Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

161–170 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#161

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

Definitely, the whole point of openclaw is to operate on your data. It's just.. Be prepared to lose it I guess. The one thing I'm definitely not giving access to yet - the payments. I think we'll develop a way to handle that though

Re: OpenClaw is a security nightmare dressed up as a daydream

#162
post #147

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

While technically this is rooted in the technological misconstruction of a missing separation of data and instructions. However my point is: on the other hand, that would be the same if you outsourced those tasks to a human, isn't it? I mean sure, a human can be liable and have morals and (ideally) common sense, but most major screw ups can't be fixed by paying a fine and penalty only.

A person can be blamed though. And people have a social fabric with understanding about human mistakes or even about people having lied to your etc.

We have no such thing for AI yet.

Re: OpenClaw is a security nightmare dressed up as a daydream

#163
post #147

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

While technically this is rooted in the technological misconstruction of a missing separation of data and instructions. However my point is: on the other hand, that would be the same if you outsourced those tasks to a human, isn't it? I mean sure, a human can be liable and have morals and (ideally) common sense, but most major screw ups can't be fixed by paying a fine and penalty only.

Yes and no. You're right to notice that this is an example of a more general problem called the principal-agent problem. https://en.wikipedia.org/wiki/Principal%E2%80%93agent_proble...

We have no general-purpose solutions to the principal-agent problem, but we have partial solutions, and they only work on humans: make the human liable for misconduct, pay the human a percentage of the profits for doing a good job, build a culture where dishonesty is shameful.

The "lethal trifecta" is just like that other infamously unsolvable problem, but harder. (If you could solve the lethal trifecta, you could solve the principal-agent problem, too.)

Since we've been dealing with the principal-agent problem in various forms for all of human history, I don't feel lucky that we'll solve a more difficult version of it in our lifetime. I think we'll probably never solve it.

Re: OpenClaw is a security nightmare dressed up as a daydream

#164

I'm a heavy OpenClaw user and I've been testing it in many different scenarios — the profundity of what I can do with it now is crazy. It's literally automating my life. Being AuDHD, OpenClaw feels like a big relief. The positive sides are amazing. The downsides... well, as with any security and any LLM, they're all prone to the same problems discussed here. Having Claude Code on yolo mode exposes you to the exact sa…

Definitely relate to the AuDHD benefits...

Re: OpenClaw is a security nightmare dressed up as a daydream

#165
post #81

Earlier quoted context omitted.

I'm gonna keep saying this forever - there are two obvious "killer apps" for crypto: 1. Semi-private blockchains, where you can rely on an actor not to be actively malicious, but still want to be able to cryptographically hold them to a past statement (think banks settling up with each other) 2. NFTs for tracking physical products through a logistics supply chain. Every time a container moves from one node to the nex…

The only "killer app" for crypto*currencies* is being a payment method. Not counting speculation. This is what they are used for right now, but the scale at which this happens doesn't justify their current valuation (even after recent losses).

But is that a better experience than just using your visa? Nobody wants to wait at the cashier for 15 minutes to pay for their groceries, which is what has to happen if you really want the decentralized experience. Otherwise you really are just reinventing a worse, centralized payment rails. Volatility and wait times are features of crypto, not bugs, but they make for terrible payment experiences.

Writing that I feel back in 2021.

Re: OpenClaw is a security nightmare dressed up as a daydream

#166
post #44
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

> why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. This AI wave is filled with "ideas guys/gals" who thought they had an amazing awesome idea and if only they knew how to program they could make a best-selling billion dollar idea, being confronted with the reality that their ideas are really uninteresting as well. They're still happy to…

Yeah it seems like we're still in the "XYZ ... but on a computer!" stage of AI.

Re: OpenClaw is a security nightmare dressed up as a daydream

#167
post #94

Earlier quoted context omitted.

Give it a hundred years or so and we're gonna have robots wandering around who about 10% of the time go totally insane and kill anyone around them. But we'll all just shrug and go about our day, because they generate so much revenue for the corporate overlords. What are a few lives when stockholder value is on the line.

It's governments that tend to declare war and kill people.

Millions of people die every year from tobacco, and tobacco companies fought for decades to deny their product causes cancer. In the 20th century alone it's estimated something like 100 million people died world wide thanks to smoking.

That's just one example off the top of my head. There are countless others involving corporations killing people either directly or indirectly in the pursuit of profits. And that's before you start looking at human rights violations, ecological damage, overthrowing of sovereign governments around the world...

Re: OpenClaw is a security nightmare dressed up as a daydream

#168
post #67

Earlier quoted context omitted.

> The whole point of OpenClaw is to run AI actions with your own private data, your own Gmail, your own WhatsApp, etc. There's no point in using OpenClaw with that much restriction on it. Hard disagree. I have OpenClaw running with its own gmail and WhatsApp running on its own Ubuntu VM. I just used it to help coordinate a group travel trip. It posted a daily itinerary for everyone in our WhatsApp group and handled a…

Do you need the simcard for WhatsApp?

I believe you only need a unique phone number to create the account, then you can use WhatsApp Web as client. Be very careful with alternative clients, as I've had an account banned in the past for this (and therefore a phone number blacklisted), even without messaging anybody. I think that clients that run WhatsApp Web in a web view (like https://github.com/rafatosta/zapzap) are safe.

I think they started banning unauthorized API users around the time that "WhatsApp For Business" was introduced, because it was competing with that product. Unfortunately WhatsApp For Business is geared toward physical products and services with registered companies, so home automation and agents are left with no options.

Re: OpenClaw is a security nightmare dressed up as a daydream

#169
post #77

Earlier quoted context omitted.

I think some folks want a legitmate personal assistant/secretary like ceo's and wealthy people have but ai. I think that's a good goal. Modern cells and pdas kinda fell short of "your own literal secretary" and I think people want that. Still we should continue pushing the boundaries beyond that.

They really didn't fall short. A lot of people who would've had assistants no longer do, now it's really just the executives like you said. But fairly low managers used to have them and now they don't. Software is pretty good. It remembers everything, perfectly, forever. It will never forget to remind you of something. It can give you directions, sort your emails by how important they are, help you find shops and res…

> It will never forget to remind you of something.

Software isn't as faultless as you suggest. The default alarm app on my phone occasionally fails to go off (not an issue with Silent Mode or DND).

> The only people busy enough to warrant an actual human doing that stuff are executives.

Life is short. It is absolutely worthwhile to spend as little time doing trivial work if possible, and avoid decision fatigue on unimportant decisions. We are nowhere close to the usefulness of a secretary in our devices.

Re: OpenClaw is a security nightmare dressed up as a daydream

#170
post #44
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

> why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. This AI wave is filled with "ideas guys/gals" who thought they had an amazing awesome idea and if only they knew how to program they could make a best-selling billion dollar idea, being confronted with the reality that their ideas are really uninteresting as well. They're still happy to…

I have "new genius" ideas very often. After doing quick search I discover that any idea worth thinking of implementation is either implemented already or what seems to be low barrier to entry clashes with some legal obstacles.
Post reply on HN