Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

301–310 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#301
post #170

Earlier quoted context omitted.

I have "new genius" ideas very often. After doing quick search I discover that any idea worth thinking of implementation is either implemented already or what seems to be low barrier to entry clashes with some legal obstacles.

Interestingly that sort of research is actually what I've used Claude/Chatgpt deep research and openclaw for. If I have an idea, I get an agent to go and do some product research for me and see if there is a market, if anyone has tried it, and if there is anyone doing it. It has unironically saved me a lot of time I would have otherwise spent going down rabbit holes. Of the models I've found that claude doesn't gas y…

Yup. I do have a 4-step process for this (just for prompts and some bash scripts that call CC). 1. Breadth first 2. Compress 3. Per player deep research 4. Per player compression. Then I just merge all the markdown files, fit it into 250k tokens, load any model that supports that much and you can pretty much "tall to market".

The biggest limitation here is data access though. A lot of market data is gated behind registration or anti-bot captchas, so the project that my CC is working on now is a playwright clone that is not easily detectable + can be used with CLI same as playwright itself.

Re: OpenClaw is a security nightmare dressed up as a daydream

#302
post #4

Earlier quoted context omitted.

Now everyone has to defend their choice of words to make it sound like what you perceive as human.

Every breath is a Turing Test. Either that or it’s the ghost of Philip K. Dick. I liked his owl by the way.

Erm accidental possible lyrics there.

Is there any music about how AI situation yet?

When AI can emulate ADHD the last bastion is breached.

Re: OpenClaw is a security nightmare dressed up as a daydream

#303
post #44

Earlier quoted context omitted.

> why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. This AI wave is filled with "ideas guys/gals" who thought they had an amazing awesome idea and if only they knew how to program they could make a best-selling billion dollar idea, being confronted with the reality that their ideas are really uninteresting as well. They're still happy to…

the whole obsequious nature of how LLMs also amp them up thinking they're onto something incredible is throwing gas on this dumpster fire. "What a great idea! This will revolutionize linkedin commenting. Let's implement it together."

Anthropic tried to fix this I think. Because it's the only model that will push back, but it's even funnier.

Ask a question, it will say yes, ask "are you sure?", it will reverse direction full throttle, then ask are you sure again and it'll go back to initial response saying "yeah I confused myself there". You can do this until context window exhaustion and this will never stop.

On the other side of this, Gemini will stand by whatever it generated the first time, no matter how much you push back and no matter how stupid the idea is.

Re: OpenClaw is a security nightmare dressed up as a daydream

#304
post #125

Earlier quoted context omitted.

Personally, if I could run capable-enough inference on hardware I control, and could rely on the harness asking me for mechanistic confirmation before the agent can take consequential actions, I'd do it immediately.

Consequential actions like searching the web or downloading packages or dependencies or doing most anything useful?

No, these are all fine for me (my agent is sandboxed in a container, so it can install all the node modules or Debian packages it wants).

I was thinking more of sending outgoing emails, publishing anything on the web, spending my money etc.

Re: OpenClaw is a security nightmare dressed up as a daydream

#305

Earlier quoted context omitted.

[flagged]

Go ahead, try it out: https://hackmyclaw.com/

This is cool. Did you have to prompt it anything specific other than "never reply to emails"?

Critically, I think people are using Openclaw to actually reply to stuff.

Re: OpenClaw is a security nightmare dressed up as a daydream

#306
post #67

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

> The whole point of OpenClaw is to run AI actions with your own private data, your own Gmail, your own WhatsApp, etc. There's no point in using OpenClaw with that much restriction on it. Hard disagree. I have OpenClaw running with its own gmail and WhatsApp running on its own Ubuntu VM. I just used it to help coordinate a group travel trip. It posted a daily itinerary for everyone in our WhatsApp group and handled a…

> handled all of the "busy work" I hate doing as the person who books the "friend group" trip

Why do you go on trips with your friends if you have to do all the work?

Re: OpenClaw is a security nightmare dressed up as a daydream

#307
post #280

Earlier quoted context omitted.

>The remediations that are in place because a engineering/safety/red team did its job are commendable. However, that does not speak to the innate vulnerability of these models, which is what we're talking about. I am talking about the innate vulnerability. The LLM model itself can be censored and controlled to do only certain behaviors. We have an actual degree of control here. >If you use LLMs daily and extensively…

> You need to think in terms of a probability of a successful hallucination or prompt injection. I would venture to say that an ACID compliant deterministic database has a 99.999999999999999999% chance of retrieving the correct information when asked by the correct SQL statement. An LLM on the other hand is more like 90%. LLMs by their innate code instruction are meant to hallucinate. I don't necessarily disagree wit…

Eh if you hire a programmer to program things for you, you won’t get a 99.9999999999%.

Getting LLMs to have a reliability rate that is on par or superior to human performance is very very achievable.

Re: OpenClaw is a security nightmare dressed up as a daydream

#308
post #297

Earlier quoted context omitted.

Hand-waving away ride-sharing as not much of a change makes me wonder what you would actually consider to be significant. It completely upended the taxi business. 2007: arrive in a new city, figure out who to call (or maybe text) for that particular city, wait, hope someone will pick you up and understand enough of your language and the local geography to get you where you want to go, possibly some unpleasant hagglin…

> arrive in a new city/country, open Uber, specify in the app precisely where you want to go, choose a vehicle, when to get picked up, etc, track vehicle progress in real-time, up-front pricing This is actually something we should be a little uncomfortable about. It's a fine example of monopolists at work. The convenience does come with downsides. I do like it, though, for exactly the reasons you state. If I end up i…

I agree, not every change is an unalloyed good.

Who stops and looks for a physical departures board in 2026? I already know the gate I'm going to because I've had ample time to check my smartphone while I'm waiting for all the carry-on maximalists to get their oversized roller AND stuffed "personal item" backpack from the overhead bins. ;)

I think you've understated/missed some of the aspects of flying itself, but probably not necessary to litigate it further. There's also all the stuff at the destination that the smartphone has enabled, eg - rental cars with carplay - walking directions on a paired smartwatch - transit pass via NFC (and transit-specific directions) - checking into accomodations (airbnb-type places especially) - authenticating Netflix, etc on tv at your airbnb/hotel - bike-sharing apps - activity passes in your digital wallet

Re: OpenClaw is a security nightmare dressed up as a daydream

#310

Earlier quoted context omitted.

Wait til you see my todo app though…

Can it suggest me to do the things I should do ? Can it talk to me into overcoming what's blocking me from completing tasks at an emotional level ? :)

Obligatorily appropriate https://m.youtube.com/watch?v=TbwlC2B-BIg&t=45s
Post reply on HN