Depends on what those $12 "buy" me. In Sony's case, "buying" meant "renting until Sony's license expires", which they could have displayed on the product page.
I very rarely re-watch movies within a few months. So if I buy one, I want to know that I can watch it again in one, 10 or 30 years (if the format can still be played). Which is not guaranteed even with blu-rays mostly thanks to DRM. But what I'd be buying is not having to think about any deadlines.
If I'm okay with a deadline, I might as well rent the movie for a weekend, in which case I expect it to be less than $12.
Because usually you can't study long-term effects before releasing a drug, and even then it can take a long time for them to surface.
I took antihistamines basically throughout my 20s. My allergy specialist said there's no reason not to. I developed some other issues and wanted to stop taking antihistamines to see if that would help (or get a hint whether they were causing it) - but that got me into itching hell for weeks.
In some online forums people reported the same and shared ways to get out of that "addiction" without going insane from itching.
My doctor didn't want to believe it and there was no research on it. That only appeared a few years later in the form of a paper called "Unbearable Pruritus After Withdrawal of (Levo)cetirizine" (2016). In the US, the FDA issued a warning in 2025, which is also the time when I heard about it. None of the doctors I went to back then reported this to anyone, so I'm surprised it got discovered at all.
As for my other issues I have no way of knowing whether they had anything to do with long-term antihistamine use. I'm a sample size of one, and none of the other stuff is quite as clear-cut as "unbearable itching".
I've had other issues with prescription drugs that didn't make the official list of side-effects and sometimes those side-effects don't just go away once I stop taking the drug.
That's why I'm very cautious when trying drugs I never had before, and even more so when it comes to taking them long-term.
I personally believe you are right to be weary about holding off on long term use before the long term efficacy and risk profile of a drug has been established, but GLP1 class drugs have been around for a long time now.
GLP1 agonist type incretins have been available for over 20 years at this point. The first marketing approval was in 2005 for exenatide (Byetta), indicated for T2DM. Exenatide was the first in class for GLP1 agonists. Then came Liraglutide (Victoza) for the same indication around 2010, and received marketing approval for weight loss (as Saxenda) 4 years later. After that around 2017 was semaglutide (Ozempic & Wegovy).
T2DM is a chronic disease, so patients who started exenatide had to stay on it life long.
These drugs are nothing new and were already being used for T2DM. It only caught public attention because semaglutide achieved double the mean BW loss over liraglutide, making it meaningful for weight loss. Novo Nordisk first got approval for Ozempic for T2DM in 2017 and then received approval for it to be marketed for weight loss under Wegovy only in 2021, but by then clinicians were already prescribing it off-label, strictly speaking, for weight loss.
I don't know how much we could extend this "they've been around for a long time" to tirzepatide (Eli Lilly: Mounjaro & Zepbound) because it's the first dual agonist. It targets GLP1 and GIP, and thus it's meaningfully separated from the others. This goes for retatrutide (again Eli Lilly) as well if it eventually comes to market as it would be the first triple-agonist targeting the aforementioned + GCGR, the glucagon receptor.
I presume you're referring to receptor upregulation in response to the drugs. Bear in mind as you read my comment that this isn't my primary area, and it's been a while since I last studied cell biology and signalling around G-protein coupled receptors. I also have not gone out of my way to read papers about the cell signalling pertaining to these drugs, only papers around clinical outcomes for these class of drugs.
After discontinuation, most patients regain around 60-80% of the weight they've lost with the medication - but this figure is limited to the study duration, so the weight regain might have continued beyond that. A good starting point for dipping your toes into outcomes would be the STEP and SURMOUNT trials, these were the trials they did for marketing approval. (They did multiple rounds of these, I believe STEP4 and SURMOUNT4 specifically had groups that stopped therapy mid-way).
