HNHacker News
TopNewBestAskShowJobs

steipete

1,290 karma · joined June 28, 2010

[ my public key: https://keybase.io/steipete; my proof: https://keybase.io/steipete/sigs/thxAWG74LlxCDGsHPbO-ESZG2kDBDFOB4mw94ZeK5pk ]
submissionscomments
steipete··on Anthropic says OpenClaw-style Claude CLI usage is allowed again
Peter here from OpenClaw. For context, here’s why our post reads the way it does:

Boris from Claude Code said publicly on Twitter that CLI-style usage is allowed. We took that seriously and invested time building around that guidance. I even changed the defaults, so when using the cli we're automatially disabling features that use excessive tokens like the heartbeat feature. But in practice, Anthropic still blocks parts of our system prompt, so the actual behavior today does not match what was communicated publicly.

https://x.com/bcherny/status/2041035127430754686

They since seemed to changed their classifier as people hack around it, as it is trivial to do so with a few renames. I'm not playing that game so it's in a weird limbo where it should work in theory but doesn't in practice.

steipete··on OpenClaw privilege escalation vulnerability
ofc it's software engineers.
steipete··on OpenClaw privilege escalation vulnerability
Honestly that seems like total guesswork. There's a lot of FUD going around, or people running portscans and assuming just because they detect a gateway on a port, that they can connect to it. That’s not the case.
steipete··on OpenClaw privilege escalation vulnerability
They both sponsor the OpenClaw Foundation and provide engineers to improve OpenClaw.
steipete··on OpenClaw privilege escalation vulnerability
OpenClaw creator here.

This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance."

The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerScopes`, and the core logic failed open when that parameter was missing.

So the strongest confirmed exploit path was: a client that ALREADY HAD GATEWAY ACCESS and enough permission to send commands could use `chat.send` with `/pair approve latest` to approve a pending device request asking for broader scopes, including `operator.admin`. In other words: a scope-ceiling bypass from pairing/write-level access to admin.

This was not primarily a Telegram-specific or message-provider-specific bug. The bug lived in the shared plugin command handler, so any already-authorized command sender that could reach `/pair approve` could hit it. For Telegram specifically, the default DM policy blocks unknown outsiders before command execution, so this was not "message the bot once and get admin." But an already-authorized Telegram sender could still reach the vulnerable path.

The practical risk for this was very low, especially if OpenClaw is used as single-user personal assistant. We're working hard to harden the codebase with folks from Nvidia, ByteDance, Tencent and OpenAI.

steipete··on I’m joining OpenAI
Mario has a special place in the Clawtributor list.

https://github.com/openclaw/openclaw#community

steipete··on Cowork: Claude Code for the rest of your work
Funny timing. Written in 10 days just when this took off. https://clawd.bot/
steipete··on Just talk to it – A way of agentic engineering
Marketing for what? I didn't even link to what I'm building because I wanna ship it when it's ready.
steipete··on Just talk to it – A way of agentic engineering
(OP) You know if I link to a half-finished project, people would take it apart as many don't understand the nuance between crap and simply not done yet. But if you follow me on twitter it'll take you a few minutes to figure out. I'm two months in, even with AI, shipping good stuff takes time.
steipete··on Just talk to it – A way of agentic engineering
(OP) 1/3rd of the code is tests.

There's an Expo app, two Tauri apps, a cli, a chrome extension. The admin part to help debug and test features is EXTREMELY detailed and around 40k LOC alone.

To give some perspective to that number.

steipete··on Just talk to it – A way of agentic engineering
OP: If you give the llm examples like https://react.dev/learn/you-might-not-need-an-effect, it does a farily good job at refactoring useEffecs.

And yes refactoring sometimes re-introduces these, so it's not a perfect solution.

steipete··on Just talk to it – A way of agentic engineering
(OP) the current projec is closed source. If you look at my cli tools, that's pure slop, all I care is that it works, so reviewing that code for sure will show some weird stuff. Does it matter? It's a tool to fetch logs form a server. I run it locally. As long as is does that reliably, idk about the code.
steipete··on Just talk to it – A way of agentic engineering
tbh in the time where everyone uses AI to write articles, some typos and mistakes like that are helpful to show that it's human made.
steipete··on Just talk to it – A way of agentic engineering
(OP) I use atlas for database migrations, it works quite well with agents and has plenty guardrails around it.
steipete··on GLM 4.5 with Claude Code
Been using that for a while, first Chinese model that works REALLY well!

Also fascinating how they solved the issue that Claude expects a 200+k token model while GLM 4.5 has 128k.

steipete··on Show HN: Conductor, a Mac app that lets you run a bunch of Claude Codes at once
For that workflow, you might be happier with https://vibetunnel.sh.
steipete··on vibetunnel - turn any browser into a terminal and command your agents on the go
Bind to localhost (default) and share securely via Tailscale.
steipete··on Give Your AI Agents Supernatural Vision on macOS
Peekaboo is a macOS-only MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.

Without screenshots, agents debug blind—Peekaboo gives them eyes.

steipete··on Commanding Your Claude Code Army
Yeah, heavily tweaked. I'm playing around with AI, still my edits tho. You can see the work in the plenty PR commits. It's all open source.

Writing that with prompts took longer than writing it myself tbh.

steipete··on Claude Code Is My Computer
Good thing we don't have to take everything literal in life and can appreciate a little exaggeration so people get curious :)
steipete··on Claude Code Is My Computer
All ~50 prompts would take you have an hour to read and wouldn’t bring across my point nearly as good.
steipete··on Claude Code Is My Computer
I worked about 4h on this and 50+ prompts. See the GitHub PR. In the end that’s not much different to iterating with a direct editor.
steipete··on Claude Code Is My Computer
See the footnote. If you use this then iPhone Mirroring is broken on current macOS. And I need that for my next project.
steipete··on Claude Code Is My Computer
tbh that one example isn’t the greatest, though yes, just talking about a topic without editor open is a refreshing change in how I usually write, so wanted to give it a go.
steipete··on Claude Code Is My Computer
No risk, no fun. I don’t run any critical website, everything I build is open source and verifiable. I’m my own boss. So, can do.
steipete··on Claude Code Is My Computer
I don’t get any money from them. There are no affiliate links anywhere. I’m just really enjoying what Claude Code can do.
steipete··on Claude Code Is My Computer
You can get pretty far with much less. See https://steipete.me/posts/2025/stop-overthinking-ai-subscrip...
steipete··on Claude Code Is My Computer
It took 50+ prompts to get it to this state. I’d say that counts as putting enough care into it to be my voice.
steipete··on Coinbase’s philosophy on account removal and content moderation
lol they blocked my account without any reason given. Sure. Do what you preach.
steipete··on Prisma – ORM for Node.js and TypeScript
How are they going to make money?
Page 1 of 4Next →