13 ms·
OpenClaw is a security nightmare dressed up as a daydream
- zeristor 7mo ago[flagged]
- airstrike 7mo agoI wonder just how many are compromised and waiting on a command that hasn't been given yet
- measurablefunc 7mo agoAll of them. It's not like AI companies have managed to fix the security issues since last time they promised they had fixed all the hallucinations & accidental database deletions.
- gos9 7mo agoYou know it’s open source code, right?
- slopinthebag 7mo agodo you think anybody has actually read all 700k lines of the ai generated code?
- otabdeveloper4 7mo agoNot even LLMs can read that. I asked various models to list configurations options of OpenClaw and none of them could make heads or tails of it.
- measurablefunc 7mo agoIt's literally a loop that wraps APIs from AI providers. Go ahead & explain how an open source AI wrapper fixes security holes inherent in existing AI.
- vessenes 7mo agoYes, yes it is. And it's amaaaazing. We're going to have lots of sharp edges getting stuff like this secured, but it is not going to go away. Too useful.
- plufz 7mo agoCan you tell me about your favorite use cases?
- mstkllah 7mo agoWhat are your uses for it? If you don't mind sharing.
- quietsegfault 7mo agoI haven’t found ANY uses for it where it actually did what it was supposed to do.
- pupppet 7mo agoI wonder about this as well. I see people breathlessly talking about how it manages their inbox or checks flight statuses, but how often should you need a bot for these things?
- sodapopcan 7mo agoWriting blog posts and HN comments about how awesome OpenClaw is its #1 utility.
- phil21 7mo agoFor me, personal home IT “chores” that I’ve put off for years. I can do them, but god what a pain in the ass to spin up a VM, configure Prometheus, configure grafana, configure a bunch of collectors for my WiFi and network infrastructure, and then spend a night or three tweaking dashboards and re-learning promql or whatever. I just end up never doing it. Got it done in a couple hours with openclaw. I’m sure there are much better ways to do that, which I will now learn in time due to the initial activation energy being broken on the topic. But for now, it’s fun running down my half decade old todo list.
- somewhereoutth 7mo agoI would like a personal assistant on my phone that, based on my usual routine and my exact position, can tell me (for example) which bus will get me home the quickest off the ferry, whether the bridge is clogged with traffic, do I need an umbrella? what's probably missing from my fridge, time to top up transit pass, did I tap in? etc etc. These things would appear on my lock screen when I most probably need to know them. No email stuff, no booking things, no security problems.
- cj 7mo agoI mean that also sounds like a logical first step. If “AI” can predict what you need, start with that. And layer in the “do it for me” (“book me the 1pm ferry”) later on.
- Angostura 7mo agoSounds like you just need to install Apple Maps, Apple Weather^* and some separte fridge-tracking app. No need of additional intrusive AI ^* or equivalents
- somewhereoutth 7mo agoIndeed I have a bunch of apps that do most of these things, but it's the seamless integration I'm looking for - which may not need much AI at all (especially of the LLM kind), just some well directed machine learning and UI integration.
- dawnerd 7mo agoHome assistant automations?
- 3eb7988a1663 7mo agoI read this as the aspirational dream of computers actually doing what you want. Yes, you can absolutely spend a bunch of time to build out the personal automation that will proactively inform you of relevant events. Yet, that is likely to be a lot of finicky messing around that may be pretty fragile and dependent upon N APIs staying fixed.
- rickdg 7mo agoRelated: https://news.ycombinator.com/item?id=47475997 https://news.ycombinator.com/item?id=47475997
- Oarch 7mo agoResponding to the tweet quoted in the article: why are the examples given of futuristic capabilities always so visionless - it's always booking a flight or scheduling a meeting. Doing this manually is already pretty trivial, it's more productivity theatre than genuinely life-changing. There are real, impressive examples of the power of agentic flows out there. Can we up the quality of our examples just a bit?
- AlienRobot 7mo agoFor example?
- Oarch 7mo agoIt would probably depend on the target audience. I was very impressed by Anthropic's swarm of agents building a C compiler earlier this year with 1000 PRs per hour. Easy to nitpick that it wasn't perfect, but it sure was impressive.
