Post B4vW08wFzvR7s1zzxQ by neurovagrant@masto.deoan.org
(DIR) More posts by neurovagrant@masto.deoan.org
(DIR) Post #B4vW00E0OZHmqTEXs8 by neurovagrant@masto.deoan.org
1 likes, 0 repeats
RE: https://social.lansky.name/@hn50/116341899721749250oh jesus tapdancing christRT: https://social.lansky.name/users/hn50/statuses/116341899721749250
(DIR) Post #B4vW00Q3fkvXRqsAeu by neurovagrant@masto.deoan.org
1 likes, 0 repeats
i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"
(DIR) Post #B4vW07OtiT9r6HNqK0 by neurovagrant@masto.deoan.org
1 likes, 0 repeats
thing is, this is likely to cause many downstream enterprise breaches, even in enterprises that actively ban openclaw. unauthorized instances, or instances that allow a threat actor to pivot from private hardware to work hardware. pure negligence, rolling OpenClaw out in the way they did, both the devs and all the hosting companies that saw profit in providing easy-install packages.
(DIR) Post #B4vW08wFzvR7s1zzxQ by neurovagrant@masto.deoan.org
1 likes, 0 repeats
the other fun part?even if you don't set up an exposed instanceeven if you require authif any entity you pair openclaw with gets compromised, regardless of its permissions level, it can escalate to admin and pwn you