Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...
my claw controls my old M2 mac, mostly my claw uses Claude code to code
OpenClaw privilege escalation vulnerability
121–130 of 306 posts
Re: OpenClaw privilege escalation vulnerability
#122[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]
Re: OpenClaw privilege escalation vulnerability
#123Re: OpenClaw privilege escalation vulnerability
#124Earlier quoted context omitted.
I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc ( https://github.com/sgillen/sf-civic-digest ). It also have mine automatically grabs a spot at my gym when spots are released because I always forget. I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any ti…
>It also have mine automatically grabs a spot at my gym when spots are released because I always forget. seems far more efficient/reliable to get codex/claude code to write and set up a bot that does this.
But he already did this. With a bonus of it will continue to work in the future if something breaks or changes. Human time is more precious than computing resources nowadays.
Re: OpenClaw privilege escalation vulnerability
#125Re: OpenClaw privilege escalation vulnerability
#126Earlier quoted context omitted.
[flagged]
Before I decide to shoot up smack, I like to ask junkies what the whole heroin experience is like, what they use it for, and how it has affected their lives. Nina Hagen - Smack Jack https://www.youtube.com/watch?v=nIDnN34ZZaE >Smack Ist Dreck, Stop It Oder Verreck!
This is exactly why I have zero interest in engaging with people over this topic.
Re: OpenClaw privilege escalation vulnerability
#127OpenClaw creator here. This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance." The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerS…
Re: OpenClaw privilege escalation vulnerability
#128Re: OpenClaw privilege escalation vulnerability
#129Earlier quoted context omitted.
Before I decide to shoot up smack, I like to ask junkies what the whole heroin experience is like, what they use it for, and how it has affected their lives. Nina Hagen - Smack Jack https://www.youtube.com/watch?v=nIDnN34ZZaE >Smack Ist Dreck, Stop It Oder Verreck!
So you're comparing a generic tool you can tailor to your own needs to drugs? This is exactly why I have zero interest in engaging with people over this topic.
Re: OpenClaw privilege escalation vulnerability
#130Earlier quoted context omitted.
1/5 rounds to “probably” when discussing security.
The 135k number appears to be pulled out of thin air? No idea where the 65% comes from. The command the post gives to list paired devices isn't correct. These are red flags.
My interpretation is that 135k instances are vulnerable, but of those there's more conditions that need to be met, specifically:
These need to be multi-user systems where there are users with 'basic pairing' privileges. Which I don't think is very common, most instances are single-user.
So way less than the 135k number. I think a more accurate title would have been "If you're running OpenClaw, you are probably vulnerable" but not "you probably got hacked", that's just outright false and there's no evidence that the exposed users were ALL hacked.