Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

291–300 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#292
post #219

Earlier quoted context omitted.

But is that a better experience than just using your visa? Nobody wants to wait at the cashier for 15 minutes to pay for their groceries, which is what has to happen if you really want the decentralized experience. Otherwise you really are just reinventing a worse, centralized payment rails. Volatility and wait times are features of crypto, not bugs, but they make for terrible payment experiences. Writing that I feel…

Doesn't lightning settle basically instantly, while still being decentralized? You're just trading signed transactions iirc, with settlement happening whenever.

The settlement happening whenever is a problem. Instant authorization is very different from a practical settlement model.

At least with card networks, there are layers of liability if solvency issues occur. There’s merchant protections from the acquiring bank and if for some reason the acquiring bank fails there is the guarantee of the card network.

On the issuing side there are chargebacks. I hate chargebacks as much as the next startup bro but consumer protections are a necessary aspect of a functioning payment rail. There are reasons we don’t use ACH for everything.

I think hand waving the pesky settlement details is absurd. The settlement process is the payment rail.

If you do want those protections you end up back with a custodial wallet, which brings us back to a centralized model.

I’m not arguing crypto doesn’t have its place in the universe, I am arguing it’s a very bad payments product.

Re: OpenClaw is a security nightmare dressed up as a daydream

#293
post #125

I love how despite all this, the author still uses the language: > We’re simply not there yet to let the agents run loose As if there aren’t fundamental properties that would need to change to ever become secure.

Personally, if I could run capable-enough inference on hardware I control, and could rely on the harness asking me for mechanistic confirmation before the agent can take consequential actions, I'd do it immediately.

Consequential actions like searching the web or downloading packages or dependencies or doing most anything useful?

Re: OpenClaw is a security nightmare dressed up as a daydream

#294
post #228

Earlier quoted context omitted.

> Software isn't as faultless as you suggest. The default alarm app on my phone occasionally fails to go off (not an issue with Silent Mode or DND). I'm guessing this is an iPhone, and yeah it's because that software is just bad. I've helped my Mom try to get her phone to ring, like, 12 times now and I've failed each time. And I'm a dev! So, point taken. > Life is short. It is absolutely worthwhile to spend as little…

Why do you guess it's an iPhone? I switched to an iPhone because my OnePlus phone failed to ring or play alarms due to a constantly crashing and restarting media indexer service (I could only tell this is what was happening from the logs).

Because all of my family members have had sound issues with iPhones. Ringer, alarms, media. Mostly software, I think. I also had an iPhone, I somewhat recently switched.

Re: OpenClaw is a security nightmare dressed up as a daydream

#295
post #219

Earlier quoted context omitted.

Doesn't lightning settle basically instantly, while still being decentralized? You're just trading signed transactions iirc, with settlement happening whenever.

The settlement happening whenever is a problem. Instant authorization is very different from a practical settlement model. At least with card networks, there are layers of liability if solvency issues occur. There’s merchant protections from the acquiring bank and if for some reason the acquiring bank fails there is the guarantee of the card network. On the issuing side there are chargebacks. I hate chargebacks as mu…

I don’t have a horse in this race, but my only point was you don’t have to wait 15 minutes for a really decentralized experience. Yeah, you do need to be ok with not being able to later chargeback your grocery store, just like with cash. Which is fine for your example of groceries in hand, less great for large purchases over the internet.

Maybe we don’t need an alternative when Visa handles everything, but it might be nice to not pay a 3% markup on everything. Alternatively, we could try to be more like India and Brazil, which each built instant bank to bank transfer setups you can use at the grocery store, without the risks that come with losing debit/credit cards. Convenient without poor people with no rewards cards subsidizing everyone else to cover Visa’s take.

Re: OpenClaw is a security nightmare dressed up as a daydream

#296
post #227

Earlier quoted context omitted.

