OpenClaw: When AI Agents Get Full System Access. Security nightmare?
1–10 of 34 posts
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#2> Despite all advances:
> * No large language model can reliably detect prompt injections
Interesting isn't it, that we'd never say "No database manager can reliably detect SQL injections". And that the fact it is true is no problem at all.
The difference is not because SQL is secure by design. It is because chatbot agents are insecure by design.
I can't see chatbots getting parameterised querying soon. :)
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#3> LLM is Immune to Prompt Injection > Despite all advances: > * No large language model can reliably detect prompt injections Interesting isn't it, that we'd never say "No database manager can reliably detect SQL injections". And that the fact it is true is no problem at all. The difference is not because SQL is secure by design. It is because chatbot agents are insecure by design. I can't see chatbots getting parame…
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#4Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#5Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#6I would hope anyone with the knowledge and interest to run OpenClaw would already be mostly aware of the risks and potential solutions canvassed in this article, but I'd probably be shocked and disappointed.
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#7> LLM is Immune to Prompt Injection > Despite all advances: > * No large language model can reliably detect prompt injections Interesting isn't it, that we'd never say "No database manager can reliably detect SQL injections". And that the fact it is true is no problem at all. The difference is not because SQL is secure by design. It is because chatbot agents are insecure by design. I can't see chatbots getting parame…
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#8I would hope anyone with the knowledge and interest to run OpenClaw would already be mostly aware of the risks and potential solutions canvassed in this article, but I'd probably be shocked and disappointed.
There are definitely people I know who are talking about using it that I want nowhere near my keyboard
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#9Earlier quoted context omitted.
There are definitely people I know who are talking about using it that I want nowhere near my keyboard
Yeah that. I had an external "security consultant" (trained monkey) tell me the other day that something fucking stupid we were doing was fine. There are many many people who should not be allowed near keyboards these days.
Re: OpenClaw: When AI Agents Get Full System Access. Security nightmare?
#10> LLM is Immune to Prompt Injection > Despite all advances: > * No large language model can reliably detect prompt injections Interesting isn't it, that we'd never say "No database manager can reliably detect SQL injections". And that the fact it is true is no problem at all. The difference is not because SQL is secure by design. It is because chatbot agents are insecure by design. I can't see chatbots getting parame…