Hackers are saving Google's abandoned Nest thermostats with open-source firmware

Alfonso Maruccia

Posts: 2,602   +978
Staff
TL;DR: When Big Tech companies turn against their customers' best interests, you can always count on dedicated hackers to step in and keep abandoned devices alive. Case in point: Google's recently discontinued Nest products now have a new home that should keep them working for years to come.

Cody Kociemba, the developer behind the Hack/House collaborative project, is waging war against Google. The tech giant recently decided to discontinue the first two generations of its Nest Thermostat, stripping the devices of much of their original functionality. Thanks to Kociemba's hacking efforts, Nest customers now have an alternative path to restoring the features Google removed.

Kociemba has launched the No Longer Evil project, an open-source initiative aimed at breathing new life into decommissioned first- and second-generation Nest thermostats. The custom software can effectively "revive" these devices, offering a modern control interface and returning full ownership and functionality to users. The community-driven project is explicitly designed to combat planned obsolescence imposed by Big Tech, Kociemba said, giving still-functional hardware a new lease on life.

According to the project's GitHub repository, NLE's core component is a custom firmware that modifies critical portions of the original Nest software to eliminate dependence on Google's servers. The modified firmware intercepts Nest's communication layer, rerouting network traffic to a custom server that hosts a replica of the original Nest API painstakingly developed through reverse engineering. As a result, the thermostat believes it is still communicating with the official Nest infrastructure, restoring remote functionality without Google's involvement.

The NLE project began earlier this month, with Kociemba cautioning that the software remains highly experimental and will require extensive work and testing before reaching maturity. Users who rely on their Nest devices for essential heating or environmental control are strongly advised not to install the custom firmware – for now, at least.

In the long term, the NLE team aims to completely replace Google's original firmware for the first two Nest generations. The custom firmware is expected to handle temperature adjustments, mode switching, and real-time smart home monitoring through a sleek interface designed to rival the official one.

Kociemba launched NLE both as a personal challenge and as an opportunity to claim a $15,000 bounty offered by the FULU Foundation, which rewards developers who liberate bricked devices from corporate ecosystems. He took advantage of the initiative while staying true to his principles of hardware hacking, reverse engineering, and resistance to unchecked corporate control.

Permalink to story:

 
All good and well - but if I understood correctly, this will basically reroute your nest and the control a device within your home network to...A server hosted by someone calling themselves "Hack/House" ?

Hopefully those API's will be available to download and run on your NAS server or something instead
 
All good and well - but if I understood correctly, this will basically reroute your nest and the control a device within your home network to...A server hosted by someone calling themselves "Hack/House" ?

Hopefully those API's will be available to download and run on your NAS server or something instead


You are right, should have called themselves the TrustMeBro 5000. Because Hacking = Bad!
 
Tricking the Nest devices to believe it is still communicating with the Nest infrastructure...And with everyone tricking everyone (scams), I wonder how many will do this especially with their IoT devices. This seems to be more of a community/hobbyist kind of thing.
 
All good and well - but if I understood correctly, this will basically reroute your nest and the control a device within your home network to...A server hosted by someone calling themselves "Hack/House" ?

Hopefully those API's will be available to download and run on your NAS server or something instead
You are right, should have called themselves the TrustMeBro 5000. Because Hacking = Bad!
At least there's not much information to really be taken surely? Oh no, they know the temp of the hallway? They know I prefer to turn off the heating in the early hours? Just trying to think of what information they could get that's of any use to do harm or sell? Because if there is, I'm suprised Google gave up to be honest.
 
At least there's not much information to really be taken surely? Oh no, they know the temp of the hallway? They know I prefer to turn off the heating in the early hours? Just trying to think of what information they could get that's of any use to do harm or sell? Because if there is, I'm suprised Google gave up to be honest.

Your Nest sensors could give someone a decent idea of what your daily schedule looks like and crucially, when your house is empty. Putting this into a non locally controlled database in the hands of some unkowns on the internet doesn't seem like a great idea. They may be perfectly trustworthy, hell they probably are, but that doesn't mean their server is as secure or reliable as Googles. A few years down the line and they don't want to / can't afford to host it and let the domain lapse then some bad actor copies the repo and buys the expired domain and BOOM, now they have all the data. Yeah, this scenario might be unlikely, but it is possible.

Google isn't necessarily giving up their collection of this data but more likely hoping a critical mass of people will upgrade to a model that likely collects even more data.
 