I think you lived in a strange bubble when you were a kid. When I was a teenager in the 90s, we'd have paper maps that we'd bring with us. We had no GPS. I don't think we knew what GPS was. In the late 90s we'd print out directions from MapQuest. That was a game-changer. Still no GPS, though. As an adult in the early 00s, I was still printing out MapQuest maps. In 2004 I got a car with a built-in navigation system! (…

I remember GPS being something mountaineers had. People who would take their jeeps up to the glacier had them. Boats also had them. Coincidentally I was a fisherman back then and did observe my captain using a super fancy navigation device with an interactive map (and yes the map did come on a DVD); I also knew a couple of jeep men (or jeppakarlar as we call them in Icelandic) who had something similar (though more c…

> I however did not see this technology coming to our phones, and becoming this commonplace.

I didn't see a lot of things coming to phones. I never expected that I'd pay for things by hovering my phone over a payment terminal. Didn't think it would replace my iPod (or MP3 CD player, or Discman, or Walkman). Absolutely had no idea it would replace my camera.

And on the other side of the coin... my "phone" is barely a phone. The phone features are probably what I like least about it.

Re: OpenClaw is a security nightmare dressed up as a daydream

#297

Earlier quoted context omitted.

Ahhh, payment via phones is also a new thing that I think very few people saw coming (including me). However it is also a very recent development and not really a part of the supposed smartphone revolution. In 2007 we did not have touchless payments (except in some public transit systems; gyms; etc. but it was limited to a special cards you couldn’t use for anything else) so this is definitely a new capability which…

Hand-waving away ride-sharing as not much of a change makes me wonder what you would actually consider to be significant. It completely upended the taxi business. 2007: arrive in a new city, figure out who to call (or maybe text) for that particular city, wait, hope someone will pick you up and understand enough of your language and the local geography to get you where you want to go, possibly some unpleasant hagglin…

> arrive in a new city/country, open Uber, specify in the app precisely where you want to go, choose a vehicle, when to get picked up, etc, track vehicle progress in real-time, up-front pricing

This is actually something we should be a little uncomfortable about. It's a fine example of monopolists at work. The convenience does come with downsides.

I do like it, though, for exactly the reasons you state. If I end up in a country with cabbies who generally have good English skills and aren't out to rip me off, it's fine, and often easier to take a taxi. But you never know until you get there, and that can be stressful. The consistent Uber/Lyft experience is a breath of fresh air after a long flight when you just want to get to your lodging and pass out.

> If you don't see how smartphones changed the experience of flying... maybe you don't fly anywhere?

Eh, I'm not convinced. Sure, it's changed, but the general paradigm is the same. The main big change is the mobile boarding pass, seamlessly delivered after checking in on your phone, which is a genuine improvement. (But so many airlines still require you to check in with a human at the airport for international travel.) Print-at-home does come close enough, though, and still means you avoid lines at kiosks or (gasp) waiting for a real person to print you a boarding pass. Some airlines now charge you to print out your boarding pass (because of the availability of mobile passes), and that's disgusting. (I know people who still insist on printing at home, because they've had bad experiences around their boarding passes refusing to load, app crashing at exactly the wrong time, etc.)

Yes, all the airlines have apps, though after traveling a bit in Central America and in the Balkans recently, I've found that some airline apps are absolute trash, worse than having to wait in line for an hour to talk to a person. Most of my digital interaction with the airline is done on my laptop before the trip anyway. Notifications about gate information or delays are useful, but a push notification from an app is not markedly better than an SMS, and either way I always feel like I need to verify on a physical departures board, especially if connection timing is tight.

In instances where my flight has been delayed or cancelled, it's definitely an improvement to be able to rebook in the app, instead of waiting in line to talk to someone, or getting on the phone with the airline (or both, as I'd usually do, to find out which would resolve the problem faster).

I've never used airtags (don't have an iPhone anyway); I've checked bags at most twice in the past 20 years when I had no other choice (my mantra: checked luggage is lost luggage). But even considering that, I feel like all the fuss people make about airtagging their luggage is overblown.

