Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster

⁨183⁩ ⁨likes⁩

Submitted ⁨⁨1⁩ ⁨day⁩ ago⁩ by ⁨Beep@lemmus.org⁩ to ⁨technology@lemmy.world⁩

https://securityscorecard.com/blog/beyond-the-hype-moltbots-real-risk-is-exposed-infrastructure-not-ai-superintelligence/

source

Comments

Sort:hotnewtop
  • XLE@piefed.social ⁨1⁩ ⁨day⁩ ago

    It’s nice to see articles that push back against the myth of AI superintelligence. A lot of people who brand themselves as “AI safety experts” preach this ideology as if it is a guaranteed fact. I’ve never seen any of them talk about real life present issues with AI, though.

    (The superintelligence myth is a promotion strategy; OpenAI and Anthropic both lean into it because they know it boosts their stocks.)

    source
    • Imgonnatrythis@sh.itjust.works ⁨1⁩ ⁨day⁩ ago

      Thankfully Steinberger is the first to deny that this is AGI.

      source
  • 4grams@awful.systems ⁨1⁩ ⁨day⁩ ago

    I am playing with it, sandboxed in an isolated environment, only interacting with a local LLM and only connected to one public service with a burner account. I haven’t even given it any personal info, not even my name.

    It’s super fascinating and fun, but holy shit the danger is outrageous. Multiple occasions, it’s misunderstood what I’ve asked and it will fuck around with its own config files and such. I’ve asked it to do something and the result was essentially suicide as it are its own settings. I’ve only been running it for like a week but have had to wipe and rebuild twice already (probably could have fixed it, but that’s what a sandbox is for). I can’t imagine setting it loose on anything important right now.

    But it is undeniably cool, and watching the system communicate with the LLM model has been a huge learning opportunity.

    source
    • baltakatei@sopuli.xyz ⁨1⁩ ⁨day⁩ ago

      Reminds me of a quote from Small Gods (1992) about an eagle that drops vulnerable tortoises to break their shell open:

      But of course, what the eagle does not realize is that it is participating in a very crude form of natural selection. One day a tortoise will learn how to fly.

      source
    • Ulrich@feddit.org ⁨1⁩ ⁨day⁩ ago

      the LLM model

      the Local Language Model model?

      source
      • 4grams@awful.systems ⁨1⁩ ⁨day⁩ ago

        lol, straight from the redundant department of redundancies.

        I do words good.

        source
    • Imgonnatrythis@sh.itjust.works ⁨1⁩ ⁨day⁩ ago

      Curious, are you having it do anything useful? If it could be trusted, a local Ai assistant would benefit from access to many facets of personal data. Once upon a time I had a trusted admin - I gave her my cc info, key fob, calendar and email access and it was amazing. She could schedule things for me, have my car taken to the shop, maintain my calendar etc. Trust of course is the key here, but it would be great to have even a small taste of that kind of help again.

      source
      • XLE@piefed.social ⁨1⁩ ⁨day⁩ ago

        There’s a story about a guy who asked his LLM to remind him to do something in the morning, and it ended up burning quite a lot of money checking to see if daylight had broken once every 30 minutes with an unnecessary API call. Such is the supposed helpful assistant.

        source
        • -> View More Comments
      • 4grams@awful.systems ⁨1⁩ ⁨day⁩ ago

        Nope, nothing useful. Right now I am playing with making some skills to do some rudimentary network testing. I figure it’s always nice to have a remote system to ping or nslookup or check a website from a remote location. I have it hooked to a telegram bot (burner account and restricted to just me) and I can ask it to ping or get me a screenshot or speedtest, etc. from anything it can reach on the internet.

        Only purpose right now is to have something to show off :).

        source
  • blackbarn@lemmy.zip ⁨1⁩ ⁨day⁩ ago

    You can be more deliberate with something like n8n and connect an LLM with memory/tools (very specific and more restricted)/etc to any number of triggers, including chat. At least I imagine so. More effort to set up, but maybe that’s a good thing. Haven’t messed with openclaw though.

    source
  • systemglitch@lemmy.world ⁨1⁩ ⁨day⁩ ago

    We’re strike my midnight soon.

    source