{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"NC Tweener Talks","title":"The Unlocked Door: Ryan Eade on What OpenClaw Users Need to Secure Right Now","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/a175693c\"></iframe>","width":"100%","height":180,"duration":1282,"description":" Ryan Eade, Chief Product and Technology Officer at PtEverywhere, gave this talk at the June 10th TweenerClaw meetup, and it covers something most practitioners skip: how to actually keep your OpenClaw instance secure. Ryan walks through the three main ways OpenClaw instances get compromised: an open port that older versions left fully exposed, third-party skills that can carry malicious code (36% of early store listings had prompt injection), and prompt injection delivered through external content like X posts or README files. He also covers the upgrade windows that matter most; the March 12th and April 5th releases each contained critical security patches, and what to do right now: curl port 18789 on your OpenClaw and see if you get a response back. The practical framework Ryan closes with is worth listening to by itself. He calls it \"staff not software\" with the idea that every access decision for your OpenClaw should mirror how you'd onboard a new employee: scoped API keys with minimum permissions, a purpose-built email account, one-time credit cards for purchasing tasks, and human approval gates before any destructive action runs. If you've been meaning to lock down your setup but kept putting it off, Ryan gives you everything you need to do it in under 20 minutes.\nTimestamps\n00:00 Intro bumper 00:16 Sponsor recognition 01:22 Scot's intro 01:56 Introducing Ryan Eade02:05 Ryan's topic: cybersecurity for OpenClaw02:50 Ryan Eade 03:28 \"Nobody starts with security\" 04:10 Why OpenClaw isn't just a chatbot 05:26 The threat landscape 06:09 Early OpenClaw exposure stats06:40 Threat 1: The open port 07:28 Docker's dirty secret: it bypasses your local firewall08:07 Fix: bind to localhost and use Tailscale09:19 What Tailscale is and why it works09:26 Threat 2: Third-party skills 10:18 How to vet skills: pull the GitHub and read the code10:58 Threat 3: Prompt injection from the web11:39 How prompt injection poisons an OpenClaw session11:47 Real examples 12:51 The full...","thumbnail_url":"https://img.transistorcdn.com/UEzoK7N1siD9YRaSVBWfZ8B3suSS2aonEIZ5NwBH1Gs/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80NjBh/YWVhZTA4ZTUyY2Fl/MDdhNzQwZWFhNDI4/MDc3Zi5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}