Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
OpenClaw privilege escalation vulnerability
41–50 of 306 posts
Re: OpenClaw privilege escalation vulnerability
#42Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
More than 25% of users seems like a pretty accurate "probably".
If you're running OpenClaw, you probably didn't get hacked in the last week.
Re: OpenClaw privilege escalation vulnerability
#43Re: OpenClaw privilege escalation vulnerability
#44Earlier quoted context omitted.
More than 25% of users seems like a pretty accurate "probably".
Today I learned nobody agrees on what the word "probably" means.
Otherwise I would say “you may have been hacked” not “you probably have been hacked”.
Re: OpenClaw privilege escalation vulnerability
#45Earlier quoted context omitted.
Today I learned nobody agrees on what the word "probably" means.
Ya I thought it meant “more probable than not” ie 50+%. Otherwise I would say “you may have been hacked” not “you probably have been hacked”.
Re: OpenClaw privilege escalation vulnerability
#46Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
It’s also only 65% of those that have zero authentication configured, according to that post (which I have done nothing to confirm or challenge at all… Frankly I wouldn’t touch OpenClaw with a ten foot… cable?) That said, I think it’s far more important to get people’s attention who might otherwise not realize how closely they need to pay attention to CVEs than it is to avoid hyperbole in headlines.
Re: OpenClaw privilege escalation vulnerability
#47[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]
Re: OpenClaw privilege escalation vulnerability
#48Earlier quoted context omitted.
It’s also only 65% of those that have zero authentication configured, according to that post (which I have done nothing to confirm or challenge at all… Frankly I wouldn’t touch OpenClaw with a ten foot… cable?) That said, I think it’s far more important to get people’s attention who might otherwise not realize how closely they need to pay attention to CVEs than it is to avoid hyperbole in headlines.
Not if this is crying wolf and causing those same people to ignore the very real security risks with using OpenClaw.