Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

201–210 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#201

Earlier quoted context omitted.

This problem is inherently unsolvable because LLMS are prone to hallucinations and prompt injection attacks. I think that you're insinuating that these things can be fixed, but to my knowledge, both of these problems are practically unsolvable. If that turns out to be false, then when they are solved, fully autonomous AI agents may become feasible. However, because these problems are unsolvable right now, anyone who…

>think that you're insinuating that these things can be fixed, but to my knowledge, both of these problems are practically unsolvable. This is provably not true. LLMs CAN be restricted and censored and an LLM can be shown refusing an injection attack AND not hallucinating. The world has seen a massive reduction in the problems you talk about since the inception of chatgpt and that is compelling (and obvious) to anyon…

I'm a LLM evangelist. I think the positive impacts will far outweigh any negatives against it over time. That said, I'm not delusional about the limitations of the technology and there are a lot of them.

> This is provably not true. LLMs CAN be restricted and censored and an LLM can be shown refusing an injection attack AND not hallucinating.

The remediations that are in place because a engineering/safety/red team did its job are commendable. However, that does not speak to the innate vulnerability of these models, which is what we're talking about. I don't fear remediated CVEs. I fear zero day prompt injection attacks and I fear hallucinations, which have NOT been solved for. I don't know what you're talking about there. If you use LLMs daily and extensively like I do, then you know these things lie constantly and effortlessly. The only reason those lies aren't destructive is because I'm already a skilled engineer and I catch them before the LLM makes the changes.

These problems ARE inherent to LLMs. Prompt injection and hallucinations are problems that are NOT solvable at this time. You can defend against the ones you find via reports/telemetry but it's like trying to bale water out of a boat with a colander.

You're handing a toddler a loaded gun and belly laughing when it hits a target, but you're absolutely ignoring the underlying insanity of the situation. And I don't really know why.

Re: OpenClaw is a security nightmare dressed up as a daydream

#202

Earlier quoted context omitted.

Of course there is! You want an AI agent to be able to do some things, but not others. OpenClaw currently gets access to both those sets. There's no reason to. I've made my own AI agent ( https://github.com/skorokithakis/stavrobot ) and it has access to just that one WhatsApp conversation (from me). It doesn't get to read messages coming from any other phone numbers, and can't send messages to arbitrary phone numbers…

> "Give it access to everything, even if it doesn't need it" is not the only security model. You're using stavrobot instead of OpenClaw precisely because the purpose of OpenClaw is to do everything ; a tool to do everything needs access to everything. OpenClaw could be kinda useful and secure if it were stavrobot instead, if it could only do a few limited things, if everything important it tried to do required human…

Yeah, I don't know, I don't see what I'm missing out on. There isn't something I wanted it to do but couldn't because of the security model.

Re: OpenClaw is a security nightmare dressed up as a daydream

#203

Earlier quoted context omitted.

The purpose of a personal assistant isn’t to fit people into your calendar. It’s to filter them out. They serve as a barrier to your time, not an enabler for other people to claim it. I don’t see how an AI can meaningfully accomplish that any better than simply just making yourself more difficult to reach.

> The purpose of a personal assistant isn’t to fit people into your calendar. It’s to filter them out. They serve as a barrier to your time, not an enabler for other people to claim it. Scheduling in a larger org and/or with multiple equally busy people is a non-trivial, complex task; it makes sense to dedicate resources to the task. Good Executive Assistants are generally fairly smart folks, in my experience. When t…

I'm a pretty busy person professionally. When I feel like I'm being pushed to "scale" my time and attention, I take that as a signal to do the opposite: do less, and do those remaining things more meaningfully.

Trying to do more is a losing game, and AI assistants just paper over that. We all have finite time and attention. I think a pragmatic engineering approach is the right one here: consider that as a non-negotiable constraint, a fact of the physical world, not something to magic away.

Re: OpenClaw is a security nightmare dressed up as a daydream

#204

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

> The whole point of OpenClaw is to run AI actions with your own private data, your own Gmail, your own WhatsApp, etc. There's no point in using OpenClaw with that much restriction on it.

Every submission I've seen on HN involving OpenClaw will have a comment with this sentiment. "What's the point if you don't give it access to your data ... And if you do, it's a security nightmare ... hence OpenClaw is evil"

It's a quick way to spot the person who's never spent any real time with OpenClaw.

I always used to give use cases that don't have you give it much (if any) of your data. Examples on how you can give it only a tiny amount of data (many HN users give more just in their HN profile).

But I tire of countering folks who clearly have not even tried it.

