Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

101–110 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#101
post #82
post #71

Earlier quoted context omitted.

Which secure alternatives? I've not seen any yet.

Connecting telegram to an agent with a bunch of skills and access to isolated compute environment is largely a solved problem. I don't want to advertise but here but plenty of solutions to spin this up, including what we have built.

But if it doesn’t have access to the network, then it’s just not very useful. And if it does, then it’s just a prompt injection away from exfiltrating your data, or doing something you didn’t expect (eg deleting all your emails).

Re: OpenClaw is a security nightmare dressed up as a daydream

#102
post #57

Earlier quoted context omitted.

How is a dedicated Mac not a sandbox?

Because the bit thats import is your context (ie email, credit card, privileged data), not the place where you do the execution. Having a separate machine thats isolated is all well and good, but that doesn't protect you from someone convincing your openclaw to give them your credit card.

It doesn’t have to have a credit card number to be useful. I don’t need it to purchase anything. Mine has its own icloud and google account. I can share calendars to it. You can donate same with email or shared lists. There are ways of using openclaw without yolo’ing all your secrets.

Re: OpenClaw is a security nightmare dressed up as a daydream

#103
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

The real impressive examples get turned into SaaS prototypes and not placeholders for your imagination.

If they had vision they wouldn't be thrown out in a blog post.

Re: OpenClaw is a security nightmare dressed up as a daydream

#104
post #81

Earlier quoted context omitted.

>There are real, impressive examples of the power of agentic flows there aren't, and just like the blockchain "industry" with its "surely this is going to be the killer app" we're going to be in this circus until the money dries up. Just like the note-taking craze, the crypto ecosystem and now AI there's an almost inverse relation between the people advocating it and actually doing any meaningful work. The more anyon…

I'm gonna keep saying this forever - there are two obvious "killer apps" for crypto: 1. Semi-private blockchains, where you can rely on an actor not to be actively malicious, but still want to be able to cryptographically hold them to a past statement (think banks settling up with each other) 2. NFTs for tracking physical products through a logistics supply chain. Every time a container moves from one node to the nex…

The only "killer app" for crypto*currencies* is being a payment method. Not counting speculation. This is what they are used for right now, but the scale at which this happens doesn't justify their current valuation (even after recent losses).

Re: OpenClaw is a security nightmare dressed up as a daydream

#105
post #33

Earlier quoted context omitted.

For example?

It would probably depend on the target audience. I was very impressed by Anthropic's swarm of agents building a C compiler earlier this year with 1000 PRs per hour. Easy to nitpick that it wasn't perfect, but it sure was impressive.

You're too easily impressed

Re: OpenClaw is a security nightmare dressed up as a daydream

#106
post #82
post #71

Earlier quoted context omitted.

Which secure alternatives? I've not seen any yet.

Connecting telegram to an agent with a bunch of skills and access to isolated compute environment is largely a solved problem. I don't want to advertise but here but plenty of solutions to spin this up, including what we have built.

That isn't secure is the issue, the more things you have it hooked up to the more havoc it can cause. The environment being locked down doesn't help when you're giving it access to potentially destructive actions. And once you remove those actions, you've neutered it.

Re: OpenClaw is a security nightmare dressed up as a daydream

#107
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

OpenClaw is just like any other tool, you need to learn it before its power is available to you.

Just like anything in engineering really: you have to play around source control to understand source control, you have to play around with database indexes to learn how to optimize a database.

Once you've learned it and incorporated it into your tool set, you then have that to wield in solving problems "oh, damn, a database index is perfect for this."

To this end, folks doing flights and scheduling meetings using OpenClaw are really in that exploration / learning phase. They tackle the first (possibly uninventive thing) that comes to mind to just dive in and learn.

The real wins come down the line when you're tackling some business / personal life problem and go: "wait a second, an OpenClaw agent would be perfect for this!"

Re: OpenClaw is a security nightmare dressed up as a daydream

#108
post #33

Earlier quoted context omitted.

It would probably depend on the target audience. I was very impressed by Anthropic's swarm of agents building a C compiler earlier this year with 1000 PRs per hour. Easy to nitpick that it wasn't perfect, but it sure was impressive.

How many C compilers do we need...

[deleted]

Re: OpenClaw is a security nightmare dressed up as a daydream

#109
post #88

The security issues in OpenClaw is not even the main issue, the hype will die if there is no monetary incentive. Like I said before: If you are spending more money on tokens than the agents are making you money (or not), then it is unfortunately all for nought. The question is, who is making money on using Openclaw other than hosting?

$10/month minimax using m2.7 and openai-codex oauth $20/month will allow you to mess around with this stuff for negligible cost.

Re: OpenClaw is a security nightmare dressed up as a daydream

#110
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

> Can we up the quality of our examples just a bit? No. And there’s mundane answers why. People used to talk about phone home screens, back in the day, every iPhone had 16 spots It became wisdom everyone had the same 12 apps but then there were 4 that that were core for you and where most of your use went, but they were different apps from everyone else. So it goes for agent demos. Another reason: every agentic flow…

There are easy no-brainer productivity boosts with LLMs. For example, automatically sorting your email by topic.

Nobody shows this because the technology is still immature and very shit.

Post reply on HN