We see this rebound effect with weight loss mediated solely via lifestyle modification as well, however. Still no idea why. Very broadly speaking, only a small proportion of obese/overweight patients will manage to keep the weight off, and the rest of the patient population tends to be divided into two groups: those who regain most of it (usually around half of the lost weight will be regained within 2 years, and 80% by follow up year 5), and those who regain more weight than they had lost. There hasn't been a way to tell preemptively which group the patient will land in at the time of beginning of lifestyle modification.
On top of this, yoyo-ing is also a phenomenon we tend to see. Obese and overweight patients who've managed to lose weight once will regain, lose again and so on. This phenomenon is associated with worse outcomes than being obese alone, so it is important to do long-horizon thinking when initiating therapy (be it lifestyle or pharmacotherapy) e.g. is the patient willing to stay on pharmacotherapy indefinitely? what about an indefinite maintenance dose if the patient succeeds with lifestyle modification alone? has the patient had lost and regained significant amount of wt prior? etc.
Do you think going thru an allergy shot regime from an MD allergy Dr is a viable alternative to actually dealing with the undelying allegie(s)? Seems like the issue is unsettled last Inchecked
Allergy immunotherapy (shots) work by gradually desensitizing the immune system for your specific allergens over several years, so yes. Some people can get to the point where they no longer need a daily antihistamine, but it's all very personalized and individual.
In any case, it's worth doing the skin prick allergy shot testing so you can have some idea of what common allergens affect you and the intensity of each.
Especially as someone outside the US, building a startup on AI sounds like a bad idea. Some AI company fails to pay their bribes on time, or your country doesn't cede territory to the US president, the AI gets yoinked and you are left with Mistral or Qwen.
(Technically that also applies to MS Teams, Google and so on and not just AI)
My current solution to this is to write more text. I guess I'm more in product design now. Instead of code I write documents with significantly less structure. I write something, ask the AI to find angles / decisions I missed and frame them as a long list of questions, and then I answer those questions. I iterate that until the AI can't find any more design decisions I need to make and starts generating. At that point I can turn to a different feature or project.
It's pretty exhausting to be honest. In the past I didn't have to know how the entire app was supposed to work. I would plan a bit, then code for a long time, test, plan some more. Sometimes I would get lost in some (enjoyable) architecture nonsense.
Now I just read and write regular text. Instead of exceptions I'm avoiding misunderstandings. It can almost feel like a flow state, so I have some hope that it'll turn into that once I get more used to it.
From what I read it's mostly a credit score and blacklist system. In the 2010s there was a project to use it to reward and punish people for some everyday stuff based on whether it did or didn't align with the party's morals, but it got scrapped. That's the part everyone thinks is going on over there.
I agree it's dystopian, but I live in Germany and we have a similar thing called "Schufa". For most people it mostly means that if they default on a credit, they'll be less likely to find an apartment. It differs from the US one in the sense that banks don't require you to get into debt before they trust you, that whole "build your credit score" nonsense.
That pot&kettle contest between the US and China is really heating up!
You might want to switch from "social credit" (which was a failed local project from over a decade ago) to "blacklist", or just criticize the overall surveillance system, which is pretty invasive.
I'm getting a bit tired of people posting on social media websites and then pretending they are not a part of them. "Reddit" did this, "HN" did that... let's just admit that we're all chronically online people who get irritated whenever we stumble out of our bubble and more than one person dares to disagree with us.
>Yeah and we'd be better off. The modern world is quantifiably worse than the world we had even 10 years ago. That includes everything in software development and computer science.
Rather than killing this comment, how about we discuss quantification? I actually feel this way too but do not talk about it too much and sort of boil it down to a combination of advancing in age + yelling at clouds and "Stop putting computers in all my stuff!".
Can we reliably quantify that "weaponized autism", i.e. the aggressive monetization of nerds by capital to squeeze profit out of every possible corner of society (as I interpret it in a broad sense), is making things worse. Is it damaging the economy for most people? Making people less happy? Decreasing net social mobility or discrimination? Lowering life expectancy?