At least there's not much information to really be taken surely? Oh no, they know the temp of the hallway? They know I prefer to turn off the heating in the early hours? Just trying to think of what information they could get that's of any use to do harm or sell? Because if there is, I'm suprised Google gave up to be honest.
Well - they would have access to a device running software from within your firewall. What the device does as a «home device» is irrelevant
 
You are right, should have called themselves the TrustMeBro 5000. Because Hacking = Bad!
Name is kinda irrelevant- my point was that you’re running on an unofficial server «somewhere» owned by «someone» - accessible by «unknown» - and you’re allowing them access to your home network as there needs to be «two-way communication».
Which is why I’d rather shelve that device unless I could just host the server on my own
 
Hopefully those API's will be available to download and run on your NAS server or something instead

It's super early days so they simply haven't had time to get around doing everything as they want yet. But from the linked GitHub page:
> The firmware images and backend API server code will be open sourced soon, allowing the community to audit, improve, and self-host their own infrastructure.
 
You can always count on the open source community to unlock the actual value of a product long after it no longer suits the margins of its corporate overlords.


I don't know about "always", as countless devices remain which are still and will likely remain locked down or, worse, permanently bricked, but it is nice when somebody comes in clutch like this.
 
If it’s open-source, and the server they run is ALSO open-source, then I don’t see any reason why not.

Thing is, for the amount of time and money it would cost to do this… I could just buy a new Nest…
ORRRR..... You could build a bunch of them and sell them! Maybe?
I wonder how cheaply they could be built?

EDIT - Oh hell man the cheapest Nest is only $85 and even the most expensive one is under $300. I can't imagine there is any money to be made building and selling those Nest server things.
 
Last edited:
If it’s open-source, and the server they run is ALSO open-source, then I don’t see any reason why not.

Thing is, for the amount of time and money it would cost to do this… I could just buy a new Nest…

I imagine a lot of people around here or who are interested in doing this might already have a home lab. If that's the case, there is no cost at all to just add another VM or docker container to run it.

Me personally? It's the final thing that has got me working on a HomeAssistant install. I'm going to be replacing it with a Z-Wave or Zigbee device. It's about the same amount of money, and my time is mostly worthless so... might as well?
 
ORRRR..... You could build a bunch of them and sell them! Maybe?
I wonder how cheaply they could be built?

EDIT - Oh hell man the cheapest Nest is only $85 and even the most expensive one is under $300. I can't imagine there is any money to be made building and selling those Nest server things.

Plus it's probably illegal. See one of Louis Rossman's recent videos. He has set up a bounty program for breaking into these types of things, and he points out in the video that bypassing electronic locks like cryptography etc is not legal in the US, even if you own the device. So while individual users would likely be fine doing this to their own thermostat, someone selling the solution would likely not be if Google decides they care (and if they are in the US, of course).

It's kind of like when people open up game consoles for "homebrew" (wink wink, nudge nudge). The guy who figures it out is usually OK, and the individual users are typically as well. It's the ***** who decides to sell it that is most often not.
 
All good and well - but if I understood correctly, this will basically reroute your nest and the control a device within your home network to...A server hosted by someone calling themselves "Hack/House" ?

Hopefully those API's will be available to download and run on your NAS server or something instead
Who do you trust? A moral hacker or Google?
 
I would suggest, since this effort has been widely publicized, that anyone that has one of these affected thermostats installed ought to consider blocking its access to the Internet until the open source firmware is available.

Otherwise I suspect, at some point before it shuts down the servers, that Google will push some sort of encrypted firmware update to the devices to lock them down and prevent them from being updated in any way.

Such actions have actually been taken by other companies in the past. And, none of those instances ever involved a company with the arrogance, power, and reach of Google.
 
Who do you trust? A moral hacker or Google?
I get your point - But at least Google could be subject to a class action lawsuit if they're caught overstepping (which they have at several points, and paid for it). "a moral hacker" - Wouldn't trust them with anything inside my home network. I applaud making new firmware though - and if it's open source, it should be possible to download and direct to your own privately hosted server
 
Let’s be real: this project isn’t some heroic liberation of abandoned Nest devices. The article emphasizes Cody Kociemba waging “war” on Google, but reading closely, it’s obvious the motivation is largely personal — anger over his Google Play ban — and financial, aimed at claiming the $15,000 FULU bounty. The whole “fighting planned obsolescence” narrative reads like cover for a personal challenge wrapped in moral righteousness.

The firmware itself is experimental, relies on custom servers he controls, and effectively swaps Google’s single point of failure for another entirely dependent on his ongoing interest and availability. There’s zero guarantee of long-term reliability, and users are explicitly warned not to rely on it for essential heating or environmental control.

On top of that, his story about being banned from Google is vague: repeated mentions of “not malware, not stealing data, no human review,” but no specifics about what was actually rejected. That, combined with the anger-driven motivation, the bounty chase, and the reliance on a fragile custom infrastructure, makes this far more of a personal stunt than a dependable solution for users.

Calling this a “rescue” effort for consumers oversells it. It’s an experimental, high-risk project powered by resentment and cash incentive, not a mature, trustworthy path for maintaining your thermostat. Anyone relying on it for a home environment is taking a serious gamble.
 
Back