Live data from Hacker News

OpenClaw 2.0, Accidentally

openclaw.ai

161–170 of 186 posts

Re: OpenClaw 2.0, Accidentally

#161
post #158

Earlier quoted context omitted.

But when the software is finished and works, who cares? Not everything is security critical. Like "Ohh you got a bunch of CRM addresses of people who go to a small time dog grooming company. You ready to sell that on the dark web?"

I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.

Use a vps and only give access to what you need.

Re: OpenClaw 2.0, Accidentally

#162
post #158

Earlier quoted context omitted.

But when the software is finished and works, who cares? Not everything is security critical. Like "Ohh you got a bunch of CRM addresses of people who go to a small time dog grooming company. You ready to sell that on the dark web?"

I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.

I guess you're not one of those "Don't worry about it" people

Re: OpenClaw 2.0, Accidentally

#163

Earlier quoted context omitted.

Nobody actually uses openclaw. [0] It's all just marketing. [0] https://trends.google.com/explore?q=openclaw&date=today%201-...

Are they using something else or nothing at all?

Nothing afaict.

The term "AI Agents" has real sway over the general public, apparently.

It took the Cryptocurrency world by storm a few years ago.

All basically worthless "bot" stuff like hey this really expensive setup can interpret and reply to tweets in a way that no legal department could ever possibly approve kind of thing.

Apparently that was worth billions to investors. Until everybody realized nobody actually wanted or used one, lol.

Re: OpenClaw 2.0, Accidentally

#164

Open claw: aka. open door to a remote privilege escalation potentially granting root access to your computer (and if you're using it "as intended" possibly all of your email/internet logins/accounts, your credit card, etc.) to any text your model ingests from the internet... It's already true of LLMs in general that they represent a privilege escalation opportunity to any text they ingest. But with human in the loop,…

The risk here is wildly overstated, prompt injection risk is becoming vanishingly small with the latest frontier models. I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.

There must be a bulk discount on those mindcuffs, considering there's a prompt injection or a related confused deputy story on HN every other day.

Literally from hours ago: https://news.ycombinator.com/item?id=49506819

Even if you believe that they can't be tricked directly, consider that these things will happily build a small node.js app in the background just to fulfill some request, run npm install... and that might've already compromised you if you're only somewhat unlucky.

Re: OpenClaw 2.0, Accidentally

#165

I actually think I would like to use OpenClaw but everytime I go to the docs I give up. It feels so intimidating. There's so much stuff going on. Maybe it is good for agents who can just motor through that volume, but me personally, I would want something simpler, maybe an `OpenClaw-lite`

When I tried OpenClaw it quickly turned into a lethargic mess which I really didn't see myself wanting to maintain long term. I looked at other alternatives which were similar enough to do what I was looking for (mostly scheduled tasks using data on my computer and some API data). I saw a mention of nanoclaw which I looked at but didn't try personally. I eventually settled on trying picoclaw[1] because it was extremely small, fast, and had enough features to do the job for me. It is under 10mb, fairly straight forward go codebase, and works with multiple model providers or locally hosted.

1 https://picoclaw.io/

Re: OpenClaw 2.0, Accidentally

#166
post #158

Earlier quoted context omitted.

I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.

Use a vps and only give access to what you need.

Let's be honest, the number of people who are doing that << the amount of OpenClaw-preinstalled hardware that's being sold alone

Re: OpenClaw 2.0, Accidentally

#167
post #160

Earlier quoted context omitted.

Pi agent supports messaging apps now. I'm actually building my own version of Open Claw, custom tailored to me using the Pi agent SDK and Discord.

Is this something native by pi, or from 3rd party devs?

Hermes supports this too, just do `/handoff telegram` and your current session is moved to telegram, it pings you on your phone, etc. It's pretty nice, though I do still prefer the Codex dedicated app for remote control

Re: OpenClaw 2.0, Accidentally

#168
post #167
post #160

Earlier quoted context omitted.

Is this something native by pi, or from 3rd party devs?

Hermes supports this too, just do `/handoff telegram` and your current session is moved to telegram, it pings you on your phone, etc. It's pretty nice, though I do still prefer the Codex dedicated app for remote control

Thats cool, did not know that, thanks!

What about pi?

Re: OpenClaw 2.0, Accidentally

#169
post #158

Earlier quoted context omitted.

I'd assume anything empowered to read+send email from my personal accounts and read+modify my calendars to be security critical.

I guess you're not one of those "Don't worry about it" people

Hard to turn off when one's professional job/value is 'worry about things and find ways to efficiently minimize risk'

Re: OpenClaw 2.0, Accidentally

#170
post #140
post #36

Earlier quoted context omitted.

Mine is contributing to media preservation by reverse engineering Android apps/games that were forced into obsolescence by Google's policies: https://xcjs.com/blog/2026/08/29/resurrecting-2013-with-qwen...

And publishing them in F-Droid?

I don't think the licensing would allow for that. I might get away with archive.org, but I'm still looking into that.
Post reply on HN