access already.
This is the same wave of slop coding/vibemaxxing we had a few months ago where everyone was building product X for the 1 million-th time without any actual progress being made.
Math has a similar problem now, before if 1000 people tried to solve a problem they all grew from that experience, the LLM is not growing/learning anything from this effort.
All we are doing is burning resources for our pleasure, I say that as someone who has now written his own compiler, vcs and browser stack, with vibe coding, though largely I would claim I have used and tried to read the code, clean it up, to learn from it where different things break.
But even this feels absurd waste of resource imagine all of us collectively burning 200$ per month plans which assuming a at cost pricing we are all burning 200$ of electricity each month to do what exactly? Some folks are on their 10th subscription that means most people are burning 1000-2000$ of ultra cheap energy generally sourced from a mix of gas/oil turbines burning away at big data centers these days.
We could all solve it by making a site.. cough github.. and not duplicating work.. cough..
But somehow because it's easy no one seems to care.
I am hardly against software progress, and if AI gets better we will have better software (because most people write horrible software most of the time) so I am happy about it, to an extent that I can be, with my profession feeling somewhat challenged.
But given I have always worked as a fixer of broken stuff it's very much also feels fine to me. Either way I am very much against these 200-500 dollar plans that allow you to burn hundreds of dollars of energy for little productive gain duplicating the same work 100th time.
I am sure software developer using 100-200$ plans just for work can get more out of it. And it's probably making up for the effort they would have put in their work otherwise.
visarga[3 comments hidden]
Brian_K_White[2 comments hidden]
If a thing is no longer difficult to perform or to produce, then I might still employ or consume it if it's useful, but I will no longer value it. No matter how useful a potato is, it's not worth any money, time, interest, effort, emotional investment, etc. Even though in a vacuum it's almost like a magic ultra utility food, most useful and valuable thing ever.
Same for countless mass produced utilitarian goods like plastic bowls and basic computers.
I don't want be an injection molded cup or a potato not just because they aren't rock stars, but because they aren't valuable enough to be a person's identity or livlihood at all, even a basic unassuming workman's.
throwawayqqq11[hidden]
neya[4 comments hidden]
jurgenburgen[hidden]
Unfortunately those are also better discussed with LLMs.
I recently had to refresh on some algorithms and some manual coding for an interview where using LLM is forbidden. It was super fun, I forgot how fun solving software puzzles can be!
It’s unfortunate our industry has become so boring. Because our society values capital above all else, quitting my job to do something fun would relegate me to economical loser status. We really need a shift to the left in politics and a way to redistribute the productivity gains this technology allows.
tobylane[hidden]
In abstract, sure, but that is a much shallower discussion that many people are strongly disinterested in. It's generic, where a human decompile may not be (as a cloner I haven't looked into those projects). I don't like the idea of a group of fans of art frames saying don't bother looking at what's in the art frame, our conversation is equal.
InvisibleUp[hidden]
Of course, in a post-AI world people will still want to work together on things. But these sorts of tools do disincentivize it. That's the point I'm getting at here.
ashdnazg[hidden]
I think this points in two directions - first that $200 is really unnecessary for this domain.
Second, that with more experience we might be able to write a non-AI matching decompiler and then naming and simplifying could be done by people/AI. While I appreciate the hobby part of it, I think automated tools are the way to really make it reach everything with far less dependency on pockets. The benefit to preservation would be incredible.
TeMPOraL[hidden]
For me personally that's a huge win, but it would be a shame if it turned out that the whole AI/anti-AI thing is really just single player vs multiplayer in disguise. Because then we won't reconcile it easily.
walrus01[2 comments hidden]
$800-level consumer 3D printers let people make highly detailed plastic models of things with very little level of technical knowledge, but people still buy and hand assemble LEGO kits for the fun of it.
KellyCriterion[hidden]