Comment Who's fault again? (Score 3, Insightful) 116
In Andrew's situation, he had not asked his AI agent to hack into his gym's booking system.
Sure he did.
Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.
Bruh, come on. You're smart enough to be trying "bleeding edge" tech such as an open source orchestration app like openclaw using, presumably, a local LLM to power it but you're gonna play dumb when you ask that very tech whether "it's possible" to move you to the top of waiting list that you already KNOW you're not supposed to be able (or even attempting to) do??
LOL...no, this wasn't an "unintentional" hack. This was some guy asking an AI agent with autonomy (that he gave it to do stuff) to, you know, go do stuff. How is it going to answer his question without testing the endpoints to find out if it's possible or not?
How crippled do we have to make these models that, in the right hands, do LOTS of REALLY powerful things for us in order to keep morons in check? Clearly a lot more than we're doing today I guess. And that irks me a bit but I see why more and more guardrails are needed here. I'm also gaining a new appreciation for the level of "ITSec" going around now...you can't fix stupid, but if you box it in (along with everyone else) tight enough maybe you can at least contain the damage sometimes. Just put the power button to everyone's devices behind a ticket support system and be done with it. The only "tRulY SeCUre" system will be one that doesn't power up or store any data. There...that'll fix it.