Live data from Hacker News

OpenClaw is a security nightmare dressed up as a daydream

composio.dev

81–90 of 323 posts

Re: OpenClaw is a security nightmare dressed up as a daydream

#81
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

>There are real, impressive examples of the power of agentic flows there aren't, and just like the blockchain "industry" with its "surely this is going to be the killer app" we're going to be in this circus until the money dries up. Just like the note-taking craze, the crypto ecosystem and now AI there's an almost inverse relation between the people advocating it and actually doing any meaningful work. The more anyon…

I'm gonna keep saying this forever - there are two obvious "killer apps" for crypto:

1. Semi-private blockchains, where you can rely on an actor not to be actively malicious, but still want to be able to cryptographically hold them to a past statement (think banks settling up with each other)

2. NFTs for tracking physical products through a logistics supply chain. Every time a container moves from one node to the next in a physical logistics chain (which includes tons of low trust "last mile" carriers), its corresponding NFT changes ownership as well. This could become as granular as there's money to support.

These would both provide material advantages above and beyond a centralized SQL database as there's no obvious central party that is trusted enough to operate that database. Neither has anything to do with retail investors or JPEGs though, so they'll never moon and you'll never hear about them.

Re: OpenClaw is a security nightmare dressed up as a daydream

#82
post #71
post #35

Earlier quoted context omitted.

There are secure alternatives but they are not making millions of dollars.

Which secure alternatives? I've not seen any yet.

Connecting telegram to an agent with a bunch of skills and access to isolated compute environment is largely a solved problem. I don't want to advertise but here but plenty of solutions to spin this up, including what we have built.

Re: OpenClaw is a security nightmare dressed up as a daydream

#83
post #22

> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of…

I wonder how many inherently unsolvable problems have been fixed before.

This problem is inherently unsolvable because LLMS are prone to hallucinations and prompt injection attacks. I think that you're insinuating that these things can be fixed, but to my knowledge, both of these problems are practically unsolvable. If that turns out to be false, then when they are solved, fully autonomous AI agents may become feasible. However, because these problems are unsolvable right now, anyone who grants autonomous agents access to anything of value in their digital life is making a grave miscalculation. There is no short-term benefit that justifies their use when the destruction of your digital life — of whatever you're granting these things access to — is an inevitability that anyone with critical thinking skills can clearly see coming.

Re: OpenClaw is a security nightmare dressed up as a daydream

#84
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

> There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

Please don't. The reason we're still enjoying the bit of the old world as we know it, is just because nobody has really figured it out yet. Enjoy the moment, while it lasts.

Re: OpenClaw is a security nightmare dressed up as a daydream

#85

As a site for people curious about technology, where is the sense of adventure? People are inventing the future of human/ai interaction themselves because big tech could not do it within their own constraints. Don't get me wrong, those constraints are there for a reason, but the hacker mentality seems muted lately.

Typically, the hacker mentality wasn't leaning towards "the most unsafe and unsecure thing in the entire history of humanity ever" which in the end "does an incredibly inept job because it just goes off the rails randomly and destroys your life"

And all cause lazy.

Instead, that's more like what addled octgenarians do. Get tricked by Nigerian scam artists into installing some p0wnage.

Re: OpenClaw is a security nightmare dressed up as a daydream

#86
post #72
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

Some of it is lack of imagination, but some of it is because many truly visionary examples would largely sound stupid to most of today's audience. Imagine it's 2007 and you're explaining how the smartphone will change society over the next 20 years: - A photo sharing app will change restaurants, public spaces, and the entire travel industry across the world - The smartphone will bring about regime change in Egypt, Tu…

Instagram Arabian spring Uber Airbnb Cloud-ification/shift to web apps and mobile-first ....tiktok? Or is YouTube considered "short video sharing app"? Because I see no evidence tiktok in particular killing TV... To be fair, QR code did hit print magazines/newspapers in Germany (just as an example; English wiki was not elaborating on initial history of public use/perception) in late 2007, so that one wasn't nearly as far-fetched.

Re: OpenClaw is a security nightmare dressed up as a daydream

#87
post #59

Earlier quoted context omitted.

All of them. It's not like AI companies have managed to fix the security issues since last time they promised they had fixed all the hallucinations & accidental database deletions.

You know it’s open source code, right?

It's literally a loop that wraps APIs from AI providers. Go ahead & explain how an open source AI wrapper fixes security holes inherent in existing AI.

Re: OpenClaw is a security nightmare dressed up as a daydream

#88
The security issues in OpenClaw is not even the main issue, the hype will die if there is no monetary incentive. Like I said before:

If you are spending more money on tokens than the agents are making you money (or not), then it is unfortunately all for nought.

The question is, who is making money on using Openclaw other than hosting?

Re: OpenClaw is a security nightmare dressed up as a daydream

#89
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

Not using OpenClaw - but I have a limited agent running that currently does a few things well. Morning Briefing: - it reads all my new email (multiple accounts and contexts), calendars (same accounts and contexts), slack (and other chat) messages (multiple slacks, matrix, discord, and so on), the weather reports, my open/closed recent to dos in a shared list across all my devices, my latest journal/log entries of thi…

What are you using for email integration?

I want to setup agent to clean up my gmail inbox which has many thousands of unread messages.

Re: OpenClaw is a security nightmare dressed up as a daydream

#90
post #77
post #17

Responding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?

I think some folks want a legitmate personal assistant/secretary like ceo's and wealthy people have but ai. I think that's a good goal. Modern cells and pdas kinda fell short of "your own literal secretary" and I think people want that. Still we should continue pushing the boundaries beyond that.

The purpose of a personal assistant isn’t to fit people into your calendar. It’s to filter them out. They serve as a barrier to your time, not an enabler for other people to claim it. I don’t see how an AI can meaningfully accomplish that any better than simply just making yourself more difficult to reach.
Post reply on HN