Osgood frames the project as a demonstration that censorship-resistant distribution no longer requires labor-intensive copying or risky physical handoffs. By repurposing a sub-$10 smart bulb's unused flash to serve roughly a thousand EPUBs over LAN and Tor, he shows that a device hiding in plain sight on house current can replicate what samizdat networks once needed dozens of people to do.
By submitting the piece and driving it to 316 points, the submitter signaled that the HN community sees this as a noteworthy political and technical artifact — not merely a hardware hack but a credible new shape for distributing forbidden literature.
Osgood is explicit that the specific banned titles are illustrative, not the payload that matters. The real demonstration is that a frosted plastic dome on a ceiling — something no searcher would think to inspect — has enough flash, compute, and network access to indefinitely host and serve a library, with no external tell in power draw, heat, or behavior.
The editorial notes that the immediate HN reaction was nostalgic — invoking Cory Doctorow's Little Brother, BBS-era dead drops, and WWII microfilming of forbidden texts. It argues this lineage framing actually undersells the shift, because the human-throughput bottleneck that defined samizdat has been replaced by cheap silicon doing the copying and serving autonomously.
Richard Osgood published a writeup (316 on Hacker News) detailing how he turned a generic Wi-Fi smart bulb — the kind that sells for under $10 and ships with a Tuya-clone firmware — into a tiny lending library of books banned in various jurisdictions. The bulb's guts are unremarkable: an ESP32-class MCU, a few megabytes of SPI flash, a Wi-Fi radio, and a PWM driver for the LEDs. Osgood desoldered nothing. He flashed new firmware over the air, carved out the unused portion of the flash partition, and dropped in a static HTTP server plus a small collection of EPUBs and PDFs.
The bulb still works as a bulb. It joins your network, accepts on/off commands from the vendor app, and dims on schedule. It also quietly serves `/library/` over HTTP on the LAN, and — via a small Tor hidden-service shim he describes — over an onion address to anyone who knows the URL. The whole thing draws roughly the same power as the original firmware. Nothing on the outside of the device betrays it. There is no LED blink code, no extra antenna, no telltale heat signature. From across the room it is a lamp.
The book selection is the political payload: titles that have been pulled from school libraries in US states over the last few years, plus a handful of works banned in authoritarian regimes. Osgood is explicit that the point is not the specific catalogue — it's the demonstration. A device most people would not think to search, that lives behind a frosted plastic dome on a ceiling, can host and distribute roughly a thousand books indefinitely on house current.
The immediate reaction in the HN thread was nostalgia — comparisons to Cory Doctorow's *Little Brother*, to BBS-era dead drops, to the WWII practice of microfilming forbidden texts. That framing undersells what changed. Samizdat used to be a labor problem: someone retyped *The Gulag Archipelago* at night, carbon copies, hand it on, hope. The bottleneck was human throughput and physical custody. Osgood's bulb collapses both. The catalogue is loaded once at the bench, the device is installed by an electrician who has no idea, and the network layer is handled by infrastructure (Tor, Wi-Fi) that neither the operator nor the visitor has to think about.
What makes this more than a cute hack is the supply-chain math. There are, by various estimates, between two and four billion ESP32-class devices in the wild — bulbs, plugs, thermostats, garage openers, pet feeders, novelty lamps from the checkout aisle at Five Below. The vast majority ship with more flash than the vendor firmware uses, an MCU that idles at single-digit milliwatts, and a Wi-Fi stack that already knows how to NAT-traverse to a cloud broker. The hardware substrate for a globally distributed, mains-powered, deniable content network is already installed, paid for, and plugged in. The only missing piece was someone bothering to write the firmware. Osgood just did.
