{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"NC Tweener Talks","title":"The Unlocked Door: Ryan Eade on What OpenClaw Users Need to Secure Right Now","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/a175693c\"></iframe>","width":"100%","height":180,"duration":1282,"description":" Ryan Eade, Chief Product and Technology Officer at PtEverywhere, gave this talk at the June 10th TweenerClaw meetup, and it covers something most practitioners skip: how to actually keep your OpenClaw instance secure. Ryan walks through the three main ways OpenClaw instances get compromised: an open port that older versions left fully exposed, third-party skills that can carry malicious code (36% of early store listings had prompt injection), and prompt injection delivered through external content like X posts or README files. He also covers the upgrade windows that matter most; the March 12th and April 5th releases each contained critical security patches, and what to do right now: curl port 18789 on your OpenClaw and see if you get a response back. The practical framework Ryan closes with is worth listening to by itself. He calls it \"staff not software\" with the idea that every access decision for your OpenClaw should mirror how you'd onboard a new employee: scoped API keys with minimum permissions, a purpose-built email account, one-time credit cards for purchasing tasks, and human approval gates before any destructive action runs. If you've been meaning to lock down your setup but kept putting it off, Ryan gives you everything you need to do it in under 20 minutes.\nTimestamps\n00:00 Intro bumper \n00:16 Sponsor recognition \n01:22 Scot's intro \n01:56 Introducing Ryan Eade\n02:05 Ryan's topic: cybersecurity for OpenClaw\n02:50 Ryan Eade \n03:28 \"Nobody starts with security\" \n04:10 Why OpenClaw isn't just a chatbot \n05:26 The threat landscape \n06:09 Early OpenClaw exposure stats\n06:40 Threat 1: The open port \n07:28 Docker's dirty secret: it bypasses your local firewall\n08:07 Fix: bind to localhost and use Tailscale\n09:19 What Tailscale is and why it works\n09:26 Threat 2: Third-party skills \n10:18 How to vet skills: pull the GitHub and read the code\n10:58 Threat 3: Prompt injection from the web\n11:39 How prompt injection poisons an OpenClaw session\n11:47 Real...","thumbnail_url":"https://img.transistorcdn.com/UEzoK7N1siD9YRaSVBWfZ8B3suSS2aonEIZ5NwBH1Gs/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80NjBh/YWVhZTA4ZTUyY2Fl/MDdhNzQwZWFhNDI4/MDc3Zi5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}