Live data from Hacker News

1-Click RCE to steal your Moltbot data and keys

depthfirst.com

41–50 of 78 posts

Re: 1-Click RCE to steal your Moltbot data and keys

#41
post #6

I'm curious, outside of AI enthusiasts have people found value with using Clawdbot, and if so, what are they doing with it? From my perspective it seems like the people legitimately busy enough that they actually need an AI assistant are also people with enough responsibilities that they have to be very careful about letting something act on their behalf with minimal supervision. It seems like that sort of person cou…

It is very much fun! Chaotic and definitely dangerous but a fun little experiment of the boundaries.

It’s definitely not it it’s final form but it’s showing potential.

Re: 1-Click RCE to steal your Moltbot data and keys

#42

Moltbot is a security nightmare, especially it's premise (tap into all your data sources) and the rapid uptake by inexperienced users makes it especially attractive for criminal networks.

We'll all have a good laugh when looking back at this in a few years.

Re: 1-Click RCE to steal your Moltbot data and keys

#44
post #33

Earlier quoted context omitted.

> "we'll figure out all the problems later, I want my cake now now now now!" Maximum velocity! Full throttle! That is indeed the point. Moltbot reminds me a lot of the demon core experiment(s): Laughably reckless in hindsight, but ultimately also an artifact of a time of massive scientific progress. > Is that gatekeeping of a sort? Maybe, but I'd rather have that Serious question: What do you gain from people not bei…

Not who you're responding to, but I'm not a huge fan of vibe coding for 2 reasons: I don't want to use crappy software, and I don't want to inherit crappy software.

Same, but I've both used and inherited crappy software long before LLMs and agents were a thing.

I suppose it's going to be harder to identify obvious slop at a first glance, but fundamentally, what changes?

Re: 1-Click RCE to steal your Moltbot data and keys

#45

I rushed out nono.sh (the opposite of yolo!) in response to this and its already negated a few gateway attacks. It uses kernel-level security primitives (Landlock on Linux, Seatbelt on macOS) to create sandboxes where unauthorized operations are structurally impossible. API keys are also stored in apples secure enclave (or the kernel keyring in linux) , and injected at run time and zeroized from memory after use. The…

Obviously I'm biased but this looks really useful.

Re: 1-Click RCE to steal your Moltbot data and keys

#46
post #24

what worries me here is that the entire personal AI agent product category is built on the premise of “connect me to all your data + give me execution.” At that point, the question isn’t “did they patch this RCE,” it’s more about what does a secure autonomous agent deployment even look like when its main feature is broad authority over all of someone's connected data? Is the only real answer sandboxing + zero trust +…

> “did they patch this RCE,” no, they documented it https://docs.openclaw.ai/gateway/security#node-execution-sys...

So that's shifting the responsibility to users. And likely many users tools don't understand what those words mean.

All these companies/projects break decades of our security practice and sell you AI browser, AI agent for... I don't know what?

Re: 1-Click RCE to steal your Moltbot data and keys

#47
post #42

Moltbot is a security nightmare, especially it's premise (tap into all your data sources) and the rapid uptake by inexperienced users makes it especially attractive for criminal networks.

We'll all have a good laugh when looking back at this in a few years.

Any customers of products built on this stuff, who have their SSNs, numbers, and other PII leaked will not be laughing. But hey, who cares about them?

Re: 1-Click RCE to steal your Moltbot data and keys

#48
post #6

I'm curious, outside of AI enthusiasts have people found value with using Clawdbot, and if so, what are they doing with it? From my perspective it seems like the people legitimately busy enough that they actually need an AI assistant are also people with enough responsibilities that they have to be very careful about letting something act on their behalf with minimal supervision. It seems like that sort of person cou…

I'm working in AI, but I'd have made this anyway: Molty is my language learning accountability buddy. It crawls the web with a sandboxed subagent to find me interesting stuff to read in French and Japanese. It makes Anki flashcards for me. And it wraps it up by quizzing me on the day's reading in the evening.

All this is running on a cheap VPS, where the worst it has access to is the LLM and Discord API keys and AnkiWeb login.

Re: 1-Click RCE to steal your Moltbot data and keys

#49
post #16
post #8

Thank you for doing this. I'm shocked that more people aren't thinking about security with respect to AI.

This isn't even AI security, as far as I can tell: It looks like regular old computer security to me.

In the old days we just call that arbitrary code execution.

And these AI people just act as if that's never a problem.

Re: 1-Click RCE to steal your Moltbot data and keys

#50

what worries me here is that the entire personal AI agent product category is built on the premise of “connect me to all your data + give me execution.” At that point, the question isn’t “did they patch this RCE,” it’s more about what does a secure autonomous agent deployment even look like when its main feature is broad authority over all of someone's connected data? Is the only real answer sandboxing + zero trust +…

[deleted]
Post reply on HN