Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

71–80 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#71
The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand.

Too much focus on shipping features, not enough attention to stability and security.

As the code base grows exponentially, so does the security vulnerability surface.

Re: OpenClaw privilege escalation vulnerability

#72

Earlier quoted context omitted.

[flagged]

Obviously I already searched the web (not specifically HN I must admit) and there were always incredibly generic non-answers that ultimately say nothing (and they assume you have 3000$ per month or 2000 Mac Minis on your desk (hyperbole)).

I think you’ve got your answer, then. If nobody can tell you what it’s really used for, it likely doesn’t have any real use cases.

Re: OpenClaw privilege escalation vulnerability

#73
post #64

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc ( https://github.com/sgillen/sf-civic-digest ). It also have mine automatically grabs a spot at my gym when spots are released because I always forget. I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any ti…

[flagged]

Re: OpenClaw privilege escalation vulnerability

#74
post #64

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc ( https://github.com/sgillen/sf-civic-digest ). It also have mine automatically grabs a spot at my gym when spots are released because I always forget. I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any ti…

>It also have mine automatically grabs a spot at my gym when spots are released because I always forget.

seems far more efficient/reliable to get codex/claude code to write and set up a bot that does this.

Re: OpenClaw privilege escalation vulnerability

#75

Earlier quoted context omitted.

Does it really? Digging up the data from example the 135k instances in the open reeks like bullshit, I would suspect several other claims are exaggerated as well.

> Digging up the data from example the 135k instances in the open reeks like bullshit, I would suspect several other claims are exaggerated as well. Do you so stringently examine most CVEs? I’ll bet you don’t. Are you a big fan of this project? I’ll bet you are. Do you have any actual data to counter what they said or do you just sort of generally not vibe with it? If so, now would be a great time to break it out whi…

They are pointing out the data provided does not appear to be real. There is no credible link to this 135k number. They do not need to provide a number, as one does not appear to exist.

Re: OpenClaw privilege escalation vulnerability

#76

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

So I neither downvoted nor upvoted you, but I think people may be downvoting, in addition to the fact that they just don't like the thing, based on the fact that you didn't directly answer the question. Specifically, what are you using it for, not what hypothetically it would be used for.

Re: OpenClaw privilege escalation vulnerability

#77

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

First words out of your mouth are to accuse OP of not seriously asking the question. Then you write paragraphs saying nothing much at all. You could have simply answered the question in a simple straightforward manner.

Re: OpenClaw privilege escalation vulnerability

#78
post #73
post #64

Earlier quoted context omitted.

I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc ( https://github.com/sgillen/sf-civic-digest ). It also have mine automatically grabs a spot at my gym when spots are released because I always forget. I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any ti…

[flagged]

No? The comment was admittedly ambiguous but if you go to repo it's far clearer:

>I use it to give me a weekly digest of what happened in my neighborhood and if there are any public hearings or trash pickups I might want to attend.

Re: OpenClaw privilege escalation vulnerability

#79

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

You're probably being downvoted because you didn't answer the question. The questioner specifically asked what people are using it for and you answered by describing your technical setup. What we want to know is, what are you actually achieving with this tool?

Re: OpenClaw privilege escalation vulnerability

#80
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]
Post reply on HN