• 0 Posts
  • 47 Comments
Joined 2 months ago
cake
Cake day: January 9th, 2026

help-circle


  • per the article: “OpenClaw as installed could read credentials from ~/.openclaw/, execute shell commands via its Gateway API, and install itself as a persistent system daemon surviving reboots1. The severity was debated - Endor Labs characterised the payload as closer to a proof-of-concept than a weaponised attack5 - but the mechanism is what matters. The next payload will not be a proof-of-concept.”

    I’m not a technical fella, but while this case didn’t seem to do much for the attacker, I’d guess that the openclaw could be instructed after install as part of the same postinstall routine, or it could be triggered at a later date to do something via some form of prompt injection… either way the point would seem to be the application of a new attack mechanic.











  • GMac@feddit.orgtoBuyFromEU@feddit.orgAndroid Keyboard
    link
    fedilink
    English
    arrow-up
    2
    ·
    29 days ago

    I’m probably paranoid but I don’t trust google apps to not be reporting usage back via play services even if internet access is disabled for the individual keyboard application. If you don’t have play services then no problem … but bank apps 🙄 🙁


  • You are free to disagree but as a man who wants to be considerate and respectful to all people, this is my take on your comment.

    Assuming fake and appreciating anything that doesn’t contravene your own boundaries is vastly insufficient. The creation process is irrelevant. The objectification and accompanying dehumanisation is the problem.

    That woman was denied agency in a manner that any and all right thinking men should be denouncing as being outside their boundaries, regardless of whether you have ever encountered the person in the images… If you aren’t objecting, you’re complicit as a member of the audience.