Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

111–120 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#111
post #62

Earlier quoted context omitted.

Right. Pretty impressive. What percentage of people will think that’s life changing? Because then we’re not talking about “can everyone up their demos to life changing, please?”, we’re talking about “can everyone use demos Oarch thinks are life changing, please?” - and “can build a MVP C compiler draft that barely works for $XXK” isn’t really that compelling to me, and we’re both software engineers, and my whole day…

I'm still sure we can do a little better though. Maybe a personalised diet and exercise plan based on a huge range of information: preferences, biometrics, habit forming, disposable income, your local area etc

Like putting glue on your pizza?

Re: OpenClaw is a security nightmare dressed up as a daydream

#112
post #103
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

The real impressive examples get turned into SaaS prototypes and not placeholders for your imagination. If they had vision they wouldn't be thrown out in a blog post.

This is the tech equivalent of my girlfriend goes to another school.

If someone implemented something impressive with this stuff, they wouldnt be keeping it quiet. False negatives are unproductive

Re: OpenClaw is a security nightmare dressed up as a daydream

#113
post #59

Earlier quoted context omitted.

You know it’s open source code, right?

do you think anybody has actually read all 700k lines of the ai generated code?

Not even LLMs can read that.

I asked various models to list configurations options of OpenClaw and none of them could make heads or tails of it.

Re: OpenClaw is a security nightmare dressed up as a daydream

#115
post #81

Earlier quoted context omitted.

>There are real, impressive examples of the power of agentic flows there aren't, and just like the blockchain "industry" with its "surely this is going to be the killer app" we're going to be in this circus until the money dries up. Just like the note-taking craze, the crypto ecosystem and now AI there's an almost inverse relation between the people advocating it and actually doing any meaningful work. The more anyon…

I'm gonna keep saying this forever - there are two obvious "killer apps" for crypto: 1. Semi-private blockchains, where you can rely on an actor not to be actively malicious, but still want to be able to cryptographically hold them to a past statement (think banks settling up with each other) 2. NFTs for tracking physical products through a logistics supply chain. Every time a container moves from one node to the nex…

Not only do you not need the blockchain for either of those things, you don't want it.

Think it through. How do you actually "cryptographically hold" someone to anything? You take them to court.

Guess what you can do, right now, without the blockchain? That's right, you can take them to court.

You're just reinventing normal contract law with extra steps.

The cryptographic part doesn't even help you when you can just say in court that "here are our records that show we gave them these packages, here are our records of customers filing complaints that they never got them" and that is completely fine.

Re: OpenClaw is a security nightmare dressed up as a daydream

#116
A thinly vailed ad for yet another variant that inevitably leads to more confusion and yet another future security nightmare. The authors (should) know better. No, the purpose of OpenClaw is not to immediately give it all your private accounts and live in bliss and no, their system is not better long term than following the mainline developments that have enough eyes (and bots) on them by now.

Re: OpenClaw is a security nightmare dressed up as a daydream

#117

Earlier quoted context omitted.

This problem is inherently unsolvable because LLMS are prone to hallucinations and prompt injection attacks. I think that you're insinuating that these things can be fixed, but to my knowledge, both of these problems are practically unsolvable. If that turns out to be false, then when they are solved, fully autonomous AI agents may become feasible. However, because these problems are unsolvable right now, anyone who…

>> This problem is inherently unsolvable because LLMS are prone to hallucinations and prompt injection attacks. Okay, but aren't you making the mistake of assuming that we will always be stuck with LLMs, and a more advanced form of AI won't be invented that can do what LLMs can do, but is also resistant or immune to these problems? Or perhaps another "layer" (pre-processing/post-processing) that runs alongside LLMs?

I don't think that is in the scope of the discussion here.

You can be as much of a futurist as you'd like, but bear in mind that this post is talking about OpenClaw.

Re: OpenClaw is a security nightmare dressed up as a daydream

#118
post #44
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

> why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. This AI wave is filled with "ideas guys/gals" who thought they had an amazing awesome idea and if only they knew how to program they could make a best-selling billion dollar idea, being confronted with the reality that their ideas are really uninteresting as well. They're still happy to…

the whole obsequious nature of how LLMs also amp them up thinking they're onto something incredible is throwing gas on this dumpster fire.

"What a great idea! This will revolutionize linkedin commenting. Let's implement it together."

Re: OpenClaw is a security nightmare dressed up as a daydream

#119
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

That's a fair point, and I guess the marketing problem here is intrinsic: If the problem is trivial, off-the-shelf solutions abound; if it's idiosyncratic, almost nobody will be able to relate (as you can't assume that people will do the transfer of "if it can solve complex problem I don't understand A, it'll probably be able to solve my complex problem B" for promotional material).
Post reply on HN