Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

51–60 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#53
post #26
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

Have you seen how bad flight booking sites can get? I've had to download airline apps a majority of the time because the website failed to finish payment properly. I don't think we should call presentations visionless or fault them for wanting to solve this UX nightmare.

And you want to add an unreliable, non-deterministic LLM into the flow too?

Re: OpenClaw is a security nightmare dressed up as a daydream

#54

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

[deleted]

Re: OpenClaw is a security nightmare dressed up as a daydream

#55
post #29
post #22

Earlier quoted context omitted.

I wonder how many inherently unsolvable problems have been fixed before.

Human make error too, but we held them liable for lots of the mistakes they make. Can we make the agent liable? or the company behind the model liable?

Humans fear discomfort, pain, death, lack of freedom, and isolation. That's why holding them liable works.

Agents don't feel any of these, and don't particularly fear "kill -9". Holding them liable wouldn't do anything useful.

Re: OpenClaw is a security nightmare dressed up as a daydream

#56

Earlier quoted context omitted.

Sounds like you just need to install Apple Maps, Apple Weather^* and some separte fridge-tracking app. No need of additional intrusive AI ^* or equivalents

Indeed I have a bunch of apps that do most of these things, but it's the seamless integration I'm looking for - which may not need much AI at all (especially of the LLM kind), just some well directed machine learning and UI integration.

Home assistant automations?

Re: OpenClaw is a security nightmare dressed up as a daydream

#57

The overlap between the target audience for openclaw in spite of its attack surface, and the audience that considers a mac mini to be a sandbox while handing over the keys to their digital life is a Venn Eclipse.

How is a dedicated Mac not a sandbox?

Re: OpenClaw is a security nightmare dressed up as a daydream

#58

I would like a personal assistant on my phone that, based on my usual routine and my exact position, can tell me (for example) which bus will get me home the quickest off the ferry, whether the bridge is clogged with traffic, do I need an umbrella? what's probably missing from my fridge, time to top up transit pass, did I tap in? etc etc. These things would appear on my lock screen when I most probably need to know t…

In an alternative reality Apple didn't absolutely shit the bed on AI and made this possible. Sadly they've shown they are woefully behind and have utterly useless people leading divisions they shouldn't have been allowed anywhere near.

Re: OpenClaw is a security nightmare dressed up as a daydream

#59

I wonder just how many are compromised and waiting on a command that hasn't been given yet

All of them. It's not like AI companies have managed to fix the security issues since last time they promised they had fixed all the hallucinations & accidental database deletions.

You know it’s open source code, right?

Re: OpenClaw is a security nightmare dressed up as a daydream

#60
It is, but I thought security wasn't the point.

The point was to give it unlimited access to your entire digital life and while I'd never use it that way myself, that's what many users are signing up for, for better or worse.

Obviously, OpenClaw doesn't advertise it like that, but that's what it is.

Needless to say, OpenClaw wasn't even the first to do this. There were already many products that let you connect an AI agent to Telegram, which you could then link to all your other accounts. We built software like that too.

OpenClaw just took the idea and brought it to the masses and that's the problem.

Post reply on HN