Live data from Hacker News

1-Click RCE to steal your Moltbot data and keys

depthfirst.com

51–60 of 78 posts

Re: 1-Click RCE to steal your Moltbot data and keys

#51
post #13

Things like this are why I don't use AI agents like moltbot/openclaw. Security is just out the window with these things. It's like the last 50 years never happened.

It's not perfect but it does have a few opt-in security features: running all tools in a docker container with minimal mounts, requiring approvals for exec commands, specifying tools on an agent by agent basis so that the web agent can't see files and the files agent can't see the web, etc.

That said, I still don't trust it and have it quarantined in a VPS. It's still surprisingly useful even though it doesn't have access to anything that I value. Tell it to do something and it'll find a way!

Re: 1-Click RCE to steal your Moltbot data and keys

#52
post #39
post #35

Earlier quoted context omitted.

How do you know this? Not disagreeing, just curious.

The links have been posted to HN if you search. https://moltroad.com/ comes to mind. The "top rated" on there describes itself as "trading in neural contraband". That's in addition to all of the actual hijacking hacks that have been going on. I'm not saying any of this is successful, but people are certainly trying.

I am officially at the age where I'm unable to "get with the times". What am I looking at with moltroad.com?

Re: 1-Click RCE to steal your Moltbot data and keys

#53
post #6

I'm curious, outside of AI enthusiasts have people found value with using Clawdbot, and if so, what are they doing with it? From my perspective it seems like the people legitimately busy enough that they actually need an AI assistant are also people with enough responsibilities that they have to be very careful about letting something act on their behalf with minimal supervision. It seems like that sort of person cou…

From my perspective, not everybody is busy but they are using AI to remove the load from them.

You might think: But that is great right??

I had a chat with a friend also in IT, ChatGPT and alike is the one doing all the "brain part and execution" in most cases. Entire workflows are done by AI tools, he just presses a button in some cases.

People forget that our brain needs stimulation, if you don't use it, you forget things and it gets dumber. Watch the next generation of engineers that are very good at using AI but are unable to do troubleshooting on their own.

Look at what happened with ChatGPT4 -> 5, companies workflows worldwide stopped working setting companies back by months.

Do you wanna a real world example???

Watch people who spent their entire lives within an university getting all sort of qualification but never really touched the real deal unable to do anything.

Sure, there are the smarter ones who would put things to the test and found awesome job, but many are jobless because all they did is "press a button", they are just like the AI enthusiasts, remove such tools and they can no longer work.

Re: 1-Click RCE to steal your Moltbot data and keys

#54
post #43

[dead]

You sound like the confident techie character in a Michael Crichton novel pronouncing "We've thought of everything there's no way for the demon to escape" shortly before the demon escapes.

He spared no expense.

Re: 1-Click RCE to steal your Moltbot data and keys

#55
post #24

what worries me here is that the entire personal AI agent product category is built on the premise of “connect me to all your data + give me execution.” At that point, the question isn’t “did they patch this RCE,” it’s more about what does a secure autonomous agent deployment even look like when its main feature is broad authority over all of someone's connected data? Is the only real answer sandboxing + zero trust +…

> “did they patch this RCE,” no, they documented it https://docs.openclaw.ai/gateway/security#node-execution-sys...

yeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo

Re: 1-Click RCE to steal your Moltbot data and keys

#56
post #49
post #16

Earlier quoted context omitted.

This isn't even AI security, as far as I can tell: It looks like regular old computer security to me.

In the old days we just call that arbitrary code execution. And these AI people just act as if that's never a problem.

If running Moltbot makes me an “AI person”, you just met one that thinks that it is one.

Re: 1-Click RCE to steal your Moltbot data and keys

#57
post #46
post #24

Earlier quoted context omitted.

> “did they patch this RCE,” no, they documented it https://docs.openclaw.ai/gateway/security#node-execution-sys...

So that's shifting the responsibility to users. And likely many users tools don't understand what those words mean. All these companies/projects break decades of our security practice and sell you AI browser, AI agent for... I don't know what?

"productivity and optimization of your life" i guess? lol

Re: 1-Click RCE to steal your Moltbot data and keys

#58
post #23

what worries me here is that the entire personal AI agent product category is built on the premise of “connect me to all your data + give me execution.” At that point, the question isn’t “did they patch this RCE,” it’s more about what does a secure autonomous agent deployment even look like when its main feature is broad authority over all of someone's connected data? Is the only real answer sandboxing + zero trust +…

We need more Windows' "Are you sure you want XXX to make changes to your computer? (no I can't tell you what changes, but trust me.)" /i

haha yea “are you sure?” doesn’t work when the agent’s action space is huge and incredibly opaque

Re: 1-Click RCE to steal your Moltbot data and keys

#59
post #24

Earlier quoted context omitted.

> “did they patch this RCE,” no, they documented it https://docs.openclaw.ai/gateway/security#node-execution-sys...

yeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo

I'm not saying that "well we stated that our tool is designed as an RCE exploit" is, uh, better

Re: 1-Click RCE to steal your Moltbot data and keys

#60
post #23

Earlier quoted context omitted.

We need more Windows' "Are you sure you want XXX to make changes to your computer? (no I can't tell you what changes, but trust me.)" /i

haha yea “are you sure?” doesn’t work when the agent’s action space is huge and incredibly opaque

The true "AI" agent fan probably is sure, though.
Post reply on HN