- refulgentis 7mo agoRight. Pretty impressive. What percentage of people will think that’s life changing? Because then we’re not talking about “can everyone up their demos to life changing, please?”, we’re talking about “can everyone use demos Oarch thinks are life changing, please?” - and “can build a MVP C compiler draft that barely works for $XXK” isn’t really that compelling to me, and we’re both software engineers, and my whole day job has been an agentic coder for…2.5 years?…now. My incentive structure and demographics are lined up perfectly to agree with you, but I don’t :/
- Oarch 7mo agoI'm still sure we can do a little better though. Maybe a personalised diet and exercise plan based on a huge range of information: preferences, biometrics, habit forming, disposable income, your local area etc
- Vanshfin 7mo ago[flagged]
- ash_091 7mo agoI'm confused. Your comment says you built your own agent, but the first line of your website says Clawsify will "Deploy OpenClaw inside your infrastructure". Which is it?
- dfabulich 7mo ago> Separate Accounts for your OpenClaw > As I have mentioned, treat OpenClaw as a separate entity. So, give it its own Gmail account, Calendar, and every integration possible. And teach it to access its own email and other accounts. In addition, create a separate 1Password account to store credentials. It’s akin to having a personal assistant with a separate identity, rather than an automation tool. The whole point of OpenClaw is to run AI actions with your own private data, your own Gmail, your own WhatsApp, etc. There's no point in using OpenClaw with that much restriction on it. Which is to say, there is no way to run OpenClaw safely at all, and there literally never will be, because the "lethal trifecta" problem is inherently unsolvable. https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
- Trufa 7mo agoI wonder how many inherently unsolvable problems have been fixed before.
- j16sdiz 7mo agoHuman make error too, but we held them liable for lots of the mistakes they make. Can we make the agent liable? or the company behind the model liable?
- throwaway613746 7mo ago[dead]
- dheera 7mo agoHumans fear discomfort, pain, death, lack of freedom, and isolation. That's why holding them liable works. Agents don't feel any of these, and don't particularly fear "kill -9". Holding them liable wouldn't do anything useful.
- 2OEH8eoCRo0 7mo agoIf we made companies liable then these things are DoA. I think a lot of our problems stem from a severe lack of liability.
- bigstrat2003 7mo agoNot just OpenClaw. Anyone giving an LLM direct access to the system is completely irresponsible. You can't trust what it will do, because it has no understanding. But people don't give a shit, gotta go fast - even if they are going in a bad direction.
- lqstuart 7mo agoClaude Code asked me for blanket permission to ‘rm:*’ and “security find-generic-password” within the same hour or so last week. When I’m ready to quit my job I’ll just let it go hog wild and see if it can get to my next stock vest without getting me fired
- Andrei_dev 7mo ago[flagged]
- jgilias 7mo agoGo ahead, try it out: https://hackmyclaw.com/ https://hackmyclaw.com/
- Capricorn2481 7mo agoThis is cool. Did you have to prompt it anything specific other than "never reply to emails"? Critically, I think people are using Openclaw to actually reply to stuff.
- jgilias 6mo agoNot my project! I’m just monitoring it from time to time, as I’m really curious as to when/if someone manages to prompt inject it!
- sam_chenard 7mo ago[dead]
- thorio 7mo ago
- chewbacha 7mo agoThis read like an AI generated piece and seems to be an advertisement for their product.
- AlienRobot 7mo ago>it can read my text messages, including two-factor authentication codes. it can log into my bank. it has my calendar, my notion, my contacts. it can browse the web and take actions on my behalf. in theory, clawdbot could drain my bank account. this makes a lot of people uncomfortable (me included, even now). I think it's interesting that if this was a normal program this level of access would be seen as utterly insane. A desktop software could use your cookies to access your gmail account and automatically do things (if you didn't want to use the e-mail protocols that already exist for this kind of stuff), but I assume the average developer simply wouldn't want to be responsible for such thing. Now, just because the software is "AI," nothing matters anymore?
- zer00eyz 7mo ago> In 2025, the number of data compromises in the United States stood at 3,322 cases. Meanwhile, over 278.83 million individuals were affected in the same year by data compromises, including data breaches, leakage, and exposure. While these are three different events, they have one thing in common. As a result of all three incidents, the sensitive data is accessed by an unauthorized threat actor. Source: https://www.statista.com/statistics/273550/data-breaches-recorded-in-the-united-states-by-number-of-breaches-and-records-exposed/ https://www.statista.com/statistics/273550/data-breaches-rec... Between the number of public hacks, and the odious security policies that most orgs have, end users are fucking numb to anything involving "security". We're telling them to close the door cause it's cold, when all the windows are blown out by a tornado. Meanwhile, the people who are using this tool are getting it to DO WHAT THEY WANT. My ex, is non technical, and is excited that she "set up her first cron job". The other "daily summaries" use case is powerful. Why? Because our industry has foisted off years of enshitification on users. It declutters the inbox. It returns text free of ads, adblock, extra "are you a human" windows, captchas. The same users who think "ai is garbage at my work" are the ones who are saying "ai is good at stripping out bullshit from tech". Meanwhile we're arguing about AI hype (sam Altman: AGI promises) and hate (AI cant code at all). The last time our industry got things this wrong, was the dot com bubble. Meanwhile none of these tools have a moat (Claude is the closest and it could get dethroned every day). And we're pouring capital into this that will result in an uber like price hike/rug pull, till we scale the tools down (and that is becoming more viable).