The security community has spent a decade worrying about IoT devices as a *threat surface* — Mirai, default-credential botnets, the smart fridge that joined a DDoS. This inverts the model. Here the device is not compromised by an attacker against the owner's interest; it is repurposed, often by the owner, against a third party — a censor, a school board, a customs officer. The defender's playbook (inventory, patching, network segmentation) doesn't apply, because there is nothing wrong with the device. It is doing exactly what its current operator intends. The smart-home category, sold for a decade as 'convenience,' just turned out to also be a covert-publishing platform that pre-installed itself in 60 million American homes.
It is also worth noticing the legal asymmetry. A USB stick full of banned books is contraband at most borders. A 9-watt LED bulb is not. The bulb has a UL mark and an FCC ID. It was bought at retail. Even after the firmware swap, it is indistinguishable from its siblings without a JTAG probe and intent. This is the same asymmetry that made Tor itself viable — the bytes on the wire are encrypted and look like every other TLS session — pushed down into the physical layer.
If you build smart-home products: your bill of materials is now also a threat model your legal team has not modeled. Vendor firmware that leaves megabytes of unused flash, ships with OTA enabled, and uses a stock bootloader is a kit. The mitigations are unpleasant — secure boot with vendor-only signing keys, flash encryption keyed to the MCU's eFuses, OTA channels locked to a signed manifest — and they break right-to-repair, hobbyist tinkering, and the entire reflashing community that made ESPHome and Tasmota possible. The honest tradeoff is: if you want your devices to *not* be repurposable as covert servers, you have to make them un-repurposable for anything, including legitimate uses. Pick.
If you run a corporate network: your IoT VLAN policy probably assumes the threat is exfiltration *outbound* from the device to an attacker C2. Osgood's design implies the inverse — inbound traffic to a device that should never accept any. The detection signal is not destination IPs; it is a thermostat accepting TCP connections on port 80 from the guest Wi-Fi. Most network detection tooling does not look there because, until now, there was no reason to.
If you're a developer thinking about edge compute more broadly: this is the cleanest existing-deployment case for 'the edge is already there, you just have to notice.' Cloudflare Workers, AWS Greengrass, and the entire WASM-on-microcontroller pitch have spent years arguing that compute should live close to the user. Osgood's bulb is that argument made literal: a fully autonomous web service running on a node that costs less than the postage to ship it, behind a power bill the owner is already paying. Anyone building distributed-systems tooling — content addressing, peer discovery, partial replication — now has a substrate to target that is bigger than every cloud region combined.
The interesting question is not whether more people will do this — they will, and the next implementations will be in plugs, doorbells, and the WLED-style addressable strips that already have enthusiast firmware communities. The interesting question is what happens the first time a customs agent, a school administrator, or a state inspector understands that a lamp can be a library. The likely response is a push for attestation — bulbs that cryptographically prove which firmware they're running before they're allowed on a network, the same trusted-computing model that PC vendors lost the fight over twenty years ago. The samizdat side has the easier job: there are billions of bulbs already in homes, and the firmware fits in a tweet's worth of hex.
The ending notes about a mesh network remind me of the Reticulum Network Stack[1].As far as I can tell, RNS is a networking protocol that attempts to provide a mesh network that can run over almost any bidirectional connection (and interconnect different types of connections) without centralisation
“As the Americans learned so painfully in Earth’s final century, free flow of information is the only safeguard against tyranny. The once-chained people whose leaders at last lose their grip on information flow will soon burst with freedom and vitality, but the free nation gradually constricting its
Years ago there was PirateBox: flash a small Wifi access point with a custom firmware that's a webserver that hosts a forum/filehost. Their website is dead, but here's a mod of the project; https://www.jasongriffey.net/librarybox/Although, I dread to think what sor
A hidden “book server” like this could be set up in just about any electronic device with a sufficiently powerful microcontroller. But I think there is something delightfully poetic about using a source of light to spread suppressed knowledge.
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
Cool project, except these aren't really "banned" books. thats a misleading term. In most of these cases, the book isn’t actually banned. Nobody is being arrested for owning it, Amazon isn’t forbidden from selling it, and adults can still read it whenever they want.What’s really being