Live data from Hacker News

OpenClaw – Moltbot Renamed Again

openclaw.ai

371–380 of 422 posts

Re: OpenClaw – Moltbot Renamed Again

#371
post #324

Earlier quoted context omitted.

this should be top comment, this whole project is a 0 day orgy

the documentation contains the actual line: > This is remote code execution on the Mac https://docs.openclaw.ai/gateway/security I... what....? what are people expecting?

This is the result of years of people sniffing the AI Powder. Our collective intelligence as a species is falling off a cliff.

Re: OpenClaw – Moltbot Renamed Again

#378
My biggest issue with this whole thing is: how do you protect yourself from prompt injection? Anyone installing this on their local machine is a little crazy :). I have it running in Docker on a small VPS, all locked down.

However, it does not address prompt injection.

I can see how tools like Dropbox, restricted GitHub access, etc., could all be used to back up data in case something goes wrong.

It's Gmail and Calendar that get me - the ONLY thing I can think of is creating a second @gmail.com that all your primary email goes to, and then sharing that Gmail with your OpenClaw. If all your email is that account and not your main one, then when it responds, it will come from a random @gmail. It's also a pain to find a way to move ALL old emails over to that Gmail for all the old stuff.

I think we need an OpenClaw security tips-and-tricks site where all this advice is collected in one place to help people protect themselves. Also would be good to get examples of real use cases that people are using it for.

reply

Post reply on HN