Live data from Hacker News

Nvidia NemoClaw

github.com

121–130 of 291 posts

Re: Nvidia NemoClaw

#121

Gotta say, that I feel kind of sad for the people that feel the need for these claw things. Are they so busy with their lives that they need an assistant, or do they waste their lives speaking to it like it is a human, and then doomscrolling on some addictive site instead of attending to their lives in the real world?

It’s not a need - it’s a fun new thing - fun to see what’s possible and how it helps.

OpenClaw is not easy to set up or user friendly for most (BlueBubbles and Claw had an annoying bug recently) - but the way I have seen it work well requires an up front time investment and then interest compounds RAPIDLY to help manage things and be more productive.

My guess is maybe you’ve never had an assistant or tried a Claw instance? I’ve never had a human assistant but man I’ve had folks that took silly things off my plate and it’s worth it.

Re: Nvidia NemoClaw

#122
post #79

Earlier quoted context omitted.

Scripts fail. Agents exfiltrate your data because someone hacked the school's website with prompt injections. Make sure it's a choice and not ignorance of the risks.

> Scripts fail. Which is totally fine for the majority of tasks. > Agents exfiltrate your data They can only exfiltrate the data you give them. What's the worst that prompt injection attack will give them?

Container security is an entire subfield of infosec. For example: https://github.com/advisories/GHSA-w235-x559-36mg

People on both sides are just getting started finding all the ways to abuse or protect you from security assumptions with these tools. RSS is the right tool for this problem and I would be surprised if their CMS doesn't produce a feed on its own.

Re: Nvidia NemoClaw

#123
post #65

Am I missing something? Why is everyone talking about sandboxes when it comes to OpenClaw? To me it's like giving your dog a stack of important documents, then being worried he might eat them, so you put the dog in a crate, together with the documents. I thought the whole problem with that idea was that in order for the agent to be useful, you have to connect it to your calendar, your e-mail provider and other servic…

> being worried he might eat them, so you put the dog in a crate, together with the documents.

Maybe you don't want the dog to shit all over the place after eating said documents, so you put it in a crate.

Re: Nvidia NemoClaw

#124
post #65

Am I missing something? Why is everyone talking about sandboxes when it comes to OpenClaw? To me it's like giving your dog a stack of important documents, then being worried he might eat them, so you put the dog in a crate, together with the documents. I thought the whole problem with that idea was that in order for the agent to be useful, you have to connect it to your calendar, your e-mail provider and other servic…

Because it's so useful to me that I'm willing to accept the risk of it having access to the thing it needs for the benefit it provides. I'm not willing to accept the risk of it having access to things it doesn't need for no benefit.

Then again, I was wary of OpenClaw's unfettered access and made my own alternative (https://github.com/skorokithakis/stavrobot) with a focus on "all the access it needs, and no more".

Re: Nvidia NemoClaw

#125
post #122

Earlier quoted context omitted.

> Scripts fail. Which is totally fine for the majority of tasks. > Agents exfiltrate your data They can only exfiltrate the data you give them. What's the worst that prompt injection attack will give them?

Container security is an entire subfield of infosec. For example: https://github.com/advisories/GHSA-w235-x559-36mg People on both sides are just getting started finding all the ways to abuse or protect you from security assumptions with these tools. RSS is the right tool for this problem and I would be surprised if their CMS doesn't produce a feed on its own.

I don't use a container. I use a VM.

I'm not totally naive. I had the VM fairly hardened originally, but it proved to be inconvenient. I relaxed it so that processes on the VM can see other devices on the network.

There's definitely some risk to that.

Re: Nvidia NemoClaw

#127
post #118

Gotta say, that I feel kind of sad for the people that feel the need for these claw things. Are they so busy with their lives that they need an assistant, or do they waste their lives speaking to it like it is a human, and then doomscrolling on some addictive site instead of attending to their lives in the real world?

It is sad, psychosis from exec-up has trickled down so people really want these tools to work yet these tools are so bad that people in this thread are recommending you create a second email so your openclaw can suggest events to you without being able to delete them. It's like having to hire a second maid to watch your maid that steals constantly instead of vacuuming yourself in 10 mins.

Imagine having a worldview so skewed that you'd rather reconcile it by assuming thousands of people are insane than questioning whether you're wrong about something.

Re: Nvidia NemoClaw

#128
post #12
post #7

Earlier quoted context omitted.

OpenClaw is so bad with Docker. I spent hours on it and hit road block after road block trying to get the most basic things working. The last one was inability to install dependencies on the docker container to enable plugins. The existing scripts and instructions don’t work (at least I couldn’t get them to work. Maybe a me problem). So I gave up and moved on. What was supposed to be a helpful assistant became a nigh…

Why not use a VM?

Because I have a machine running dozens of apps on Docker and have a solid and stable workflow I want to take advantage of to manage my apps.

Re: Nvidia NemoClaw

#129
post #65

Am I missing something? Why is everyone talking about sandboxes when it comes to OpenClaw? To me it's like giving your dog a stack of important documents, then being worried he might eat them, so you put the dog in a crate, together with the documents. I thought the whole problem with that idea was that in order for the agent to be useful, you have to connect it to your calendar, your e-mail provider and other servic…

> Am I missing something? You are indeed missing a TON. A lot of Open Claw users don't give it everything. We give it specific access to a group of things it needs to do the things we want. If I want an agent to sit there 24/7 maximizing uptime of my service, I give it access to certain data, the GitHub repo with PR privileges, and maybe even permissions to restart the service. All of this has to be very thoughtful a…

Can you talk us through that a bit more? I suspect it would need more access than the permissions you mentioned to be more useful than a simple rules based automation.

Re: Nvidia NemoClaw

#130

The fully autonomous agentic ecosystem makes me feel a little crazy — like all common sense has escaped. It feels like there is a lot of engineering effort being exhausted to harden the engine room on the Titanic against flooding. It's going to look really secure... buried in debris at the bottom of the ocean. When a state sponsored threat actor discovers a zero day prompt injection attack, it will not matter how iso…

[dead]
Post reply on HN