OpenClaw opens a wide attack surface on your digital life that cannot be remediated so long as hallucinations and prompt injection remain unsolved problems. Anything built on top of it is equally insecure and probably even more insecure. I really don't want to yuck anybody's yums or step on dev work that I had nothing to do with, because I've been there and I know it sucks, but OpenClaw is barely secure enough to eve…
Show HN: DenchClaw – Local CRM on Top of OpenClaw
81–90 of 143 posts
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#82Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#83Readme has a discord link claiming 25K online, might want to update that it's quite misleading.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#84Are small local models good enough for driving OpenClaw-likes or an API key from one of the big labs is needed?
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#85Earlier quoted context omitted.
Bruh it's not botted, the 500 stars came from Garry Tan's viral tweet.
Can you link to it? I'm not able to find it on his account. Unless you mean his retweet of your tweet? If so, that retweet has just under 10k views and the tweet is in celebration of hitting 500 stars on Github.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#86OpenClaw opens a wide attack surface on your digital life that cannot be remediated so long as hallucinations and prompt injection remain unsolved problems. Anything built on top of it is equally insecure and probably even more insecure. I really don't want to yuck anybody's yums or step on dev work that I had nothing to do with, because I've been there and I know it sucks, but OpenClaw is barely secure enough to eve…
This rings so true. Software Engineering should have stricter bar similar to med professionals. If we have leaked such lousy products and the public crowd thinks this is usable, it's a failure of the industry as a whole.
This is a month-old project by someone how has been suckling at the YC teat of release as early as possible; #YOLO. There's no "engineering" here.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#87OpenClaw opens a wide attack surface on your digital life that cannot be remediated so long as hallucinations and prompt injection remain unsolved problems. Anything built on top of it is equally insecure and probably even more insecure. I really don't want to yuck anybody's yums or step on dev work that I had nothing to do with, because I've been there and I know it sucks, but OpenClaw is barely secure enough to eve…
Aren't hallucinations mathematically impossible to be _solved_? Cannot believe how so many people just willy nilly give everything they have to a lying parrot.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#88Are small local models good enough for driving OpenClaw-likes or an API key from one of the big labs is needed?
I always recommend Claude Opus 4.6 for anything OpenClaw gets its hands on.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#89OpenClaw opens a wide attack surface on your digital life that cannot be remediated so long as hallucinations and prompt injection remain unsolved problems. Anything built on top of it is equally insecure and probably even more insecure. I really don't want to yuck anybody's yums or step on dev work that I had nothing to do with, because I've been there and I know it sucks, but OpenClaw is barely secure enough to eve…
It seems to me many infosec best practices that have been built over decades have been forgot in the last few months like nothing happened. People really do give this kind of software full system access, plus access to their emails, their private chats, most likely their passwords too and who knows what else via plugins. I couldn't really imagine this happening one year ago.
I'm 100% confident that any state actor and cybercrime groups are currently heavily focusing their research on these tools. You compromise the right person and you can access all kind of critical information, it would basically be the same as having some remote control software on their system with full permissions.
And everyone on the hype train seems to be absolutely unaware of this. Maybe I'm missing something, but all of this feels so odd to me.
Re: Show HN: DenchClaw – Local CRM on Top of OpenClaw
#90OpenClaw opens a wide attack surface on your digital life that cannot be remediated so long as hallucinations and prompt injection remain unsolved problems. Anything built on top of it is equally insecure and probably even more insecure. I really don't want to yuck anybody's yums or step on dev work that I had nothing to do with, because I've been there and I know it sucks, but OpenClaw is barely secure enough to eve…
As someone that has worked in the automotive space, an enormous amount of regulation and effort is spent making sure you cannot do something like forgetfully remote start the car with your garage door closed and gas yourself. Nevermind securing it so that others cannot do this to you.
And these people are plugging it into ... this, which will happily go "oh, the car turned off after 15 minutes, let me turn it back on!"
There are realistic odds that someone is rotting in their house while their lobster pays the bills and writes blog posts for them.