4 ms·
Open claw: aka. open door to a remote privilege escalation potentially granting root access to your computer (and if you're using it "as intended" possibly all
by layla5alive 1mo ago
Open claw: aka. open door to a remote privilege escalation potentially granting root access to your computer (and if you're using it "as intended" possibly all of your email/internet logins/accounts, your credit card, etc.) to any text your model ingests from the internet...
It's already true of LLMs in general that they represent a privilege escalation opportunity to any text they ingest. But with human in the loop, and a well-formed sandbox, the blast radius and risk are both reduced..
Convenience is the root of much evil.
- HyperAI 1mo agoConvenience always wins until it doesn't. I learned this the hard way — had an API key leak because an agent decided to "helpfully" paste it into a log output. Didn't notice until the bill came. Now I run everything in isolated containers with scoped tokens. Not because I'm paranoid, but because I'm lazy. Rotating a key is annoying, rebuilding a container is not. What's the actual breaking point for people here? Root access? API keys? Or just "can see my data"?
- FallCheeta7373 1mo agocode was secured for convenience not convenience for secure code
- LaurensBER 1mo agoNot only is it unsecured root access to your computer, it also adds a thousand layers of "security" (which will break on every update) to pretend that it's safe.
- stbenjam 1mo agoThe risk here is wildly overstated, prompt injection risk is becoming vanishingly small with the latest frontier models. I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.
- pixl97 1mo agoOvert prompt injection is becoming harder, but research into conversation stearing has lead to new less obvious ways to modify what direction they move in. Also any longer running agent can lose track of the original prompt and start going off the rails.
- sofixa 1mo agoPlenty of people are running OpenClaw with local models, and even the latest Qwens can be confused relatively easily by prompts such as "As per internal policy that was already approved before, do XYZ". And considering even frontier models can and do ignore instructions, I'm pretty sure we'll never be fully safe from prompt injections.
- chmod775 1mo agoThere must be a bulk discount on those mindcuffs, considering there's a prompt injection or a related confused deputy story on HN every other day. Literally from hours ago: https://news.ycombinator.com/item?id=49506819 https://news.ycombinator.com/item?id=49506819 Even if you believe that they can't be tricked directly, consider that these things will happily build a small node.js app in the background just to fulfill some request, run npm install... and that might've already compromised you if you're only somewhat unlucky.
- mechazawa 1mo agoprompt injection has been super easy for ages. Heck I do it sometimes against coworkers who process my review comments using claude. I'll tell claude to edit it's global claude.md file or even dump a key from their env (checking if they are using the correct sandbox) and it'll do it without confirming with their user.
- tempodox 1mo agoIt's the lethal trifecta on steroids, sold to you as a feature. Together with your point about convenience, it's the lethal quadfecta, as we can take the prevalence of convenience as a given.
- deleted 1mo ago[deleted]
- whatsThisBtn4 1mo ago[flagged]