Top
Best
New

Posted by fs_software 2 days ago

OpenClaw is a security nightmare dressed up as a daydream(composio.dev)
391 points | 285 commentspage 4
chewbacha 2 days ago|
This read like an AI generated piece and seems to be an advertisement for their product.
koconder 1 day ago||
Should have said this was a fear to promote a b2b sass "TrustClaw"
feeworth 1 day ago||
Didn't Nvidia create the safer version basically?
perbu 1 day ago|
The problem is that the the LLM can't distinguish between data and instruction so there is just so much the harness can do.
Yizahi 1 day ago||
Every LLM evangelist seems to forget that there is a reason why LLMs work so well for coding. It's because there were and are preexisting non-LLM validation tools for coding. The slop doesn't make it past linters, compilers, cone analysis and other tools, and then there is a second barrier in the form of code review. And even will these guardrails LLMs often produce substandard output.

Buying a ticket, writing an email, setting calendars or fiddling with files on the drive etc. have none of these guardrails. LLMs can and will simply oneshot the slop into a real system, without neither computer nor human validation.

fuzzfactor 1 day ago||
Well Facebook started out by design as a security nightmare, dressed up as a daydream and look how that went.
love2read 2 days ago||
One more "AI is a security threat" post gets to the top of HN.
rvz 2 days ago||
The security issues in OpenClaw is not even the main issue, the hype will die if there is no monetary incentive. Like I said before:

If you are spending more money on tokens than the agents are making you money (or not), then it is unfortunately all for nought.

The question is, who is making money on using Openclaw other than hosting?

nickthegreek 2 days ago||
$10/month minimax using m2.7 and openai-codex oauth $20/month will allow you to mess around with this stuff for negligible cost.
rvz 12 hours ago||
But to do what? Other than being a hosting provider, how is using openclaw going to give someone a meaningful ROI?
rolo_1992 1 day ago||
[dead]
semiinfinitely 2 days ago||
I guess nobody cares?
Lazar71 3 hours ago|
[dead]
More comments...