0:00 Music 0:07 So what are we going to have a look at? 0:09 It's like OpenClaw, and it's something that I already mentioned to some of you, but in reality, OpenClaw did a couple of things. 0:19 First, it made something that was actually available in 2023 with NA10 and some smart automation in 2023. 0:29 So it's no revolution and nothing too like normal in terms of software engineering for the most of the software engineering community. 0:40 It is some smart and conventional choices in memory architecture, which have proved to be pretty great. 0:48 And it's not easy to achieve with an ATM. 0:50 But otherwise, it's basically just the AI agents in a loop, similar to what we 0:57 saw together in the previous slide in the morning, that repeatedly does all the same thing, following the mission that you put into it, inspired by the soul that you put into it. 1:09 So OpenClaw is the absolute GitHub number one repository. 1:15 GitHub is like Instagram for engineers. 1:18 So some posts pictures, images, and videos, and reels. 1:23 Engineers post their code, share with each other, and they do it on GitHub. 1:28 So 150,000. 1:30 and are stars at GitHub in 70 hours is mind-blowing because it's more than Linux, more than like operating system, more than major Google Docker container orchestration systems. 1:43 It's an absolutely mind-blowing, unprecedented scale for... 1:50 Anything in software world. 1:52 So it like really blew the minds of the whole world in software. 2:00 But at the same time, what happened, it's a security disaster for many cases, because the author of OpenClaw had guts to put out in the wild for consuming by 2:14 basically anyone, dangerous technology that's untethered. 2:20 So our default setup basically exposes your control of your workstation, your microphone, camera, like Windows browser, files, passwords, credit cards, personal private photos. 2:34 Anything that you can find in your computer, on your phone, like everywhere. 2:39 It's an absolute security disaster. 2:41 They try hard to put some guardrails on it since the beginning, obviously. 2:47 But because the concept of EI architecture and agentic EI in particular is new, 2:55 There are no good methodologies that work in 100% of the time. 3:00 It happens for pretty obvious reasons. 3:07 There is this concept, again, known more to software engineers, which is called the legal trifecta. 3:13 And it means the combination of three things coming together. 3:17 So whenever a tool has access to execute anything, basically to execute actions, commands, send data, whenever it has any inputs from untrusted sources, 3:31 like emails, messages, texts, web pages, like anything that gets into the inbox of the system. 3:41 And whenever this system has access to read files or access to any sensitive information, it's a recipe for disaster. 3:50 So you... 3:52 If you move away even one aspect out of this, the security becomes manageable. 3:58 If you leave just all three, even trying to make them manageable, it's total out of control. 4:07 Right now, there is no solution to solve this. 4:11 It's kind of what, even without all vulnerabilities, 4:18 there is on the right that are known to exist in OpenClaw, even if in theory anyone would go ahead and harden the security of OpenClaw by closing all 4:30 known possible security holes in its system implementation. 4:36 This is a major issue that's not easy to solve. 4:40 And there is no good way to make it reliable unless you put it in a jail, in a sandbox. 4:50 And you actually eliminate one of these inputs. 4:55 So in our case, what we'll do, we'll not give it any access to anything sensitive. 5:02 So we'll give it a sandbox to execute actions, to run commands, to do some anything it wants. 5:10 You can even play around with skills. 5:12 You can send your open cloud to Moldbook or like anywhere else to play around with those AI agents. 5:21 And it will receive any inputs. 5:23 But because it will be isolated in a sandbox environment, there is no way that it can do. 5:31 Any significant harm other than swear or whine to other agents about, you know, how annoying their cost is. 5:41 They're not letting them access to anything interesting and then limiting within a confined jail or water space.
0:00 Music 0:07 So what are we going to have a look at? 0:09 It's like OpenClaw, and it's something that I already mentioned to some of you, but in reality, OpenClaw did a couple of things. 0:19 First, it made something that was actually available in 2023 with NA10 and some smart automation in 2023. 0:29 So it's no revolution and nothing too like normal in terms of software engineering for the most of the software engineering community. 0:40 It is some smart and conventional choices in memory architecture, which have proved to be pretty great. 0:48 And it's not easy to achieve with an ATM. 0:50 But otherwise, it's basically just the AI agents in a loop, similar to what we 0:57 saw together in the previous slide in the morning, that repeatedly does all the same thing, following the mission that you put into it, inspired by the soul that you put into it. 1:09 So OpenClaw is the absolute GitHub number one repository. 1:15 GitHub is like Instagram for engineers. 1:18 So some posts pictures, images, and videos, and reels. 1:23 Engineers post their code, share with each other, and they do it on GitHub. 1:28 So 150,000. 1:30 and are stars at GitHub in 70 hours is mind-blowing because it's more than Linux, more than like operating system, more than major Google Docker container orchestration systems. 1:43 It's an absolutely mind-blowing, unprecedented scale for... 1:50 Anything in software world. 1:52 So it like really blew the minds of the whole world in software. 2:00 But at the same time, what happened, it's a security disaster for many cases, because the author of OpenClaw had guts to put out in the wild for consuming by 2:14 basically anyone, dangerous technology that's untethered. 2:20 So our default setup basically exposes your control of your workstation, your microphone, camera, like Windows browser, files, passwords, credit cards, personal private photos. 2:34 Anything that you can find in your computer, on your phone, like everywhere. 2:39 It's an absolute security disaster. 2:41 They try hard to put some guardrails on it since the beginning, obviously. 2:47 But because the concept of EI architecture and agentic EI in particular is new, 2:55 There are no good methodologies that work in 100% of the time. 3:00 It happens for pretty obvious reasons. 3:07 There is this concept, again, known more to software engineers, which is called the legal trifecta. 3:13 And it means the combination of three things coming together. 3:17 So whenever a tool has access to execute anything, basically to execute actions, commands, send data, whenever it has any inputs from untrusted sources, 3:31 like emails, messages, texts, web pages, like anything that gets into the inbox of the system. 3:41 And whenever this system has access to read files or access to any sensitive information, it's a recipe for disaster. 3:50 So you... 3:52 If you move away even one aspect out of this, the security becomes manageable. 3:58 If you leave just all three, even trying to make them manageable, it's total out of control. 4:07 Right now, there is no solution to solve this. 4:11 It's kind of what, even without all vulnerabilities, 4:18 there is on the right that are known to exist in OpenClaw, even if in theory anyone would go ahead and harden the security of OpenClaw by closing all 4:30 known possible security holes in its system implementation. 4:36 This is a major issue that's not easy to solve. 4:40 And there is no good way to make it reliable unless you put it in a jail, in a sandbox. 4:50 And you actually eliminate one of these inputs. 4:55 So in our case, what we'll do, we'll not give it any access to anything sensitive. 5:02 So we'll give it a sandbox to execute actions, to run commands, to do some anything it wants. 5:10 You can even play around with skills. 5:12 You can send your open cloud to Moldbook or like anywhere else to play around with those AI agents. 5:21 And it will receive any inputs. 5:23 But because it will be isolated in a sandbox environment, there is no way that it can do. 5:31 Any significant harm other than swear or whine to other agents about, you know, how annoying their cost is. 5:41 They're not letting them access to anything interesting and then limiting within a confined jail or water space.