logoalt Hacker News

rvzlast Friday at 5:20 PM3 repliesview on HN

OpenClaw has over 400+ security issues and vulnerabilities. [0]

Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks?

Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone.

[0] https://github.com/openclaw/openclaw/security


Replies

da_grift_shiftyesterday at 5:22 AM

Wow. The advisories page is worthy of a post in itself.

nickthegreeklast Friday at 5:23 PM

It does not need access to your full machine. It can literally run in a vps.

show 3 replies
TacticalCoderyesterday at 1:35 PM

Upvoted because, yup, it's insanity.

However:

> Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks?

I'd say that it's a given that we live in a world when your LAN is infested with compromised and hostile devices: from phones (spying devices) to home automation (spying chinese webcams) to TVs (with the TV's microphone listening 24/7 to everything people are saying) to chinese routers (which, yup, have backdoors for the chinese state) to that corean soundbar to really whatever enshittied device the world of enshittified turds we live in can come up with.

It is a fact of life that compromised, insecure, backdoored and at times all three of these shall find their way to our homes and appartments...

And it shouldn't be an issue.

What I mean by this: machines could be scanning my local networks and even maybe determine that this box at this IP is running Linux and... It still should be able to do exactly jack fucking shit with that information.

We must all learn to secure our devices for the Internet of Insecure and Enshittified Things is moving forward at godspeed. And if you think OpenClaw on its own device on your LAN is bad, wait until all the companies that were already selling enshittifed devices since years realize they'll now be able to enshittify those even more by slapping OpenClaw (or the equivalent) on their devices.

These insecure turds are all going to get a big boost of insecuredness, this time AI powered.

I'd say: bring it on. I'm ready. We all should be.