Live data from Hacker News

1-Click RCE to steal your Moltbot data and keys

depthfirst.com

61–70 of 78 posts

Re: 1-Click RCE to steal your Moltbot data and keys

#61
post #6

I'm curious, outside of AI enthusiasts have people found value with using Clawdbot, and if so, what are they doing with it? From my perspective it seems like the people legitimately busy enough that they actually need an AI assistant are also people with enough responsibilities that they have to be very careful about letting something act on their behalf with minimal supervision. It seems like that sort of person cou…

What you are missing: now people finally have a Siri that actually works.

Re: 1-Click RCE to steal your Moltbot data and keys

#62
post #59

Earlier quoted context omitted.

yeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo

I'm not saying that "well we stated that our tool is designed as an RCE exploit" is, uh, better

haha fair "we've designed a fully exploitable agent and we can't wait to share it with the world" :')

Re: 1-Click RCE to steal your Moltbot data and keys

#63
post #60

Earlier quoted context omitted.

haha yea “are you sure?” doesn’t work when the agent’s action space is huge and incredibly opaque

The true "AI" agent fan probably is sure, though.

maybe personal AI agents are just a massive psyop to get the massive population of true fans' data then lol - or we just get new security tools that can keep up with this pace of AI innovation. who knows

Re: 1-Click RCE to steal your Moltbot data and keys

#64
Apart from the actual exploit, it is intriguing to see how a security researcher can leverage an AI tool to give them an asymmetric advantage to the actual developers of the code. Devs are pretty focused on their own subsystem and it would take serendipity or a ton of experience to be able to spot such patterns.

Thinking about this more .. given all the AI generated code being put into production these days (I routinely see posts of anthropic and others boast how much code is being written by AI). I can see it being much, much harder to review all the code being written by AIs. It makes a lot of sense to use an AI system to find vulnerabilities that humans don't have time to catch.

Re: 1-Click RCE to steal your Moltbot data and keys

#65

Apart from the actual exploit, it is intriguing to see how a security researcher can leverage an AI tool to give them an asymmetric advantage to the actual developers of the code. Devs are pretty focused on their own subsystem and it would take serendipity or a ton of experience to be able to spot such patterns. Thinking about this more .. given all the AI generated code being put into production these days (I routin…

By your logic, it would be really easy for the code creator to run an agent to find and fix exploits in their own code.

Re: 1-Click RCE to steal your Moltbot data and keys

#66

I rushed out nono.sh (the opposite of yolo!) in response to this and its already negated a few gateway attacks. It uses kernel-level security primitives (Landlock on Linux, Seatbelt on macOS) to create sandboxes where unauthorized operations are structurally impossible. API keys are also stored in apples secure enclave (or the kernel keyring in linux) , and injected at run time and zeroized from memory after use. The…

Why not use containers (eg. Podman) with secrets management?

Re: 1-Click RCE to steal your Moltbot data and keys

#67
What I find really amazing is that the same ones who kept saying that cars were/are wasteful and that kept making fun of cryptocurrencies and complaining about the high energy usage to mine Bitcoin are now head first spending $$$ on the most energy intensive endeavour the human race ever invented: AI.

I mean: there are literally people spending $200 and more per month to have their personal, a bit schizophrenic, assistant engage moreover in conspicuous consumption for them.

Now as to my take on it: I think energy, when it comes to 8 billion humans, is basically infinite so I think it's only a matter of converting enough of that energy that either is or reaches our planet into a usable form. So I don't mind energy consumption.

But it'd be nice if could we at least have those who use AI not being hypocrites and stop criticizing Bitcoin mining and ICE cars? (by ICE I mean "Internal Combustion Engine" in case you thought I was talking about other kind of cars)

From now on you're only allowed to criticize ICE cars and Bitcoin mining if you don't use AI.

Re: 1-Click RCE to steal your Moltbot data and keys

#68
post #15
post #7

So many people are giving keys to the kingdom to this thing. What is happening with humanity?

Humanity is the same it's always been. Some people are just inherently curious despite the obvious dangers. Also, if you think about it, billions of people aren't running Moltbot at all.

X is full of people including Karpathy, Jason C and others boasting about this.

Re: 1-Click RCE to steal your Moltbot data and keys

#69

Apart from the actual exploit, it is intriguing to see how a security researcher can leverage an AI tool to give them an asymmetric advantage to the actual developers of the code. Devs are pretty focused on their own subsystem and it would take serendipity or a ton of experience to be able to spot such patterns. Thinking about this more .. given all the AI generated code being put into production these days (I routin…

Looking at their website, depthfirst seems to offer an product that essentially solves this problem.

Re: 1-Click RCE to steal your Moltbot data and keys

#70
post #56
post #49

Earlier quoted context omitted.

In the old days we just call that arbitrary code execution. And these AI people just act as if that's never a problem.

If running Moltbot makes me an “AI person”, you just met one that thinks that it is one.

"AI people" in the comment was not referring to end users.
Post reply on HN