Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

41–50 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#41
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

It’s also only 65% of those that have zero authentication configured, according to that post (which I have done nothing to confirm or challenge at all… Frankly I wouldn’t touch OpenClaw with a ten foot… cable?) That said, I think it’s far more important to get people’s attention who might otherwise not realize how closely they need to pay attention to CVEs than it is to avoid hyperbole in headlines.

Re: OpenClaw privilege escalation vulnerability

#42
post #33
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

More than 25% of users seems like a pretty accurate "probably".

Here's a statement that's about 3x as true then:

If you're running OpenClaw, you probably didn't get hacked in the last week.

Re: OpenClaw privilege escalation vulnerability

#43
Well, such things were to be expected. It's easy to bash on all the people who haven't gotten the necessary IT understanding of securing such things. Of course, it's uber-dumb to run an unprotected instance. But at the same time, it's also quite cool that so many people can do interesting IT stuff now. I'm thinking basically it's a trade-off. Be able to do great stuff, live with the consequences of doing that without proper training. Like repairing your car yourself. You might have fun doing it, it might get you somewhere, but you have to accept that if you have no idea about cars, you just introduced a pretty big risk into your life (say if you replaced the brakes or something). But yea, security, privacy, fighting climate change, all very much on the decline - humans doing cool things, ignoring important things - we'll have to live with the consequences.

Re: OpenClaw privilege escalation vulnerability

#44
post #33

Earlier quoted context omitted.

More than 25% of users seems like a pretty accurate "probably".

Today I learned nobody agrees on what the word "probably" means.

Ya I thought it meant “more probable than not” ie 50+%.

Otherwise I would say “you may have been hacked” not “you probably have been hacked”.

Re: OpenClaw privilege escalation vulnerability

#45

Earlier quoted context omitted.

Today I learned nobody agrees on what the word "probably" means.

Ya I thought it meant “more probable than not” ie 50+%. Otherwise I would say “you may have been hacked” not “you probably have been hacked”.

That is what it means. Unless you're losing an argument on the internet and you need a word to hide behind. ;)

Re: OpenClaw privilege escalation vulnerability

#46
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

It’s also only 65% of those that have zero authentication configured, according to that post (which I have done nothing to confirm or challenge at all… Frankly I wouldn’t touch OpenClaw with a ten foot… cable?) That said, I think it’s far more important to get people’s attention who might otherwise not realize how closely they need to pay attention to CVEs than it is to avoid hyperbole in headlines.

Not if this is crying wolf and causing those same people to ignore the very real security risks with using OpenClaw.

Re: OpenClaw privilege escalation vulnerability

#47
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#48

Earlier quoted context omitted.

It’s also only 65% of those that have zero authentication configured, according to that post (which I have done nothing to confirm or challenge at all… Frankly I wouldn’t touch OpenClaw with a ten foot… cable?) That said, I think it’s far more important to get people’s attention who might otherwise not realize how closely they need to pay attention to CVEs than it is to avoid hyperbole in headlines.

Not if this is crying wolf and causing those same people to ignore the very real security risks with using OpenClaw.

How is 20% of users getting pwned ”crying wolf” by any reasonable measure? This is a zero authentication admin access vulnerability.
Post reply on HN