Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. There used to be a time when building out a botnet required *some* work – writing exploits, taking over devices, obscuring the purpose of the executable, etc.

There used to be a time when building out a botnet required *some* work – writing exploits, taking over devices, obscuring the purpose of the executable, etc.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
openclawhypeinfosec
47 Indlæg 19 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • rysiek@mstdn.socialR rysiek@mstdn.social

    @marcink right?

    Don't worry, as soon as OpenClaw gets hit by supply-chain attack, which they inevitably are going to, this will flip.

    marcink@stolat.townM This user is from outside of this forum
    marcink@stolat.townM This user is from outside of this forum
    marcink@stolat.town
    wrote sidst redigeret af
    #41

    @rysiek But between this being openclaw and the insufferably LLM-ish tone of the blog post (pictured below) we can at least rest assured that there is a chance that no human being had to be involved in writing, editing, or reviewing these.

    rysiek@mstdn.socialR 1 Reply Last reply
    0
    • marcink@stolat.townM marcink@stolat.town

      @rysiek But between this being openclaw and the insufferably LLM-ish tone of the blog post (pictured below) we can at least rest assured that there is a chance that no human being had to be involved in writing, editing, or reviewing these.

      rysiek@mstdn.socialR This user is from outside of this forum
      rysiek@mstdn.socialR This user is from outside of this forum
      rysiek@mstdn.social
      wrote sidst redigeret af
      #42

      @marcink what a fantastic scene in that film.

      marcink@stolat.townM 1 Reply Last reply
      0
      • rysiek@mstdn.socialR rysiek@mstdn.social

        @marcink what a fantastic scene in that film.

        marcink@stolat.townM This user is from outside of this forum
        marcink@stolat.townM This user is from outside of this forum
        marcink@stolat.town
        wrote sidst redigeret af
        #43

        @rysiek If there is any silver lining to this LLM bubble is that it will provide way more than enough material for a sequel.

        1 Reply Last reply
        0
        • rysiek@mstdn.socialR rysiek@mstdn.social

          There used to be a time when building out a botnet required *some* work – writing exploits, taking over devices, obscuring the purpose of the executable, etc.

          Not any more!

          Instead of "malware", call it an "AI agent" and people will just happily install it on their devices with full root privileges!
          https://github.com/jgamblin/OpenClawCVEs/

          Bam! RCE by asking nicely.

          🧵

          #OpenClaw #AI #Hype #InfoSec

          fds@mastodon.socialF This user is from outside of this forum
          fds@mastodon.socialF This user is from outside of this forum
          fds@mastodon.social
          wrote sidst redigeret af
          #44

          @rysiek it’s a shame we still act like people are doing great things when they publish stuff like this.

          rysiek@mstdn.socialR 1 Reply Last reply
          0
          • fds@mastodon.socialF fds@mastodon.social

            @rysiek it’s a shame we still act like people are doing great things when they publish stuff like this.

            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.social
            wrote sidst redigeret af
            #45

            @fds 💯

            (assuming "stuff like this" is OpenClaw, not the openClawCVEs repo)

            fds@mastodon.socialF 1 Reply Last reply
            0
            • rysiek@mstdn.socialR rysiek@mstdn.social

              Do they mention any of this on their landing page? No, of course not:
              https://openclawai.io/

              Do they mention this on their quickstart page? No, of course not:
              https://openclawai.io/quickstart

              But they sure mention the managed hosting that is "coming soon"! Which of course they shill in their blogpost about the vulnerabilities:

              > For many users, that’s a reasonable tradeoff. For others, it’s the argument for managed hosting.

              Security fuckup? More like business opportunity, amirite? 🤡

              🧵

              womble@infosec.exchangeW This user is from outside of this forum
              womble@infosec.exchangeW This user is from outside of this forum
              womble@infosec.exchange
              wrote sidst redigeret af
              #46

              @rysiek the entire basis of modern capitalism is to sell the solution to a problem you yourself created.

              1 Reply Last reply
              0
              • rysiek@mstdn.socialR rysiek@mstdn.social

                @fds 💯

                (assuming "stuff like this" is OpenClaw, not the openClawCVEs repo)

                fds@mastodon.socialF This user is from outside of this forum
                fds@mastodon.socialF This user is from outside of this forum
                fds@mastodon.social
                wrote sidst redigeret af
                #47

                @rysiek Oh yes definitely OpenClaw. I have no problem whatsoever if people want to experiment on their own, but it was highly irresponsible to release it in the state it was in, imo.

                1 Reply Last reply
                0
                • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                Svar
                • Svar som emne
                Login for at svare
                • Ældste til nyeste
                • Nyeste til ældste
                • Most Votes


                • Log ind

                • Har du ikke en konto? Tilmeld

                • Login or register to search.
                Powered by NodeBB Contributors
                Graciously hosted by data.coop
                • First post
                  Last post
                0
                • Hjem
                • Seneste
                • Etiketter
                • Populære
                • Verden
                • Bruger
                • Grupper