(And I'm not even that pro-OpenClaw. I was using it, then a bug on my system prevented me from using it - a week without OpenClaw and so far no withdrawal symptoms).

Re: OpenClaw is a security nightmare dressed up as a daydream

#205
post #72
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

Some of it is lack of imagination, but some of it is because many truly visionary examples would largely sound stupid to most of today's audience. Imagine it's 2007 and you're explaining how the smartphone will change society over the next 20 years: - A photo sharing app will change restaurants, public spaces, and the entire travel industry across the world - The smartphone will bring about regime change in Egypt, Tu…

- A nation-agnostic online currency (and its offshoots) would lead to a multi-polar world.

- Publicly waving your resume around will passively invite job interviews.

There's a new OpenClaw adaptation, Ottie, that I think could be a bank manager, bank teller, stockbroker, piggy bank, accountant, wallet, security guard and credit card provider all rolled into one. I just haven't used it yet. https://ottie.xyz/

So that would be:

- Digital sidekick weeds out parasitic relationships.

There has to be tremendous value in that.

When solutions are looking for problems, it means that things may seem oversold when in fact they are still undersold.

Re: OpenClaw is a security nightmare dressed up as a daydream

#206
post #173
post #130

Earlier quoted context omitted.

Booking a flight is the kind of thing I want to dedicate my full attention to. It's expensive, and the timing and details matter a lot. I'm happy for the voice assistant to add stuff to my grocery list, though. The consequences are not serious if it screws up a letter or something.

Apparently I'm the only one here who finds it to be one of the worst things I ever have to do, I hate managing the combinatorial tab explosion by hand. Compounded by the adversarial nature of the price-setting algorithms that jack up the price on you if you show too much interest by researching too intensively. Just booked a flight for our family in two parts, and booking for one set of us made the price for the seco…

I think we literally have those agents today, albeit implemented in meat rather than silicon. Any particular reason you elect not to use the free-to-you travel agent? Generally they are the same or less expensive and able to work in your best interests.

Re: OpenClaw is a security nightmare dressed up as a daydream

#207
I'd argue there's really no way to make OpenClaw truly safe, no matter what you do. The only place it really makes sense is within trusted environments, like B2B coordination or tightly controlled processes between systems that share the same assumptions.

The moment it steps outside that boundary, you're sending the bot into unpredictable territory. At that point, things can get ambiguous pretty quickly, and in some cases even adversarial.

Re: OpenClaw is a security nightmare dressed up as a daydream

#208
post #173
post #130

Earlier quoted context omitted.

Booking a flight is the kind of thing I want to dedicate my full attention to. It's expensive, and the timing and details matter a lot. I'm happy for the voice assistant to add stuff to my grocery list, though. The consequences are not serious if it screws up a letter or something.

Apparently I'm the only one here who finds it to be one of the worst things I ever have to do, I hate managing the combinatorial tab explosion by hand. Compounded by the adversarial nature of the price-setting algorithms that jack up the price on you if you show too much interest by researching too intensively. Just booked a flight for our family in two parts, and booking for one set of us made the price for the seco…

Booking flights/tickets is terrible. And then the dark patterns… wonder if OpenClaw can navigate these? Anyway, it is nothing compared to sourcing electronic components, there are literally thousands and thousands of different manufacturers, lead times, moq’s … for the same component, leading to super hard to search and filter database/websites that are slow as molasses.

Re: OpenClaw is a security nightmare dressed up as a daydream

#209
post #173

Earlier quoted context omitted.

Apparently I'm the only one here who finds it to be one of the worst things I ever have to do, I hate managing the combinatorial tab explosion by hand. Compounded by the adversarial nature of the price-setting algorithms that jack up the price on you if you show too much interest by researching too intensively. Just booked a flight for our family in two parts, and booking for one set of us made the price for the seco…

I think we literally have those agents today, albeit implemented in meat rather than silicon. Any particular reason you elect not to use the free-to-you travel agent? Generally they are the same or less expensive and able to work in your best interests.

Travel agents duh. Reminds me of the classic silicon valley startup trope that most tech bro’s are basically trying to pitch a product that replaces their mother.

Re: OpenClaw is a security nightmare dressed up as a daydream

#210

Earlier quoted context omitted.

Can it suggest me to do the things I should do ? Can it talk to me into overcoming what's blocking me from completing tasks at an emotional level ? :)

nope. It won't even help you understand that the 20 second task you've been putting off for 6 months causing anxiety will only take 20 seconds (nor will we learn from this)

Or the fact that in the time it took me to read this thread I could have finished that task. Sometimes I really want to punch my brain in its stupid face lol.
Post reply on HN