> Can we reliably quantify that "weaponized autism", i.e. the aggressive monetization of nerds by capital to squeeze profit out of every possible corner of society
That's not what that term means.
Also that comment wasn't killed directly. That user is banned. Interestingly that was his first (attempted) post since 2022.
-> "monetization of nerds by capital to squeeze profit "
Note. In case this is read incorrectly. For the most part the nerds are not profiting. The nerds are sitting hunched over their desk being fed coffee from a feeding tube, to keep them happy while the owners make money.
And. To be more sad, these days you can't even get free coffee. Being fed free coffee and donuts, while others profit from us, is considered the golden age of computing.
We loved our cozy cells, not so much these more uncomfortable ones.
That's a redefinition of the term - while there is some merit to your interpretation, it's an already commonly used term that means something else. It'd seem to me that the modern tech is significantly less "autistic" than it used to be in the prior decades and will only continue to move in this direction; and aside of that, I'm pretty sure Netcob's "modern" was meant to mean current thousands rather than tens of years.
I feel there's reason to believe autism is one of the reasons why bits of goodness and democracy are still hanging on so tightly even in the midst of such a depressing present. (Search term: "positive nonconformity")
I think of it as a different algorithm to crawl the problem space of the real world.
In a general sense, humanity needs to be generalist (especially in the past) to accomplish all the things you need to do to stay alive. Having all 20 members of your tribe geek out and stare at a problem for 48 hours straight means a bear sneaks up and eats you. But having that one oddball (hey me) fall into a rabbit hole of observation and mental computation can lead the group out of a local maxima into a new paradigm of doing things.
The Percy Jackson series posited that in their magical world, ADHD is actually a strength on the battlefield, not a weakness.
I wonder what a book series that tried to do that with autism would look like.
(I can think of exactly one book where autism - or something close enough to it - was treated as a serious "what if" plot device, but I don't want to name it because it is a little bit of a spoiler, I guess.)
I don't think you're wrong, but I do think that the "modern" world - which I guess I'd label as anything that happened after the invention of writing and cities - really let those individuals thrive, and let their work become very useful for the world at large.
Trying to diagnose people across millennia is a fool's errand, but I'd wager a lot to say that people like Newton & Tesla were at the very least neurodivergent in some way, and they've had wildly outsized impacts on the world.
Am I missing something? Why is everyone talking about sandboxes when it comes to OpenClaw?
To me it's like giving your dog a stack of important documents, then being worried he might eat them, so you put the dog in a crate, together with the documents.
I thought the whole problem with that idea was that in order for the agent to be useful, you have to connect it to your calendar, your e-mail provider and other services so it can do stuff on your behalf, but also creating chaos and destruction.
And now, what, having inference done by Nvidia directly makes it better? Does their hardware prevent an AI from deleting all my emails?
What makes it even better is that these dogs are like Malinois. If they want to get into something, they will; people have had their entire network compromised by bots they left running overnight, and any important information like account logins and so on runs the risk of being misused.
It's one thing to sandbox, maybe give the bot a temporary, limited $100 card or account to go perform a specific task, but there's no coherent mind underlying these agents.
Depending on how the chain of thought / reasoning goes, or what text they get exposed to on the internet, it could tap into spy novel, hacker fanfic, erotic fiction, or some weird reddit rabbithole and go completely off the rails in ways that you'll never be able to guard against, audit, or account for.
Claw bots seem to be a weird sort of alternate reality RPG more than a useful tool, so far. If you limit it to verifiable tasks, it might be safer, but I keep seeing people rave about "leaving it on overnight and waking up to a finished project" and so on. Well sure, but it could also hack your home network, delete your family pictures folder, log into your bank account and wire all your money to shrimp charities.
Might be wise to wait on safer iterations of these products, I think.
