Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

271–280 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#271

Earlier quoted context omitted.

Millions of people die every year from tobacco, and tobacco companies fought for decades to deny their product causes cancer. In the 20th century alone it's estimated something like 100 million people died world wide thanks to smoking. That's just one example off the top of my head. There are countless others involving corporations killing people either directly or indirectly in the pursuit of profits. And that's bef…

We have governments to stop the obvious ones like tobacco too.

What point do you think you're making?

Re: OpenClaw is a security nightmare dressed up as a daydream

#272
post #86
post #72

Earlier quoted context omitted.

Some of it is lack of imagination, but some of it is because many truly visionary examples would largely sound stupid to most of today's audience. Imagine it's 2007 and you're explaining how the smartphone will change society over the next 20 years: - A photo sharing app will change restaurants, public spaces, and the entire travel industry across the world - The smartphone will bring about regime change in Egypt, Tu…

Instagram Arabian spring Uber Airbnb Cloud-ification/shift to web apps and mobile-first ....tiktok? Or is YouTube considered "short video sharing app"? Because I see no evidence tiktok in particular killing TV... To be fair, QR code did hit print magazines/newspapers in Germany (just as an example; English wiki was not elaborating on initial history of public use/perception) in late 2007, so that one wasn't nearly as…

Not only is TV alive and well, we're even getting channels back with the content splintered across multiple streaming platforms.

Re: OpenClaw is a security nightmare dressed up as a daydream

#273
post #227

Earlier quoted context omitted.

I think you lived in a strange bubble when you were a kid. When I was a teenager in the 90s, we'd have paper maps that we'd bring with us. We had no GPS. I don't think we knew what GPS was. In the late 90s we'd print out directions from MapQuest. That was a game-changer. Still no GPS, though. As an adult in the early 00s, I was still printing out MapQuest maps. In 2004 I got a car with a built-in navigation system! (…

I remember GPS being something mountaineers had. People who would take their jeeps up to the glacier had them. Boats also had them. Coincidentally I was a fisherman back then and did observe my captain using a super fancy navigation device with an interactive map (and yes the map did come on a DVD); I also knew a couple of jeep men (or jeppakarlar as we call them in Icelandic) who had something similar (though more c…

Air travel has changed a lot.

Booking, boarding, change/gate notifications, rebooking options, customs and immigration is done via phone.

Transit to/from the airport via Uber or a transit pass stored in your smartphone wallet.

Baggage tracking via airtags

Yeah, there's vague precedents for this stuff from the desktop computer era, but it only _really_ works when you've got an internet-connected device in your pocket.

Re: OpenClaw is a security nightmare dressed up as a daydream

#274

Earlier quoted context omitted.

I remember GPS being something mountaineers had. People who would take their jeeps up to the glacier had them. Boats also had them. Coincidentally I was a fisherman back then and did observe my captain using a super fancy navigation device with an interactive map (and yes the map did come on a DVD); I also knew a couple of jeep men (or jeppakarlar as we call them in Icelandic) who had something similar (though more c…

Air travel has changed a lot. Booking, boarding, change/gate notifications, rebooking options, customs and immigration is done via phone. Transit to/from the airport via Uber or a transit pass stored in your smartphone wallet. Baggage tracking via airtags Yeah, there's vague precedents for this stuff from the desktop computer era, but it only _really_ works when you've got an internet-connected device in your pocket.

Ahhh, payment via phones is also a new thing that I think very few people saw coming (including me). However it is also a very recent development and not really a part of the supposed smartphone revolution. In 2007 we did not have touchless payments (except in some public transit systems; gyms; etc. but it was limited to a special cards you couldn’t use for anything else) so this is definitely a new capability which was probably hard to sell in 2007.

The others you mentions, I would argue against. Yes it is convenient to order a taxi via an app on your phone, but in 2007 you could do so via SMS or a phone call, so not much has change really other then we now have one more interface to pick from.

I don’t see how smartphones have changed rebooking, nor customs, and especially not immigration which has become 100x more of a headache then it was in 2007. And finally, airtags are a separate technology from smartphones.

Re: OpenClaw is a security nightmare dressed up as a daydream

#275
post #224
post #173

Earlier quoted context omitted.

Apparently I'm the only one here who finds it to be one of the worst things I ever have to do, I hate managing the combinatorial tab explosion by hand. Compounded by the adversarial nature of the price-setting algorithms that jack up the price on you if you show too much interest by researching too intensively. Just booked a flight for our family in two parts, and booking for one set of us made the price for the seco…

I think it depends on your priorities and needs. I just booked a round trip for myself, plus two more flights for quicker hops while I'm away, and I didn't spend much time on it at all. I just looked at Google flights, picked the flights I wanted, and then ended up buying them through Chase with points. Chase's travel website is among the worst I've ever used, but it wasn't hard. Then I went to the airline's website…

Yeah, maybe just finding a small shop is the move. Surprising that they can get you something for less than buying direct can after their fee, though!

Re: OpenClaw is a security nightmare dressed up as a daydream

#276

Earlier quoted context omitted.

The purpose of a personal assistant isn’t to fit people into your calendar. It’s to filter them out. They serve as a barrier to your time, not an enabler for other people to claim it. I don’t see how an AI can meaningfully accomplish that any better than simply just making yourself more difficult to reach.

