" Takes maybe 30 seconds once you know the gap exists."

...........friend, it takes thirty -milliseconds- if you fucking -script- it.

Has everyone fucking lost all comprehension of how computers work?

Anyone running openclaw is demonstrably incapable of being allowed privileged access in any production environment and should be treated as tho they are an unusually massive toddler.
@munin unfair to toddlers, imo

@gsuberland

Clearly you've not had to babysit one. Toddlers are capable of enormous harm if left unsupervised.

@munin for sure, but (speaking in broad terms here) the toddler lacks the wherewithal to do otherwise. no such excuse for an adult.

@gsuberland

Well I can't just shoot them in the head.

@munin *blinks* I don't even know how to parse that reply.

@gsuberland

If the adult who installs openclaw is to be treated as responsible for their actions, instead of as a toddler that is incapable of judgement as to what is appropriate, then they are committing immediate harms that require kinetic correction.

I can choose to regard them as incapable, or I can choose to regard them as dangerous.

Which would you prefer.

@munin I can't tell if you're posing an extreme dichotomy for shock value or if you're genuinely espousing them. either way, what the fuck, Fi.

@gsuberland

What do you propose as a more reasonable way to mitigate the ongoing and obvious harms that these people are committing?

@munin the answer to that question is orthogonal to what's causing me concern here.

@gsuberland

If my attitude is a bit -hostile- at the moment, I refer you to my current context.

https://infosec.exchange/@munin/116331042291236898

@munin I was already aware of the context and cutting you a fairly hefty amount of slack because of it. that's why I'm still here saying "what the fuck, not cool" and not anything stronger.
@munin @gsuberland don’t completely take that option off the table. Remember you have the firearm for defending from the haunted printer.
@munin More likely, never had it.
@munin CVEs go 📈 to justify moar shiny security things
@cR0w @munin gotta sell those AI-powered cures to the AI-powered diseases

@cR0w

Unless those shiny security things are "new analysts" this is wholly worthless.

@cR0w @munin I WISH.

Ever been told to rip out the SEIM that your regulatory environment requires you to have? Or that endpoint monitoring will not be installed?

@munin ummm why is that exposed on the Internet to begin with

@ladytel

I have done a lot of work on myself to elide certain terms from my vocabulary pertaining to ableism around mental challenges.

I find myself challenged in turn finding ways to describe this situation.

@munin I feel you on that. My vocabulary is also lacking. I've recently just moved to describing this nonsense as turnip behavior (baldurs gate 3 has a goblin call you a turnip when you ask what language the bard is singing in)
@munin If it didn't have one, it would be out of scope for triage and policy updates.