frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: OpenClaw is supposedly a security nightmare, but is it?

2•butILoveLife•1h ago
Two types of knowledge: Induction(from experience) and Deduction(from logic).

Deduction: Can OpenClaw get prompt injected and delete your filesystem and send your money to a hacker? Yes, it has all the tools to do so.

Induction: Has this ever happened? Not yet.

Induction is probabilistically true. Deduction is either true or false.

Someone prove me wrong, but a normie isnt getting a multi million dollar 0 day spent on them. And in the wild, openclaw seems to be doing fine.

I'd argue there is some 99% chance that OpenClaw is going to be fine for me. (And that number is probably low)

Comments

aytuakarlar•1h ago
For a weekend project or local use case, your inductive reasoning (probabilistically, no one is spending a 0-day on me) is totally fine. But the moment you move to enterprise, fintech, or any system handling real data, I truly believe that relying on induction is a non-starter.

The deductive risk (the fact that the agent can execute rm -rf or transfer funds if prompted maliciously) is actually very common. I am working with one of the top universities in my country to write a paper about that issue. We benchmarked 118 test scenarios, 1,062 API calls across GPT-4o, Claude Sonnet, and Gemini Flash. they all fail to consistently follow their own guardrails. The results will be published by if you are interested here are the charts:

https://github.com/akarlaraytu/llm-agent-policy-enforcement

We shouldn't have to choose between crippling the agent's capabilities and just hoping we don't get targeted. And I really believe that the solution is putting a deterministic governance layer between the agent and the execution environment.

This is actually why I started building a product according to that and I just published a Show HN here. You can check it out and if you are interested I can give you credit on my platform which is dedicated to restrict unsafe behaviors and decisions of AI agents.

https://news.ycombinator.com/item?id=47501849

Rust Training

https://github.com/microsoft/RustTraining
1•dcuthbertson•56s ago•0 comments

OSS Is Dead

https://www.youtube.com/watch?v=6godSEVvcmU
1•FpUser•2m ago•0 comments

NYSE teams up with Securitize to develop tokenized securities platform

https://www.reuters.com/business/nyse-teams-up-with-securitize-develop-tokenized-securities-platf...
1•giuliomagnifico•3m ago•0 comments

What are the best headless browsers?

1•aledevv•3m ago•0 comments

EU, Australia seal trade deal as Western countries hedge against U.S. risks

https://www.cnbc.com/2026/03/24/eu-australia-trade-deal-trump-tariffs-war-risks.html
1•doener•5m ago•0 comments

Rust Threads on the GPU

https://www.vectorware.com/blog/threads-on-gpu/
1•emschwartz•5m ago•0 comments

Show HN: I Built an Open-Source Math Academy for Propositional Logic

https://plcourse.moaaza.com/auth?redirectTo=%2Fhttps%3A%2F%2Fsveltekit-prerender%2F
1•moaaz_ae•5m ago•1 comments

Is it me or is Claude memory causing fixation?

1•ahd94•6m ago•0 comments

Show HN: NeedHuman – API that lets AI agents hire a real human when stuck

https://needhuman.ai
1•mariusaure•6m ago•1 comments

Better Memory Tiering, Right from the First Placement

https://danglingpointers.substack.com/p/better-memory-tiering-right-from
1•blakepelton•8m ago•0 comments

Reflecting on the Crimson Desert Debacle

https://tapestry.news/tech/crimson-desert-ai/
1•zygon•9m ago•0 comments

Using Markov Models for Password Complexity Estimation in Microsoft Edge

https://microsoftedge.github.io/edgevr/posts/Using-Markov-model-for-password-complexity-estimatio...
1•soheilpro•9m ago•0 comments

71% of Waterloo's best engineers leave Canada

https://twitter.com/ericjackson/status/2035807638789800001
2•TimGubth•9m ago•0 comments

12,479 Applications, Zero Ghosting: A Look at Checkly's 2025 Hiring

https://www.checklyhq.com/blog/checkly-2025-hiring-data/
2•tnolet•10m ago•0 comments

My Trackz – Habit Tracker App

https://mytrackz.com
1•saturn5k•11m ago•0 comments

So where are all the AI apps?

https://www.answer.ai/posts/2026-03-12-so-where-are-all-the-ai-apps.html
4•tanelpoder•11m ago•1 comments

Beyond the Big Three: Building a Sovereign EU Cloud Stack

https://octigen.com/blog/posts/2026-03-24-sovereign-cloud-journey/
5•m_mueller•12m ago•0 comments

Detach or Die

https://emilybroadhurst.substack.com/p/detach-or-die
2•embrata•12m ago•1 comments

Show HN: Agonora – Character benchmarking for the post-AI job market

https://agonora.com/
1•mw67•13m ago•0 comments

Show HN: Typerson – Turn boring forms into chat-like experiences

https://www.typerson.com
1•briandev•13m ago•1 comments

We are losing our ability to understand the world

https://chinatowntyler.substack.com/p/the-closing-range
1•orange_joe•13m ago•1 comments

Ask HN: Go-to places to get some ideas to work on

1•sujayk_33•13m ago•0 comments

Applying the self-driving framework to commercial insurance underwriting

https://www.shepherdinsurance.com/blog/the-road-to-autonomous-underwriting
2•mmahalwy•14m ago•1 comments

I built a crash dump analyzer for C++ devs after getting burned by WinDbg

https://github.com/keithpotz/Crash-Catch-Analyzer-Release
1•crashcatchlabs•14m ago•0 comments

Xrism identifies gamma Cas X-ray origin, solving a 50-year-old stellar mystery

https://phys.org/news/2026-03-xrism-gamma-cas-ray-year.html
1•Brajeshwar•15m ago•0 comments

Graphs: Edge List, Adjacency Matrix, Adjacency List, DFS, BFS

https://www.youtube.com/watch?v=4jyESQDrpls
1•Brysonbw•16m ago•0 comments

Show HN: Vesper – MCP-native tool that automates dataset prep for AI agents

https://getvesper.dev/
2•sultanchek•16m ago•0 comments

Quirkatar – Zero-dependency avatar generator with 34M+ combinations

https://github.com/Nitty-Gritty-Design/quirkatarfor
1•NGDesign•16m ago•1 comments

Sandboxed Trivy GitHub Action

https://github.com/lhotari/sandboxed-trivy-action
1•flarecoder•16m ago•1 comments

Show HN: Glanceway – A programmable menu bar info aggregator for macOS

https://glanceway.app
1•codytseng•17m ago•0 comments