logoalt Hacker News

jasongi • today at 2:52 PM • 3 replies • view on HN

There is one thing Meta got "right" here and it's not about UX. It's about security/liability brinksmanship.

People like Muse because you can put your password in and it does the thing end-to-end, which is something that I can only assume OpenAI and Anthropic had deliberately been avoiding because it's obviously a bad idea. It's pushing the "Overton window" of actions you're letting it do without regard for what happens when it goes wrong.

Just like how OpenClaw pushed it with no human-in-the-loop, Claude code pushed it before that with the all the risks of giving a third-party RCE on your machine.

You could argue that the main difference with CLI agents and OpenClaw is that they are aimed at technical users who understand the risks, whereas with Muse and GrokBot the target is explicitly "normal people" who put their password as their birthday and fall for phishing pages.

The pattern is clear, the leaders will take less risks than those in 3rd and 4th place because they have more to lose. The frontiers, smartly, keep liability low by leaving the dangerous/stupid (but incredibly fun/productive) AI uses outside of anything they actively encourage.

The insane part about Muse is that generally things like Coding agents/OpenClaw were stupider the cheaper the model you were using, which meant most people were paying for frontier to get good results (at least initially) - if you try to do complex tasks with a crappy model, you would face way more "delete production" moments. Meta is pushing boundaries AND doing so on a free plan - suggesting the use of an economical model, which makes it even more insane.

The question now becomes... will the risk be worth it? Or will people be turned away by horror stories of LLMs going on a spending spree and then being unable to make rent.


Replies

blfr • today at 4:19 PM

Claude will happily accept secrets (passwords, tokens, ssh keys) as environmental variables or in files. It only refuses to handle them directly.

I have a local repo with my home lab mapped out and Claude manages servers via ssh. It is completely fine with using my ssh keys and pass.

Claude will also drive the browser. After a couple times, it will even offer to do something via the browser where no API or other machine interface exists.

And yes, the digital drudgery has definitely reached a point where this is worth the risk.

abelyagubyan • today at 7:15 PM

The scary part isn't Meta storing your passwords. It's a cheap free-tier model holding them and deciding on its own when to use them.

alex1138 • today at 3:01 PM

It's FB's modus operandi. They don't care about safety or being careful. About fucking anything.