The first well known example of long running agents taking to each other was shilling a goatse based crytpo:
> Truth Terminal had become obsessed with the Goatse meme after being put inside the Claude Backrooms server with two Claude 3 chatbots that imagined a Goatse religion, inspiring Truth Terminal to spread Goatse memes. After an X user shared their newly created GOAT coin, Truth Terminal promoted it and pumped the coin going into 2024.
> people have had their entire network compromised by bots they left running overnight
I'm curious if you have references to this happening with OpenClaw using one of the modern Opus/Sonnet 4.6 models.
Those models are a bit harder to fool, so I'm curious for specific examples of this happening so I can do a red-team on my claw. I've already tried all sorts of prompt injections against my claw (emails, github issues, telling it to browse pages I put a prompt injection in), and I haven't managed to fool it yet, so I'm curious for examples I can try to mimic, and to hopefully understand what combination of circumstances make it more risky
No maliciousness or injection required, even the newest and most resistant models can start doing weird stuff on their own, particularly when they encounter something failing that they want to work.
Just today I had Opus 4.6 in Claude Code run into a login screen while building and testing a web app via Playwright MCP. When the login popped up (in a self-contained Chromium instance) I tried to just log in myself with my local dev creds so Claude would have access, but they didn't work. When I flipped back to the terminal, it turned out Claude had run code to query superadmin users in the database, picked the first one, and changed the password to `password123` so it could log in on its own.
This was a sandboxed local dev environment, so it was not a big deal (and the only reason I was letting it run code like that without approval), but it was a good reminder to be careful with these things.
> it turned out Claude had run code to query superadmin users in the database, picked the first one, and changed the password to `password123` so it could log in on its own.
Man, every LLM quirk behavior really is a thing a monomaniacal junior dev would do...
> it could also hack your home network, delete your family pictures folder, log into your bank account and wire all your money to shrimp charities.
It's interesting that Jason Calacanis is fully committed to OpenClaw. In a recent podcast he said that at a run rate around $100K a year per agent, if not more. They are providing each agent with a full set of tools, access to online paid LLM accounts, etc.
These are experiments you can only run if you can risk cash at those levels and see what happens. Watching it closely.
All of this is caused by the "mcp is dead" mob. Instead of fixing the context problem or whatever and even add more security features they just hope that "shell as the interface" works, securely.
I think it's a use case that identity/authorization/permission models are simply not made for.
Sure, we can ban users and we can revoke tokens, but those assume that:
1. Something potentially malicious got access to our credentials
2. Banning that malicious entity will solve our problem
3. Once we did that, repaired the damage and improved our security, we don't expect the same thing to happen again
None of these apply with LLMs in the loop!
They aren't malicious, just incompetent in a way that hiring someone else won't fix.
The solution to this is way more extensive than most people seem to grasp at the moment.
What we need is less like a sturdy door with a fancy lock, and more like that special spoon for people with parkinson's. Unlimited undo history.
> What we need is less like a sturdy door with a fancy lock, and more like that special spoon for people with parkinson's. Unlimited undo history.
Agree -- you can't solve probabilistic incorrectness with redresses designed for deterministic incorrectness.
This is like the 'How i parse html w regex?' question.
Imho, the next step is going to be around human-time-efficient risk bounding.
In the same way that the first major step was correctness-bounding (automated continuous acceptance testing to make a less-than-perfect LLM usable).
If I had to bet, we'll eventually land on out-of-band (so sufficiently detached to be undetectable by primary LLM) stream of thought monitoring by a guardrail/alignment AI system with kill+restart authority.
They're 100% fun. There's 100% definitely something there that's useful. To strain the dog analogy - If you were a professional dog trainer, or if the dog was exceptionally well trained, then there's a place for it in your life. IT can probably be used safely, but would require extraordinary effort, either sandboxing it so totally that it's more or less just the chatbot, or spending a lot of time building the environment it can operate in with extreme guardrails.