Some airlines have eliminated seat-back entertainment and expect you to use your phone. That's crap.

Meanwhile, as GP has pointed out, security, customs, immigration have all gotten worse. Boarding processes have not improved, food hasn't gotten better, and airplane seat comfort has gone down. I say this not to blame smartphones, but to suggest that there are other, more important problems with air travel that have nothing to do with phones.

Re: OpenClaw is a security nightmare dressed up as a daydream

#298
post #295

Earlier quoted context omitted.

The settlement happening whenever is a problem. Instant authorization is very different from a practical settlement model. At least with card networks, there are layers of liability if solvency issues occur. There’s merchant protections from the acquiring bank and if for some reason the acquiring bank fails there is the guarantee of the card network. On the issuing side there are chargebacks. I hate chargebacks as mu…

I don’t have a horse in this race, but my only point was you don’t have to wait 15 minutes for a really decentralized experience. Yeah, you do need to be ok with not being able to later chargeback your grocery store, just like with cash. Which is fine for your example of groceries in hand, less great for large purchases over the internet. Maybe we don’t need an alternative when Visa handles everything, but it might b…

>Yeah, you do need to be ok with not being able to later chargeback your grocery store, just like with cash.

Well the reason that works is because in grocery stores you have a concept of card present so the liability shifts to the issuing bank... so there are no chargebacks. Concepts like card present and card not present demand a centralized authority and really can't exist in a decentralized payment rail, unless you're going to somehow invent decentralized pos hardware for merchants. Once you enter the world of atoms, you have re-introduced centralized trust into your payment rail though.

> Convenient without poor people with no rewards cards subsidizing everyone else to cover Visa’s take.

I fully agree. This is a crappy part of ccs and the best remedy is to disallow rewards programs for credit products. This isn't a fault of the card networks its a fault of issuing banks (and the airlines). Every crypto company in 2021 was offering 8% APY, you think those guys would have been better about this than Amex?

> Maybe we don’t need an alternative when Visa handles everything, but it might be nice to not pay a 3% markup on everything.

I'm actually not bothered by a take from the banks and networks involved. They are underwriting risk and affording insurances to me and the merchant. I guess my main argument is that it's good to have centralized insurance in money transfer facilitation. 3% is high and a failure of Dodd Frank. The Durbin Amendment should have reigned in cc fees and not just focused on debit interchange.

> Alternatively, we could try to be more like India and Brazil, which each built instant bank to bank transfer setups you can use at the grocery store, without the risks that come with losing debit/credit cards.

I don't disagree. As you pointed out it really comes down to the crappy reward programs from the issuing banks that make merchants and poor people suffer.

I don't mind crypto as an idea. I don't have a horse in the crypto race either. What I mind is the notion that it is somehow a viable payment rail. I'm sorry, it's been 20 years and crypto's best use case for payments has been buying acid on the internet because it was the only payment option.

I think one of the most interesting business stories in the world is about the guy who invented the Visa network, Dee Hock. It truly is a story of decentralization at its finest. John Coogan did a great video on him a couple of years ago I highly recommend: https://www.youtube.com/watch?v=RNbi2cUZt1o.

Re: OpenClaw is a security nightmare dressed up as a daydream

#299
post #88

The security issues in OpenClaw is not even the main issue, the hype will die if there is no monetary incentive. Like I said before: If you are spending more money on tokens than the agents are making you money (or not), then it is unfortunately all for nought. The question is, who is making money on using Openclaw other than hosting?

$10/month minimax using m2.7 and openai-codex oauth $20/month will allow you to mess around with this stuff for negligible cost.

But to do what? Other than being a hosting provider, how is using openclaw going to give someone a meaningful ROI?

Re: OpenClaw is a security nightmare dressed up as a daydream

#300
post #4
post #2

[flagged]

Now everyone has to defend their choice of words to make it sound like what you perceive as human.

Every breath is a Turing Test.

Either that or it’s the ghost of Philip K. Dick.

I liked his owl by the way.

Post reply on HN