• ReallyCoolDude@lemmy.ml
    link
    fedilink
    English
    arrow-up
    83
    arrow-down
    1
    ·
    24 hours ago

    How could any person with some programing literacy event thinking about installing openclaw. A malware ridden by critical bugs

    • Jrockwar@feddit.uk
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      5 hours ago

      I don’t think there’s anything wrong with running Openclaw. What is way too brave for my taste is giving it access to accounts with your personal data, or the filesystem in your computer. That’s a disaster waiting to happen.

      I run it in an isolated server, and it doesn’t have access to my data - if it goes tits up, it deletes unimportant stuff only. If anyone gets access to the credentials in it, it’s a bunch of budget-limited API keys, so they can spend all of $4 on openrouter. Maybe the riskiest bit is its Google account. I went with the approach of giving it its own Google account, so that it can create docs and calendar events and then add me, rather than getting access to my Google account. But then again… That account has no payment info, nothing that I would be mega worried if it got leaked…

      Sure, it might limit the usefulness a bit, but I think installing something like this is only acceptable if you sandbox it and don’t let it access valuable information. Going full mad scientist on something as “alpha” as this, letting it run wild with your info is nuts.

      • flux@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I went with the approach of giving it its own Google account, so that it can create docs and calendar events and then add me, rather than getting access to my Google account.

        I wonder though: if Google can link this account to you as its actual owner, I wonder if there’s a risk if the bot does something against the ToS?

        I hope you have backups of your Google account…

    • XLE@piefed.social
      link
      fedilink
      English
      arrow-up
      46
      ·
      20 hours ago

      She’s the head AI Safety Expert for Meta. The field might as well be labeled AI Misunderstander.

      • ReallyCoolDude@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        8 hours ago

        I work with some data sciencetists and ml engineers on web projects. They might be good at etls, fine tuning etx, but dont let them touch anything with a public.layer or infra constraints.

    • 5gruel@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      13
      ·
      19 hours ago

      I program medical devices for a living and I have openclaw and nanobot running at home. AMA.

      • melfie@lemy.lol
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        2 hours ago

        I don’t get all the downvotes, unless people misinterpreted your comment and assume you’re using it for medical devices. It’s open source and can be run with locally hosted, open weight models, so no harm in playing around with it as long as you don’t give it access to anything too risky.

        • 5gruel@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          2
          ·
          8 hours ago

          Because i want to work on meaningful things that benefit people directly.

          Because i want to unterstand the capabilities and limitations of openclaw-like agents. LLMs aren’t going away, better be proactive and learn what the hype is about.

        • 5gruel@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          7 hours ago

          That’s why unit and integration tests shouldn’t be written by Copilot.

      • ReallyCoolDude@lemmy.ml
        link
        fedilink
        English
        arrow-up
        6
        ·
        17 hours ago

        How you deal with critical vulnerabilities on your system? Do you work with high confidential data and have openclaw os those system? How many medical devices did you have to secure from mass incursion?