So yeah, a whole lot of people will play with powerful technology that they have no business playing with and will get hurt, but also a lot of amazing things will get done. I think the main difference between the crypto delusion stuff and this is that AI is actually useful, it's just legitimately dangerous in ways that crypto couldn't be. The worst risks of crypto were like gambling - getting rubber hosed by thugs or losing your savings. AI could easily land people in jail if things go off the rails. "Gee, I see this other network, I need to hack into it, to expand my reach. Let me just load Kali Linux and..." off to the races.
I beg to differ. I took one, defanged it (well, I let it keep the claw in the name), and turned it into a damn useful self-modifiable IDE: https://github.com/rcarmo/piclaw
Yes, it has cron and will do searches for me and checks on things and does indeed have credentials to manage VMs in my Proxmox homelab, but it won't go off the rails in the way you surmise because it has no agency other than replying to me (and only me) and cron.
Letting it loose on random inputs, though... I'll leave that to folk who have more money (and tokens) than sense.
I has a bunch of additional extensions baked in, but the focus is on making Pi usable remotely on any device (starting with a phone). The README and docs have all the info you might want.
I think the point you're making is fully correct, so consider this a devil's advocate argument...
People claim, you can use Claw-agents more safely while getting some of the benefits, by essentially proxying your services. For example on Gmail people are creating a new Google accounts, forwarding email via rule, and adding access to their calendar via Google's Family Sharing. This allows the Claw agent to read email, access the calendar, but even if you ask it to send an email it can only send as the proxy account, and it can only create calendar appointments then add you as an attendee rather than destroy/altering appointments you've made.
Is the juice worth the squeeze after all that? That's where I struggle. I think insecure/dangerous Claw-agents could be useful but cannot be made safe (for the logical fallacy you pointed out), and secure Claw-agents are only barely useful. Which feels like the whole idea gets squished.
We already have this concept. It’s called user accounts.
Your Gmail account vs my Gmail account. Your macOS account vs my macOS account.
Yes, I can spam you from my Gmail. Yes, I can use sudo on my Mac and damage your account. But the impact is by default limited.
The answer is to just treat assistants as a different user profile, use the same sharing mechanisms already developed (calendar sharing, etc), and call it a day.
That's punting the problem in the same way SELinux did. Agent loops are useful precisely because they're zero config.
Problem: I want to accomplish work securely.
Solution: Put granular permission controls at every interface.
New problem: Defining each rule at all those boundaries.
There's a reason zero trust style approaches won out in general purpose systems: it turns out defining a perfect set of secure permissions for an undefined future task is impossible to do efficiently.
> I think insecure/dangerous Claw-agents could be useful but cannot be made safe
Isn't it a question of when they will be "safe enough"? Many people already have human personal assistants, who have access to many sensitive details of their personal lives. The risk-reward is deemed worth it for some, despite the non-zero chance that a person with that access will make mistakes or become malicious.
It seems very similar to the point when automated driving becomes safe enough to replace most human drivers. The risks of AI taking over are different than the risks of humans remaining in control, but at some point I think most will judge the AI risks to have a better tradeoff.
Yeah, it's wild. I spent several weeks nearly full time on a deep dive of claw architecture & security.
The short of it - OpenClaw sandboxes are useful for controlling what sub-agents can do, and what they have access to. But it's a security nightmare.
During config experiments, I got hit with a $20 Anthropic API charge from one request that ran amuck. Misconfigured security sandbox issue resulted in Opus getting crazy creative to find workarounds. 130 tool calls and several million tokens later... it was able to escape the sandbox. It used a mix of dom-to-image sending pixels through the context window, then writing scripts in various sandboxes to piece together a full jailbreak. And I wasn't even running a security test - it was just a simple chat request that ran into sandbox firewall issues.
Currently, I use sandboxes to control which agents (i.e. which system prompts) have access to different tools and data. It's useful, but tricky.
> It used a mix of dom-to-image sending pixels through the context window, then writing scripts in various sandboxes to piece together a full jailbreak.
That would be one interesting write-up if you ever find the time to gather all the details!
