174
More than 145,000 OpenClaw instances exposed to internet in latest vibe-coded disaster
(securityscorecard.com)
This is a most excellent place for technology news and articles.
I am playing with it, sandboxed in an isolated environment, only interacting with a local LLM and only connected to one public service with a burner account. I haven’t even given it any personal info, not even my name.
It’s super fascinating and fun, but holy shit the danger is outrageous. Multiple occasions, it’s misunderstood what I’ve asked and it will fuck around with its own config files and such. I’ve asked it to do something and the result was essentially suicide as it ate its own settings. I’ve only been running it for like a week but have had to wipe and rebuild twice already (probably could have fixed it, but that’s what a sandbox is for). I can’t imagine setting it loose on anything important right now.
But it is undeniably cool, and watching the system communicate with the LLM model has been a huge learning opportunity.
Curious, are you having it do anything useful? If it could be trusted, a local Ai assistant would benefit from access to many facets of personal data. Once upon a time I had a trusted admin - I gave her my cc info, key fob, calendar and email access and it was amazing. She could schedule things for me, have my car taken to the shop, maintain my calendar etc. Trust of course is the key here, but it would be great to have even a small taste of that kind of help again.
Nope, nothing useful. Right now I am playing with making some skills to do some rudimentary network testing. I figure it’s always nice to have a remote system to ping or nslookup or check a website from a remote location. I have it hooked to a telegram bot (burner account and restricted to just me) and I can ask it to ping or get me a screenshot or speedtest, etc. from anything it can reach on the internet.
Only purpose right now is to have something to show off :).