Comment on We eliminated 1,400 CVEs in NanoClaw's container imagesComments−eviks30dWhat is NanoClaw? Glad you asked:NanoClaw is a secure, lightweight alternative to OpenClaw.−Hamuko30dIf the lightweight alternative has 1400 CVEs, how many does OpenClaw have?−overgard30dI'm pretty skeptical you can call any claw-like thing secure unless you solve prompt injection.−stavros30dSecurity isn't binary. There's nothing that's "secure" unless you define a threat model first.−TZubiri30dSounds like the kind of stuff devs that introduce security vulnerbilities say.−r14c30dif you can't define a threat model, or know why you need one, you will write vulnerable code.−stavros30dUnrelatedly, I wonder why I don't see the downvote arrows on comments any more.
Comments
What is NanoClaw? Glad you asked:
If the lightweight alternative has 1400 CVEs, how many does OpenClaw have?
I'm pretty skeptical you can call any claw-like thing secure unless you solve prompt injection.
Security isn't binary. There's nothing that's "secure" unless you define a threat model first.
Sounds like the kind of stuff devs that introduce security vulnerbilities say.
if you can't define a threat model, or know why you need one, you will write vulnerable code.
Unrelatedly, I wonder why I don't see the downvote arrows on comments any more.