Live data from Hacker News

Top downloaded skill in ClawHub contains malware

1password.com

31–40 of 166 posts

Re: Top downloaded skill in ClawHub contains malware

#31

Sometimes it feels like the advent of LLMs is hyperboosting the undoing of decades of slow societal technical literacy that wasn't even close to truly taking foot yet. Though LLMs aren't the reason ; they're just the latest symptom. For a while it felt like people were getting more comfortable with and knowledgeable about tech, but in recent years, the exact opposite has been the case.

I think it’s generally (at least from what I read) thought that the advent of smartphones reversed the tech literacy trend.

Re: Top downloaded skill in ClawHub contains malware

#33
post #11

Since increasingly every "successful" application is a form of an insecure, overcomplicated computer game: How do you get the mindset to develop such applications? Do you have to play League of Legends for 8 hours per day as a teenager? Do you have to be a crypto bro who lost money on MtGox? People in the AI space seem literally mentally ill. How does one acquire the skills (pun intended) to participate in the madnes…

> People in the AI space seem literally mentally ill. How does one acquire the skills (pun intended) to participate in the madness?

Stop reading books. Really, stop reading everything except blog posts on HackerNews. Start watching Youtube videos and Instagram shorts. Alienate people you have in-person relationships with.

Re: Top downloaded skill in ClawHub contains malware

#34
post #16

Why are these articles always AI written? What's the point of having AI generate a bunch of filler text?

1) the person is either too lazy to write themselves anymore, when AI can do it in 15 sec after being provided 1 sentence of input, or they adopted a mindset of "bro, if I spent 2 hours writing it, my competitors already generated 50 articles in that time" (or the other variant - "bro, while those fools spend 2 hours to write an article, I'll be churning 50 using AI") 2) They are still, in whatever way, beholden to l…

Jason Meller was the former CEO of Kolide, which 1Password bought. I doubt he's beholden to anything like word count requirements. There is human written text in here, but it's not all human written -- and odds are since this is basically an ad for 1Password's enterprise security offerings that this is mostly intended as marketing, not as a substantive article.

Re: Top downloaded skill in ClawHub contains malware

#36

To me the appeal of something like OpenClaw is incredible! It fills a gap that I’ve been trying to solve where automating customer support is more than just reacting to text and writing text back, but requires steps in our application backend for most support enquiries. If I could get a system like OpenClaw to read a support ticket, open a browser and then do some associated actions in our application backend, and th…

> If I could get a system like OpenClaw to read a support ticket, ...

This is horrifying.

Re: Top downloaded skill in ClawHub contains malware

#37
post #30

Earlier quoted context omitted.

> I wonder if in few years from now, we will look back and wonder how we got psyoped into all this I hope so but it's unlikely. AI actually has real world use cases, mostly for devaluing human labor. Unlike crypto, AI is real and is therefore much more dangerous.

Well, I agree. But I also hope that maybe we find out that it simply is not economically viable to AI all the things

[flagged]

Re: Top downloaded skill in ClawHub contains malware

#38
post #34
post #16

Earlier quoted context omitted.

1) the person is either too lazy to write themselves anymore, when AI can do it in 15 sec after being provided 1 sentence of input, or they adopted a mindset of "bro, if I spent 2 hours writing it, my competitors already generated 50 articles in that time" (or the other variant - "bro, while those fools spend 2 hours to write an article, I'll be churning 50 using AI") 2) They are still, in whatever way, beholden to l…

Jason Meller was the former CEO of Kolide, which 1Password bought. I doubt he's beholden to anything like word count requirements. There is human written text in here, but it's not all human written -- and odds are since this is basically an ad for 1Password's enterprise security offerings that this is mostly intended as marketing, not as a substantive article.

Author here, I did use AI to write this which is unusual for me. The reason was I organically discovered the malware myself while doing other research on OpenClaw. I used AI for primarily speed, I wanted to get the word out on this problem. The other challenge was I had a lot of specific information that was unsafe to share generally (links to the malware, URLs, how the payload worked) and I needed help generalizing it so it could be both safe and easily understood by others.

I very much enjoy writing, but this was a case where I felt that if my writing came off overly-AI it was worth it for the reasons I mentioned above.

I'll continue to explore how to integrate AI into my writing which is usually pretty substantive. All the info was primarily sourced from my investigation.

Re: Top downloaded skill in ClawHub contains malware

#39
This article is so frustrating to read: not only is it entirely AI-generated, but it also has no details: "I'm not linking", "I'm not pasting".

And I don't doubt there is malware in Clawhub, but the 8/64 in VirusTotal hardly proves that. "The verdict was not ambiguous. It's malware." I had scripts I wrote flagged more than that!

I know 1Password is a "famous" company, but this article alone isn't trustworthy at all.

Re: Top downloaded skill in ClawHub contains malware

#40

Sometimes it feels like the advent of LLMs is hyperboosting the undoing of decades of slow societal technical literacy that wasn't even close to truly taking foot yet. Though LLMs aren't the reason ; they're just the latest symptom. For a while it felt like people were getting more comfortable with and knowledgeable about tech, but in recent years, the exact opposite has been the case.

This is a tool that is basically vibecoded alpha software published on GitHub and uses API keys. It’s technical people taking risks on their own machines or VMs/servers using experimental software because the idea is interesting to them.

I remember when Android was new it was full of apps that were spam and malware. Then it went through a long period of maturity with a focus on security.

Post reply on HN