Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

111–120 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#111

Earlier quoted context omitted.

Not if this is crying wolf and causing those same people to ignore the very real security risks with using OpenClaw.

How is 20% of users getting pwned ”crying wolf” by any reasonable measure? This is a zero authentication admin access vulnerability.

Because 20% is not “probably got hacked” and overstates the problem for most users.

That doesn’t mean this isn’t a critical vulnerability, and I think it’s insane to run OpenClaw in its current state. But the current headline will burn your credibility, because 80% of users will be fine with no action, and they’ll take future security issues less seriously as a result.

Re: OpenClaw privilege escalation vulnerability

#112
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#113
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

If you're running OpenClaw, you already threw security and reliability out the window by running LLMs on the command line. It's a bit late to start worrying now.

Re: OpenClaw privilege escalation vulnerability

#114

Earlier quoted context omitted.

Not if this is crying wolf and causing those same people to ignore the very real security risks with using OpenClaw.

How is 20% of users getting pwned ”crying wolf” by any reasonable measure? This is a zero authentication admin access vulnerability.

All the numbers you are using appear to be made up by the reddit poster. I say that as they provided no citation to them (for all I know they got them from an AI). I attempted to verify any of the numbers he used and could not. By exaggerating the numbers he is crying wolf.

Re: OpenClaw privilege escalation vulnerability

#115
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

This sounds like a classic case of "35% of statistics are made up"

Re: OpenClaw privilege escalation vulnerability

#116

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

[flagged]

Before I decide to shoot up smack, I like to ask junkies what the whole heroin experience is like, what they use it for, and how it has affected their lives.

Nina Hagen - Smack Jack

https://www.youtube.com/watch?v=nIDnN34ZZaE

>Smack Ist Dreck, Stop It Oder Verreck!

Re: OpenClaw privilege escalation vulnerability

#117
With respect...Security through obscurity is dead. We are approaching the point where only formally verified (for security) systems can be trusted. Every possible attack will be attempted. Every opening will be exploited, and every useful combination of those exploits will be done.

LLMs are patient, tireless, capable of rigorous opsec, and effectively infinite in number.

Re: OpenClaw privilege escalation vulnerability

#118
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#119
post #12

OpenClaw has over 400+ security issues and vulnerabilities. [0] Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks? Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone. [0] https://github.com/opencl…

It does not need access to your full machine. It can literally run in a vps.

The thing is that if you want it to do useful things, you kinda have to give it access to some of your accounts.

Re: OpenClaw privilege escalation vulnerability

#120

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I use it to manage a media server. And use natural language to download movies and series. Also I use to for homeassistant so I csn use natural language for vacuuming the house and things like that. I do use it for a number of other tasks but those are the most partical.
Post reply on HN