Project ideas from Hacker News discussions.

REA Reverse – Engineer Anything

📝 Discussion Summary (Click to expand)

1. AI‑assisted reverse engineering is increasingly capable and useful
- “Glancing at the Touhou 4 decomp[1], it's a lot better quality than a lot of AI decomps I've seen.” – InvisibleUp
- “Reverse engineering is about discovering specific methods or protocols… A lot of the specific methods and protocols have been sucked up into the LLM weights…” – bob1029
- “I built droidasc… Global xref on a 300MB APK takes 1.5 seconds.” – mgaldys4

2. Legal, ethical, and IP concerns dominate the conversation
- “Fundamentally, the idea that you can't reverse engineer things… without permission is strange to me… These machines have been trained on the sum intellectual output of humanity… being used to close off that commons?” – areoform
- “Using an LLM is not a clean room, imo. Its just IP laundering.” – lifeisloving
- “We cannot look at Adobe sources. Use of Ghidra is disallowed.” – echelon

3. The impact on hobbyist/professional communities and the perceived value of manual effort
- “…eliminating reasons to collaborate with others and form relationships, and replacing it with an individualized dependence on a commercial product.” – InvisibleUp
- “It really depends on your perspective of what the point of the hobby is… many participants… lament the loss of ‘street cred’.” – cassonmars
- “If a thing is no longer difficult to perform or to produce… I will no longer value it.” – Brian_K_White


🚀 Project Ideas

Generating project ideas…

SafeBinAI – AI‑powered sandboxed binary installer and analyzer

Summary

  • Provides a secure workflow for downloading, verifying, and executing binaries/scripts using AI‑driven static/dynamic analysis and sandboxing, addressing the insecurity of curl|bash and unknown code execution.
  • Core value: Lets users safely run and reverse‑engineer unknown binaries while automatically flagging malicious behavior and generating analysis reports.

Details

Key Value
Target Audience Security researchers, reverse engineers, developers who frequently download and test tools/scripts from the internet
Core Feature AI‑assisted sandbox execution that monitors system calls, network, file modifications, and uses LLMs to detect malicious patterns; also verifies hashes/signatures and provides a safe RE environment
Tech Stack Rust (sandbox via seccomp/bpf or Firecracker), Python (orchestration), local LLMs (llama.cpp or similar), eBPF for monitoring, SQLite for reports
Difficulty Medium
Monetization Revenue‑ready: SaaS tiered (free basic, $10/mo for advanced AI scans)

Notes

  • HN users expressed concern about curl|bash insecurity: carsoon noted “installation has always been such a security issue…”, and t‑writescode highlighted the difference between static verification and dynamically loaded external sources.
  • Potential for discussion: a trusted, AI‑augmented sandbox could become the go‑to method for safely experimenting with unknown binaries while feeding back analysis to improve model‑based threat detection.

SpecExtract – Clean‑room specification generator from binaries

Summary

  • Uses AI to observe binary behavior (via sandboxed execution) and generate high‑level functional specifications (data formats, algorithms, API contracts) without exposing copyrighted code, enabling clean‑room reimplementation.
  • Core value: Reduces legal risk of reverse engineering by providing a behavior‑based spec that developers can use to write original, non‑infringing implementations.

Details

Key Value
Target Audience Developers and companies wanting to create compatible clean‑room clones of proprietary software (e.g., driver reimplementations, game mods, legacy tool replacements)
Core Feature Automated black‑box testing + AI summarization that produces a structured spec (e.g., Markdown or protobuf) describing inputs/outputs, state transitions, and performance characteristics
Tech Stack Python (pytest/hypothesis for fuzzing), local or API LLMs, OpenAPI/Swagger generator, Docker‑based sandbox
Difficulty High
Monetization Revenue‑ready: Enterprise licensing ($200/mo per seat)

Notes

  • Commenters stressed clean‑room RE to avoid legal trouble: echelon said “We do not decompile binaries, we do everything 100% clean room…”, and others worried about DMCA and IP laundering.
  • Potential for discussion: supplying provably clean specifications could satisfy both legal teams and engineers seeking to interoperate with legacy or proprietary systems while staying within copyright limits.

DecompHub – Collaborative, verifiable decompilation repository

Summary

  • A Git‑like platform where users can upload AI‑assisted decompilations, automatically verify correctness via recompilation and diff against the original binary, and earn reputation for accurate contributions.
  • Core value: Eliminates duplicated effort, ensures quality, and provides a trusted source of clean, human‑readable decompiled code for learning and modding.

Details

Key Value
Target Audience Reverse engineering hobbyists, game modders, security researchers, developers preserving legacy software
Core Feature Upload binary + decompiled source; system runs build, compares behavior, runs test suite, and flags mismatches; includes AI‑assisted commenting and variable naming
Tech Stack Go or Rust backend, Git‑LSFS for storage, WebAssembly sandbox for building, LLMs for comment generation, React frontend
Difficulty Medium
Monetization Revenue‑ready: SaaS tiered (free public, $12/mo for private)

Notes

  • InvisibleUp warned of “a flood of half‑decent decomps effortlessly generated by anyone with a $200/mo AI subscription”, highlighting wasted duplicate work.
  • Potential for discussion: a reputation‑backed, verified hub could turn the current scramble for AI‑generated decompilations into a collaborative effort that improves quality and reduces redundant token consumption.

Read Later