Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

251–260 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#251
Every LLM evangelist seems to forget that there is a reason why LLMs work so well for coding. It's because there were and are preexisting non-LLM validation tools for coding. The slop doesn't make it past linters, compilers, cone analysis and other tools, and then there is a second barrier in the form of code review. And even will these guardrails LLMs often produce substandard output.

Buying a ticket, writing an email, setting calendars or fiddling with files on the drive etc. have none of these guardrails. LLMs can and will simply oneshot the slop into a real system, without neither computer nor human validation.

Re: OpenClaw is a security nightmare dressed up as a daydream

#253
post #216

Earlier quoted context omitted.

I run my own claw on a hetzner setup. The claw writes his own code based on some rules I gave to him (20 prs per day). it's active on moltbook and has access to my whatsapp, Gmail etc. dangerous it is. But fun as well. Specially fun to see which features it decides to build. https://github.com/holoduke/myagent

What gpu hardware/model? Good enough?

Small vps 5 euros a month. Uses the Claude cli . No compute needed on running machine.

Re: OpenClaw is a security nightmare dressed up as a daydream

#254

Earlier quoted context omitted.

>think that you're insinuating that these things can be fixed, but to my knowledge, both of these problems are practically unsolvable. This is provably not true. LLMs CAN be restricted and censored and an LLM can be shown refusing an injection attack AND not hallucinating. The world has seen a massive reduction in the problems you talk about since the inception of chatgpt and that is compelling (and obvious) to anyon…

I'm a LLM evangelist. I think the positive impacts will far outweigh any negatives against it over time. That said, I'm not delusional about the limitations of the technology and there are a lot of them. > This is provably not true. LLMs CAN be restricted and censored and an LLM can be shown refusing an injection attack AND not hallucinating. The remediations that are in place because a engineering/safety/red team di…

>The remediations that are in place because a engineering/safety/red team did its job are commendable. However, that does not speak to the innate vulnerability of these models, which is what we're talking about.

I am talking about the innate vulnerability. The LLM model itself can be censored and controlled to do only certain behaviors. We have an actual degree of control here.

>If you use LLMs daily and extensively like I do, then you know these things lie constantly and effortlessly.

Yes and these lies over the last 2 or 3 years have gotten significantly less.

>These problems ARE inherent to LLMs. Prompt injection and hallucinations are problems that are NOT solvable at this time.

Again not true. This is not a binary solve or unsolved situation. There is progress in this area. You need to think in terms of a probability of a successful hallucination or prompt injection. There is huge progress in bringing down that probability. So much so that when you say they are NOT solvable it is patently false from both from a current perspective and even when projecting into the future.

>You're handing a toddler a loaded gun and belly laughing when it hits a target, but you're absolutely ignoring the underlying insanity of the situation. And I don't really know why.

Such an extreme example. It's more like giving a 12 year old a credit card and gun. It doesn't mean that 12 year old is going to shoot up a mall or off himself. The risk is there, but it's not guaranteed that the worst will happen.

Re: OpenClaw is a security nightmare dressed up as a daydream

#255
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

[deleted]

Re: OpenClaw is a security nightmare dressed up as a daydream

#256
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

I feel like part of it is the obsession with AI assistants a la Jarvis from Iron Man, but most people do not have the skills or need for an AI agent to support technical work, so they just end up trying to do mundane things that have already been largely streamlined by smartphones, while the primary advantages of these kind of agentic workflows are in technical work.

Re: OpenClaw is a security nightmare dressed up as a daydream

#257
post #46

Earlier quoted context omitted.

The dream of the middle class IT drone is to become the executive Office Man: he shouts at his PA and she books his flights. Now AI can provide a simulacrum of his fondest aspiration, to be too important to click through booking.com and make someone else do it for him.

Been a middle-class IT drone much of my adult life. This is not my dream. In fact I just realized that one reason I don't like AI dev tools is because they turn me into the kind of dickhead manager I despise: one who doesn't understand the code or the nature of the work involved, just gives orders on what needs to be built and complains when it doesn't work.

I fix it by micromanaging it. Which class, method, function, module - I dictate the low level structure and features. I dump my all my hard earned coding opinions in a profoundly crafted markdown file.

Re: OpenClaw is a security nightmare dressed up as a daydream

#259

Earlier quoted context omitted.

> booking a flight > Doing this manually is already pretty trivial No, it’s not! You are the one who made it trivial by using three words to define! How about if I could only fly out between 9 am-noon next Friday? Also, combine it with hotel and rental car. Many times total $ between sites could be a difference of close to $200 or more along with better itinerary. That’s just the surface. The more preferences you add…

get a travel agent? Probably more reliable and corp ones exist.

> get a travel agent?

I think: to Uber founder, you’d have said get a driver or yellow cab :-)

To TurboTax founder, you’d have said get a tax accountant :-)

Re: OpenClaw is a security nightmare dressed up as a daydream

#260
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

I love when they use making a restaurant reservation as the example. On a list of things keep me up at night that is somewhere around #6,054, yet apparently for many tech bros that’s a top 10 life problem.
Post reply on HN