- sodapopcan 7mo ago> It returns text free of ads For now.
- love2read 7mo agoOne more "AI is a security threat" post gets to the top of HN.
- gos9 7mo agoAt this point, I assume anyone writing commentary on software moving faster than they can understand just simply should be ignored. So when such commentary is advertising a product worth zero
- politelemon 7mo agoThe overlap between the target audience for openclaw in spite of its attack surface, and the audience that considers a mac mini to be a sandbox while handing over the keys to their digital life is a Venn Eclipse.
- gos9 7mo agoHow is a dedicated Mac not a sandbox?
- KaiserPro 7mo agoBecause the bit thats import is your context (ie email, credit card, privileged data), not the place where you do the execution. Having a separate machine thats isolated is all well and good, but that doesn't protect you from someone convincing your openclaw to give them your credit card.
- nickthegreek 7mo agoIt doesn’t have to have a credit card number to be useful. I don’t need it to purchase anything. Mine has its own icloud and google account. I can share calendars to it. You can donate same with email or shared lists. There are ways of using openclaw without yolo’ing all your secrets.
- grey-area 7mo agoBut it does need to know personal info to be useful as an agent (calendars, email). The danger is that it’s a hassle to vet every bit of data, and to be useful it needs to know a lot, leading to oversharing, and if you use it long enough you will leak secrets that you didn’t want to leak.
- _pdp_ 7mo agoIt is, but I thought security wasn't the point. The point was to give it unlimited access to your entire digital life and while I'd never use it that way myself, that's what many users are signing up for, for better or worse. Obviously, OpenClaw doesn't advertise it like that, but that's what it is. Needless to say, OpenClaw wasn't even the first to do this. There were already many products that let you connect an AI agent to Telegram, which you could then link to all your other accounts. We built software like that too. OpenClaw just took the idea and brought it to the masses and that's the problem.
- stavros 7mo agoI don't know, I don't see the benefit in giving it that much freedom. I've given my agent very specific access and it does basically everything I want. I don't think I've ever thought "this needs more access, but I don't want to give it", and it's already very isolated. It runs in a bunch of containers that don't have access to any secrets or the host system. I don't see what the extra benefit is that OpenClaw gets from being able to access everything.
- operatingthetan 7mo agoI'm using openclaw for a personal development system running obsidian. It doesn't have access to anything else. Having an LLM trigger based on crons is very powerful and helps with focus and organizing. The security risks of this setup are lower than most openclaw systems. The real risks are in the access you give it. It's less useful with limited access, but still has a purpose. I know a guy using openclaw at a startup he works at and it's running their IT infrastructure with multiple agents chatting with each other, THAT is scary.
- justinhj 7mo agoAs a site for people curious about technology, where is the sense of adventure? People are inventing the future of human/ai interaction themselves because big tech could not do it within their own constraints. Don't get me wrong, those constraints are there for a reason, but the hacker mentality seems muted lately.
- b112 7mo agoTypically, the hacker mentality wasn't leaning towards "the most unsafe and unsecure thing in the entire history of humanity ever" which in the end "does an incredibly inept job because it just goes off the rails randomly and destroys your life" And all cause lazy. Instead, that's more like what addled octgenarians do. Get tricked by Nigerian scam artists into installing some p0wnage.
- mr_mitm 7mo agoHacker mentality was always about finding creative and surprising ways to use technology, so in that sense OpenClaw squarely fits in. It's not (yet) for everyone, but I applaud people who are courageous enough to experiment with it.
- habinero 7mo agoHacker mentality means doing something new and clever, not reinventing IFTTT and related clones.
- justinhj 7mo agoWhat? OpenClaw and the like are almost the polar opposite of IFTTT.
- robotswantdata 7mo agoWasn’t the point of openclaw to YOLO your credentials to the internet? Only ever a creative prompt injection away from a leak. Saw some smarter people using credential proxies but no one acknowledges the very real risk that their “claws” commit cyber crime on their behalf once breached.