This is it right here. I've long thought about this one and whether I should bother with an AI agent that can do all of this stuff for me, but the reality is both what you said and I'm not rich enough. Do I want the AI Agent to take my bank account and automatically pay some bill every month in full? What if you go a little over that month due to an emergency expense you weren't prepared for? And it's not a matter of…

>Do I want the AI Agent to take my bank account and automatically pay some bill every month in full?

Also this supposed use case is called "Autopay" and requires zero AI. A lot of people still don't use it. Even when it includes a discount!

Re: OpenClaw is a security nightmare dressed up as a daydream

#277

Earlier quoted context omitted.

Air travel has changed a lot. Booking, boarding, change/gate notifications, rebooking options, customs and immigration is done via phone. Transit to/from the airport via Uber or a transit pass stored in your smartphone wallet. Baggage tracking via airtags Yeah, there's vague precedents for this stuff from the desktop computer era, but it only _really_ works when you've got an internet-connected device in your pocket.

Ahhh, payment via phones is also a new thing that I think very few people saw coming (including me). However it is also a very recent development and not really a part of the supposed smartphone revolution. In 2007 we did not have touchless payments (except in some public transit systems; gyms; etc. but it was limited to a special cards you couldn’t use for anything else) so this is definitely a new capability which…

Hand-waving away ride-sharing as not much of a change makes me wonder what you would actually consider to be significant. It completely upended the taxi business.

2007: arrive in a new city, figure out who to call (or maybe text) for that particular city, wait, hope someone will pick you up and understand enough of your language and the local geography to get you where you want to go, possibly some unpleasant haggling over the fare

2026: arrive in a new city/country, open Uber, specify in the app precisely where you want to go, choose a vehicle, when to get picked up, etc, track vehicle progress in real-time, up-front pricing

And that's the consumer side. The provider side was even more radically changed.

If you don't see how smartphones changed the experience of flying... maybe you don't fly anywhere?

Airtags are entirely dependent on the ubiquity of smartphones.

Re: OpenClaw is a security nightmare dressed up as a daydream

#278
post #67

Earlier quoted context omitted.

> The whole point of OpenClaw is to run AI actions with your own private data, your own Gmail, your own WhatsApp, etc. There's no point in using OpenClaw with that much restriction on it. Hard disagree. I have OpenClaw running with its own gmail and WhatsApp running on its own Ubuntu VM. I just used it to help coordinate a group travel trip. It posted a daily itinerary for everyone in our WhatsApp group and handled a…

Do you need the simcard for WhatsApp?

I believe you can use a virtual number/VOIP (like Twilio or Google Voice), but I want to be able to eventually use SMS where WhatsApp can't be used, so I do know some services identify "non residential" SMS phone numbers (for example I've seen Google Voice numbers blocked) so I wanted to prevent that from happen. Again, key thing here for me is that my assistant appears to be a human.

Re: OpenClaw is a security nightmare dressed up as a daydream

#279

Earlier quoted context omitted.

Ahhh, payment via phones is also a new thing that I think very few people saw coming (including me). However it is also a very recent development and not really a part of the supposed smartphone revolution. In 2007 we did not have touchless payments (except in some public transit systems; gyms; etc. but it was limited to a special cards you couldn’t use for anything else) so this is definitely a new capability which…

Hand-waving away ride-sharing as not much of a change makes me wonder what you would actually consider to be significant. It completely upended the taxi business. 2007: arrive in a new city, figure out who to call (or maybe text) for that particular city, wait, hope someone will pick you up and understand enough of your language and the local geography to get you where you want to go, possibly some unpleasant hagglin…

I have already said navigation and tuchless payments are worthy examples of smartphones providing new and unpredictable innovations.

Your ride sharing experience sound more like you would expect from any consumer product gaining a global market share (or even monopoly). 1980 - Arrive in a new city and not knowing how to get a hamburger. 2000 - Arrive in a new city, find the nearest McDonalds and get your usual BigMac.

Re: OpenClaw is a security nightmare dressed up as a daydream

#280

Earlier quoted context omitted.

I'm a LLM evangelist. I think the positive impacts will far outweigh any negatives against it over time. That said, I'm not delusional about the limitations of the technology and there are a lot of them. > This is provably not true. LLMs CAN be restricted and censored and an LLM can be shown refusing an injection attack AND not hallucinating. The remediations that are in place because a engineering/safety/red team di…

>The remediations that are in place because a engineering/safety/red team did its job are commendable. However, that does not speak to the innate vulnerability of these models, which is what we're talking about. I am talking about the innate vulnerability. The LLM model itself can be censored and controlled to do only certain behaviors. We have an actual degree of control here. >If you use LLMs daily and extensively…

> You need to think in terms of a probability of a successful hallucination or prompt injection.

I would venture to say that an ACID compliant deterministic database has a 99.999999999999999999% chance of retrieving the correct information when asked by the correct SQL statement. An LLM on the other hand is more like 90%. LLMs by their innate code instruction are meant to hallucinate. I don't necessarily disagree with your sentiment, but the gap from 90% to 99.999999999999999999% is much greater of than the 0% to 90% improvement...unless something materially changes about how an LLM works at the bytecode level.

Post reply on HN