Earlier quoted context omitted.
But when the software is finished and works, who cares? Not everything is security critical. Like "Ohh you got a bunch of CRM addresses of people who go to a small time dog grooming company. You ready to sell that on the dark web?"
I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.
OpenClaw 2.0, Accidentally
161–170 of 186 posts
Re: OpenClaw 2.0, Accidentally
#162Earlier quoted context omitted.
But when the software is finished and works, who cares? Not everything is security critical. Like "Ohh you got a bunch of CRM addresses of people who go to a small time dog grooming company. You ready to sell that on the dark web?"
I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.
Re: OpenClaw 2.0, Accidentally
#163Earlier quoted context omitted.
Nobody actually uses openclaw. [0] It's all just marketing. [0] https://trends.google.com/explore?q=openclaw&date=today%201-...
Are they using something else or nothing at all?
The term "AI Agents" has real sway over the general public, apparently.
It took the Cryptocurrency world by storm a few years ago.
All basically worthless "bot" stuff like hey this really expensive setup can interpret and reply to tweets in a way that no legal department could ever possibly approve kind of thing.
Apparently that was worth billions to investors. Until everybody realized nobody actually wanted or used one, lol.
Re: OpenClaw 2.0, Accidentally
#164Open claw: aka. open door to a remote privilege escalation potentially granting root access to your computer (and if you're using it "as intended" possibly all of your email/internet logins/accounts, your credit card, etc.) to any text your model ingests from the internet... It's already true of LLMs in general that they represent a privilege escalation opportunity to any text they ingest. But with human in the loop,…
The risk here is wildly overstated, prompt injection risk is becoming vanishingly small with the latest frontier models. I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.
Literally from hours ago: https://news.ycombinator.com/item?id=49506819
Even if you believe that they can't be tricked directly, consider that these things will happily build a small node.js app in the background just to fulfill some request, run npm install... and that might've already compromised you if you're only somewhat unlucky.
Re: OpenClaw 2.0, Accidentally
#165I actually think I would like to use OpenClaw but everytime I go to the docs I give up. It feels so intimidating. There's so much stuff going on. Maybe it is good for agents who can just motor through that volume, but me personally, I would want something simpler, maybe an `OpenClaw-lite`
Re: OpenClaw 2.0, Accidentally
#166Earlier quoted context omitted.
I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.
Use a vps and only give access to what you need.
Re: OpenClaw 2.0, Accidentally
#167Earlier quoted context omitted.
Pi agent supports messaging apps now. I'm actually building my own version of Open Claw, custom tailored to me using the Pi agent SDK and Discord.
Is this something native by pi, or from 3rd party devs?
Re: OpenClaw 2.0, Accidentally
#168Earlier quoted context omitted.
Is this something native by pi, or from 3rd party devs?
Hermes supports this too, just do `/handoff telegram` and your current session is moved to telegram, it pings you on your phone, etc. It's pretty nice, though I do still prefer the Codex dedicated app for remote control
What about pi?
Re: OpenClaw 2.0, Accidentally
#169Earlier quoted context omitted.
I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.
I guess you're not one of those "Don't worry about it" people
Re: OpenClaw 2.0, Accidentally
#170Earlier quoted context omitted.
Mine is contributing to media preservation by reverse engineering Android apps/games that were forced into obsolescence by Google's policies: https://xcjs.com/blog/2026/08/29/resurrecting-2013-with-qwen...
And publishing them in F-Droid?