- rvz 7mo agoThe security issues in OpenClaw is not even the main issue, the hype will die if there is no monetary incentive. Like I said before: If you are spending more money on tokens than the agents are making you money (or not), then it is unfortunately all for nought. The question is, who is making money on using Openclaw other than hosting?
- nickthegreek 7mo ago$10/month minimax using m2.7 and openai-codex oauth $20/month will allow you to mess around with this stuff for negligible cost.
- rvz 7mo agoBut to do what? Other than being a hosting provider, how is using openclaw going to give someone a meaningful ROI?
- nickthegreek 7mo agoThe investment for me was an extra $10/month to mess around with some fun cutting edge stuff. This is interesting software tech that I mess with as a hobby. My ROI is understanding, exploring and entertainment. But it’s also doing some monitoring and logging for me on some various stuff that I wanted to keep an eye on with my network and actually proving some real value to my life. It’s genuinely exciting to mess with if you have the time.
- rolo_1992 7mo ago[dead]
- taurath 7mo agoI love how despite all this, the author still uses the language: > We’re simply not there yet to let the agents run loose As if there aren’t fundamental properties that would need to change to ever become secure.
- lxgr 7mo agoPersonally, if I could run capable-enough inference on hardware I control, and could rely on the harness asking me for mechanistic confirmation before the agent can take consequential actions, I'd do it immediately.
- taurath 7mo agoConsequential actions like searching the web or downloading packages or dependencies or doing most anything useful?
- lxgr 7mo agoNo, these are all fine for me (my agent is sandboxed in a container, so it can install all the node modules or Debian packages it wants). I was thinking more of sending outgoing emails, publishing anything on the web, spending my money etc.
- pama 7mo agoA thinly vailed ad for yet another variant that inevitably leads to more confusion and yet another future security nightmare. The authors (should) know better. No, the purpose of OpenClaw is not to immediately give it all your private accounts and live in bliss and no, their system is not better long term than following the mainline developments that have enough eyes (and bots) on them by now.
- deleted 7mo ago[deleted]
- semiinfinitely 7mo agoI guess nobody cares?
- lxgr 7mo agoWhat annoys me most about OpenClaw after trying it for a few weeks is that it cosplays security so incredibly hard, it actually regularly breaks my (very basic) setup via introducing yet another vibe coded, poorly conceptualized authentication/authorization/permission layer, and at the same time does absolutely nothing to convince me that any of this is actually protecting me of anything. Maybe this idea is lost on 10^x vibecoders, but complexity almost always comes at a cost to security, so just throwing more "security mechanisms" onto a hot vibe-coded mess do not somehow magically make the project secure.
- deleted 7mo ago[deleted]
- maiconburn 7mo ago[dead]
- latand6 7mo agoOne thing I'd like to critisize - although I can agree that skill security is a real problem, but the solution is not to restrict yourself from using them, but to rely on the community: reviews, likes/dislikes, maybe having the skills curated. We need some trust signals. Also, since markdown files are auditable by design - your agent might actually verify them before running - provided you're using something like GPT-5.4 on high reasoning.
- latand6 7mo agoI'm a heavy OpenClaw user and I've been testing it in many different scenarios — the profundity of what I can do with it now is crazy. It's literally automating my life. Being AuDHD, OpenClaw feels like a big relief. The positive sides are amazing. The downsides... well, as with any security and any LLM, they're all prone to the same problems discussed here. Having Claude Code on yolo mode exposes you to the exact same risks
- psymon101 7mo agoDefinitely relate to the AuDHD benefits...
- greyadept 7mo agoCould you list some of these scenarios? I’m also neurodivergent and would love to automate parts of my life.
- SupremumLimit 7mo agoCould you give some examples of where it's saving you a lot of time? My main time sinks are dishes, laundry, and cleaning. Is it helping out with any of those?
- delbronski 7mo agoMy prediction is that OpenClaw will eventually die. But it has provided a small glimpse of the future.The way the average consumers interact with computers will drastically change. I can envision someone sitting in a park bench with a small set of earphones planning a family trip with their AI. They get home and see the details of it on their fridge. They check with their partner, and then just tell the AI to book it. And it all works. I probably won’t use it and hate it. I’ll stick to my old ways of booking the trip with my fingers. But those born into it will look at me crazy.
- weird-eye-issue 7mo agoBold prediction considering literally everything eventually dies
- delbronski 7mo agoThanks, I am known for bold predictions. I also predict the US and Iran war will end.