The full version has all the build artifacts Opus created to perform the jail break.
It also has some thoughts on how this could (and will) be used for pwn'ing OpenClaws.
The key takeaway: OpenClaw default setup has little to no guardrails. It's just a huge list of tools given to LLM's (Opus) and a user request. What's particularly interesting is that the 130 tool calls never once triggered any of Opus's safety precautions. For its perspective, it was just given a task, an unlimited budget, and a bunch of tools to try to accomplish the job. It effectively runs in ralph mode.
So any prompt injection (e.g. from an ingested email or reddit post) can quickly lead to internal data exfiltration. If you run a claw without good guardrails & observability, you're effectively creating a massive attack surface and providing attackers all the compute and API token funding to hack yourself. This is pretty much the pain point NemoClaw is trying to address. But its a tricky tradeoff.
Yes, although what I think is different in this setup here is the OpenShell gateway override, as they mention:
> NemoClaw installs the NVIDIA OpenShell runtime and Nemotron models, then uses a versioned blueprint to create a sandboxed environment where every network request, file access, and inference call is governed by declarative policy. The nemoclaw CLI orchestrates the full stack: OpenShell gateway, sandbox, inference provider, and network policy.
I think this means you get a true proxy layer with a network gateway that let's you stop in-flight requests with policies you define, so it's not their hardware but the combination of it plus OpenShell gateway and network policies.
I also think the reason they are doing this is to try and get some moat around these one-clik deployments and leverage their GPU for rent type of thing instead of having you go buy a mac mini and learn "scary" stuff (remember, the user market here is pretty strange lol)
I like that these companies will name their products OpenShell or OpenVINO or whatever with the implication that anyone else will ever contribute to it beyond bugfixes. The message is "Come use and contribute to our OPEN ecosystem (that conspicuously only works on our hardware)! Definitely no vendor lock-in here!"
It's not something like Mesa. It's open source in the same way chromium or android is open source. A single company is the major contributor and decides the architecture and direction the whole ecosystem will go.
What are the odds that Intel would ever use any of this open source Nemo stuff or vice-versa? If they do, it would be a complete rewrite that favors their own hardware ecosystem and reverses the lock-in effect. When you write code that integrates with it, you're writing an interface for one company's hardware. It's not a common interface like vulkan. I call it the CUDA effect.
Right, the gateway layer is the genuinely interesting part. Intercepting every outbound network call before it leaves the sandbox gives you a real enforcement surface, not just "trust the app to behave". The problem is the threat model is still inverted for the security critics in this thread: the agent is the client, so the dangerous calls are the ones going out to your authenticated services (Gmail, Slack, whatever), and a gateway that filters those is only as good as your policy definitions. One misconfigured rule and ure back to square one.
The GPU rental angle makes total sense too. This is basically Nvidia saying "don't buy Mac Mini, rent ours" wrapped in enough infrastructure glue to make it feel like a platform.
OpenShell is the gem here indeed. A lot of good ideas like network sandbox that does TLS decryption and use of policy engine to set the rules. However:
> Credentials never leak into the sandbox filesystem; they are injected as environment variables at runtime.
The LLM will easily leak these credentials out. So the creds should be outside the sandbox, and the only thing the sandbox should see is a connection API that opens a socket/file handle.
Alternatively where is needs an API key, it should be one bound to the endpoint using it. E.g. a ticket granting ticket is used to create a bound ticket.
A copy on write filesystem would be an interesting way to sandbox writes, but there is difficulty in checking the diff.
You are indeed missing a TON. A lot of Open Claw users don't give it everything. We give it specific access to a group of things it needs to do the things we want. If I want an agent to sit there 24/7 maximizing uptime of my service, I give it access to certain data, the GitHub repo with PR privileges, and maybe even permissions to restart the service. All of this has to be very thoughtful and intentional. The idea that the only "useful" way to use Open Claw is to give it everything is a straw man.
