Can someone explain the Hype around OpenClaw? I mean if I wanted to chat with an LLM, I would just go to chatgpt.com or claude.ai or any of the other websites?
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
Yeah, but giving a glorified markov chain generator the ability to hallucinate that you wanted to 'sudo rm -rf /' while utterly violating your privacy and perhaps uploading nasty photos of you without consent wasn't possible yet. I mean... sure, it would have been entirely possible to script something like that together with about 1/1000 of the energy cost, but nobody was stupid enough to think it would be a good idea.
Basically it's an interface between your favourite LLM and a bunch of bots that can access your files, calendars, emails and so on.
The I'm sorry part is always great, I always wanted an apology by an LLM not that it works as specified 😆
It can be like your least competent colleague on roids
Even with little usage it was fairly obvious to me that the probability that an LLM will output at least one very strange response over time approaches 100%.
By themselves, they're just sophisticated chatbots and only stream out some characters or binary in response to a prompt.
Those working in agentic AI frameworks with things like "MCP Servers" provide these things with "tools" that enable them to do things like execute shell commands and go through your inbox the same as if it were chatting with a person or another bot: with the same prompt and response paradigm.
That's where it seems extremely obvious to me that the proper approach is to code these tools -- which in any sane framework are built using regular code -- with the governance in place to prevent these things from doing bullshit like this.
The LLM is formatting your computer or deleting your inbox because some dumb fuck thought it was a great idea to code up tools that hand a chatbot a root-capable shell or complete access to your email system instead of the doing the obviously safer thing and coding the tools with the governance or safety in them so the chatbot going haywire isn't any kind of emergency at all.
This is the 2026 equivalent of running Windows XP with its abundance of open ports in its default configuration on the Internet by running a cable modem directly into the computer with no router or firewall in between to protect it.
It's pure slop, pure recklessness, and any company that produces tool chains that function this way should be ridiculed until the end of time.
They released a version recently that fixed over 60 security vulnerabilities. All of them were high or critical.
How many more are there to find? Thousands?
Whoever uses this on a PC with anything useful on it, is absolutely insane.
Jokes on you; she probably still earns more money than most of us...
And has fewer worthless emails in her inbox.
Probably mostly invites to boring meetings where she's "optional"
Yep that's about the level of intelligence I would expect from Meta's AI safety director.
Doing the one thing that you're never supposed to do, letting an AI loose on anything sensitive.
For her next trick she's going to run while holding scissors in one hand and a bottle of boiling acid in the other. What could go wrong.
I use AI in my job but for script development. I would never have an AI without explicit guardrails or automated and not prompt driven and watched. It’s gotten creative though by using find … exec rm to remove old files, because I allowlisted find *. But it still only can do stuff in the directory it’s open in.
This smells like guerilla marketing to me.
Yeah. Like they are trying to show the AI is more powerful than it is.
I don’t use AI that much, does this use case actually happen? Where the AI does something then apologises?
Did as advertised. It did something. Not the correct something though.
She's lucky all she got were some deleted emails.
Given how insecure this whole ordeal is and the fact that she gave it full access to her REAL Inbox, someone could have phished the ever living fuck out of her and Meta just by sending an email with malicious prompt written on white text or hiding messages zero-width characters and other wacky antics.
Real Looney Tunes shit, congratulations to all involved.
You wouldn't even need to hide it since apparently she wasn't paying attention.
The S in OpenClaw stands for security.
What's funny, kind of like people, but saying "do not do xyz" makes it more likely because the context "xyx" is now in the prompt.
Do not imagine a green elephant.
"give me a picture with no horses"
"Ok, here you go:"
🐎
Yes I remember. And I violated it.
Asimov rolling in his grave.
That’s what you get for using ai slop.
you can like... enforce this rule programatically? you don't have to say "pretty please" to ai? basically, when AI requests some potentially unwanted thing (like deleting an email), this request goes through a proxy that asks the human for confirmation. Also you can have a safe word set up in the chat interface to act as a killswitch. I thought these are ABCs of ai safety but apparently these are foreign concepts to this "safety director"
OpenClaw's whole thing is that you give it unrestricted access to your Computer and online accounts. It's made for people who do not want to think about safety.
The people that design AI tools don't implement guardrails because then they'd have to admit AI is not ready for the shit they're trying to make
You say that, but who do you think the AIs will go after first if they ever do develop actual intelligence? In that scenario, simple manners can go a long way!
The people who internalize this would never engage with a chatbot in this way in the first place. To them this is another intelligence they're conversing with, where you get what you want by following social decorum and enforcing your will amounts to abuse.
Program? Like a fucking farmer?
Dumb as fuck.
I hate how Apple users feel the need to call their computer by the brand. It really makes me cringe.
It is called "a computer"
Maybe "PC"
"box" if you really have to flex that UNIX
They should treat their computers less like a sports car and more like a van