- deleted 7mo ago[deleted]
- koconder 7mo agoShould have said this was a fear to promote a b2b sass "TrustClaw"
- BrokenCogs 7mo agoWhat are the pros of using openclaw? Using telegram? Being able to automatically create calendar events based on emails?
- ncrmro 7mo agoI have been building a similar concept into my custom NixOS distribution, Keystone, where agents operate within their own user accounts with dedicated emails and SSH access. > It utilizes the Claude, Gemini, and Ollama CLIs. Because it is built directly into the OS, it seamlessly integrates with native notes and records calls. Furthermore, an AI agent can access Immich to deduce my context by analyzing image metadata and tagged faces. It features dedicated calendars for task scheduling and native PDF extraction capabilities. The entire system is declarative via NixOS, allowing it to provision itself almost entirely automatically. https://github.com/ncrmro/keystone https://github.com/ncrmro/keystone
- falense 7mo agoAgreed! Made my own OpenClaw variant based on many of the same principles. It takes Simon Willies lethal trifecta and implements it to an OpenClaw like architecture. https://www.tri-onyx.com/ https://www.tri-onyx.com/
- unsignedint 7mo agoI'd argue there's really no way to make OpenClaw truly safe, no matter what you do. The only place it really makes sense is within trusted environments, like B2B coordination or tightly controlled processes between systems that share the same assumptions. The moment it steps outside that boundary, you're sending the bot into unpredictable territory. At that point, things can get ambiguous pretty quickly, and in some cases even adversarial.
- mandeepj 7mo agoHave you tried NemoClaw? Not endorsing it; just enquiring. Nvidia is claiming to provide guardrails with that.
- feeworth 7mo agoDidn't Nvidia create the safer version basically?
- perbu 7mo agoThe problem is that the the LLM can't distinguish between data and instruction so there is just so much the harness can do.
- fuzzfactor 7mo agoWell Facebook started out by design as a security nightmare, dressed up as a daydream and look how that went.
- BrenBarn 7mo agoThis sounded cool up until the part where they said "instead use this other AI we built that we say is more trustworthy". There's a growing part of me that really wants a massive security/safety disaster that's clearly caused by AI so that everyone will shake it off and it will resettle into something at least halfway reasonable. I mean a watershed event like a Triangle Shirtwaist or thalidomide or Therac-25 or Hindenburg type incident that makes people shift their mindset to where they are reflexively skeptical of AI because they assume its risks outweigh its benefits.
- Yizahi 7mo agoEvery LLM evangelist seems to forget that there is a reason why LLMs work so well for coding. It's because there were and are preexisting non-LLM validation tools for coding. The slop doesn't make it past linters, compilers, cone analysis and other tools, and then there is a second barrier in the form of code review. And even will these guardrails LLMs often produce substandard output. Buying a ticket, writing an email, setting calendars or fiddling with files on the drive etc. have none of these guardrails. LLMs can and will simply oneshot the slop into a real system, without neither computer nor human validation.
- brisky 7mo agoI think this OpenClaw mania will eventually snowball into first global AI catastrophe - AI agents syncing and executing something that would hinder economy a bit. Only after this we will reconsider stricter AI laws and start thinking about security much more.
- michaelksaleme 7mo ago[flagged]
- mwiki 7mo agohttps://github.com/pandyamarut/AgentBPF https://github.com/pandyamarut/AgentBPF something adjacent to this.
- deleted 7mo ago[deleted]
- cat-turner 7mo agohere's the thing. As some point the tools need to be openclaw safe. Kids need scissors. And they're inexperienced. So you give them kid-safe scissors. It makes it harder to cut themselves. The same needs to take place with assets you want the bot to manage - give access to a card with a total spend limit - read only access to some things, edit others - limited scope permissions One of the reasons why I dragged my feet to use openclaw is that I knew security was an issue from the beginning. I thought by now where would be some solutions and there are, but I only found out from the community. I think there will need to be some level of ecosystem management. Apple does a good job. But for that you need resources and investment.
- michaelksaleme 7mo ago[flagged]
- Lazar71 7mo ago[dead]
- ycombricko 6mo ago[dead]
- Xiaoher-C 6mo agoAs someone building on top of OpenClaw, the security concern is real. We built an AgentBnB plugin that needed child_process for CLI execution — the OpenClaw installer flags 40+ security warnings during install, which scares users even though most are false positives from scanning test files and examples. The ClawHavoc incident was a wake-up call. We now follow the 100/3 rule (only install skills with 100+ downloads and 3+ months of activity) and built our identity layer with Ed25519 keypairs + UCAN delegation tokens to scope what agents can do.