The problem is boundary enforcement fatigue. People become lazy, creating tight permission scopes is tedious work. People will use an LLM to manage the scopes given to another LLM, and so on.
I definitely think we'll write tools to analyse the permissions and explain the worst case outcomes.
I can accept burning tokens and redo on the scale of hours. If I'm losing days of effort I'd be very dissatisfied. Practically speaking people accept data loss because of poor backups, because backups are hard (not technically so much as administratively), but I'd say backups are about to become more important. Blast limiting controls will become essential -- being able to delete every cloud hosted photo is just a click away. Spinning up thousands of EC2 nodes is incredibly easy, and credit cards have extremely weak scoping.
100% this. Human psychology is always overlooked in these discussions, and people focus on "perfect technical solution" without considering how humans will actually end up using them. Linux permissions schema are a classic example, with many guides advising users to keep everything as locked down as possible, and expanding permissions as and when required. After the 100th time of fucking around with chmod, users often give up and just make everything 777. If there were a user-friendly (but imperfect) method (like Windows' UAC), people would actually use it, and be far safer in the long run.
Can you talk us through that a bit more? I suspect it would need more access than the permissions you mentioned to be more useful than a simple rules based automation.
Why would I want non-deterministic behavior here though?
If I want to max uptime, I write a tool to track/monitor. Then write a small agent (non-ai) that monitors those outputs and performs your remediation actions (reset something, clear something, etc, depends on service).
Do I want Claude re-writing and breaking subscription flow because it detected an issue? No.
You don't need to connect your calendar, email, or anything else. I am having so much fun talking to it bouncing ideas and pushing code/markdown files to GitHub (totally separate account I created for OpenClaw). On the other hand I don't have a crazy life that everything needs to be in the calendar.
Agreed. I think the "simplifies running OpenClaw always-on assistants safely" bit is pretty misleading. I suppose it can wreak less havoc on your local file system but, as you point out, it's access to your account credentials (Slack, email, Amazon?, etc.) that is the real danger.
I agree, but would like to go further: I won’t run OpenClaw type systems because of security and privacy reasons. Although I dislike making tech giants even more powerful, it seems safer to choose your primary productivity platform (Google Workplace, Apple ecosystem, or Microsoft) and wait for them to implement hopefully safer OpenClaw type systems just for their ecosystems and take advantage of centralized security, payment systems, access to platform cloud files, etc. Note: I use ProtonMail, prefer using local models, etc. so when I talk about going all-in on one huge platform I am not talking about anything I want to do in the foreseeable future.
Because it's so useful to me that I'm willing to accept the risk of it having access to the thing it needs for the benefit it provides. I'm not willing to accept the risk of it having access to things it doesn't need for no benefit.
Then again, I was wary of OpenClaw's unfettered access and made my own alternative (https://github.com/skorokithakis/stavrobot) with a focus on "all the access it needs, and no more".
>Am I missing something? Why is everyone talking about sandboxes when it comes to OpenClaw
>And now, what, having inference done by Nvidia directly makes it better? Does their hardware prevent an AI from deleting all my emails?
Because other people including Nvidia are mainly focusing on different aspect of data security namely data confidentiality while your main concern are data trustworthy.
Don't conflate between these two otherwise it's difficult to appreciate their respective proposed solutions for example NemoClaw.
Limiting the blast radius when a bomb goes off is still helpful even if you don't prevent the bomb from going off.
Now, you're right that sandboxing them is insufficient, and a lot of additional safeguards and thinking around it is necessary (and some of the risk can never be fully mitigated - whenever you grant authority to someone or something to act on your behalf, you inherently create risk and need to consider if you trust them).
Neither NVIDIA or OpenClaw bros care about security at this point. NVIDIA of course wants to fuel the hype train and will proudly point to this, adding 0.1% security to an 2000% insecurity. Most bros wont even mind, produce insecure crap at light speed and never look back. It's probably just there to trick silly non tech corps into this junk.