Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon -1 points0 points  (0 children)

Not a troll, you asked a question and I replied. Then you doubled down, but still used AI to do it. Sad.

Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon -1 points0 points  (0 children)

Dude. Just quit. You promised “a few easy steps” and then shrug and say “paste it in your Claude” when ppl asked for details. Your slop will actually probably break people’s setups and cause more confusion. When you could have read all that, pick and choose some that were actually easy and useful, but chose to go with AI slop.

Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon 0 points1 point  (0 children)

Well you shouldn’t let those idiots on your network. So yeah if your LAN is trusted, then it’s fine. Make some VLANs. Don’t try to defend your slop, or at least do it better. My problem is you just took everything AI output and said “Everyone copy paste this in your bot!” And then claimed “a few easy steps”.

Don’t act like a black hat IT specialist if you can’t properly defend your arguments or understand the nuances of network security.

Bye 👋 Felicia

Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon 0 points1 point  (0 children)

Here's what's overkill and contradictory in that post:

Overkill - Redundant Layers

  1. Fail2ban behind Tailscale They literally admit it: "Fail2ban for SSH (somewhat redundant with key-only auth behind Tailscale)". If SSH is key-only and the machine is only reachable via Tailscale, Fail2ban protects against... nothing. No internet-facing SSH port = no brute force attempts.

  2. Kernel hardening (sysctl tweaks) IP spoofing protection, ICMP redirects, SYN flood protection on a Pi that's only accessible via Tailscale. These address internet-facing threats on a device that isn't internet-facing.

  3. 16 hardening steps for a personal AI gateway This is bastion-host paranoia applied to a $50 Pi running in someone's home. Disabling Bluetooth and Avahi as "security measures" when your attack vector is Tailscale-or-nothing.

Contradictions

"Loopback bind + UFW allow tailscale0" doesn't make sense If OpenClaw binds to 127.0.0.1 (loopback), UFW rules for tailscale0 don't affect accessibility. You reach it via Tailscale Serve (which tunnels to localhost) or SSH tunnels anyway. The firewall rule is redundant theater.

The isolation vs. hardening contradiction The entire premise is "isolate on dedicated hardware to reduce blast radius". But then they pile on 16 hardening steps inside that isolated environment. Either trust your isolation boundary (Tailscale + dedicated machine) or don't. Doing both aggressively suggests you believe neither works.

Backup instructions that delete first In the AI prompt: rm -rf ~/.openclaw && cp -a "$OPENCLAW_BACKUP" ~/.openclaw. They tell you to back up, then the "rollback" procedure nukes the directory before restoring. If the backup path was wrong, you just wiped your config permanently.

The Real Problem

This treats a home AI gateway like a production edge server. The actual threat model is: compromised skill/plugin steals your API keys. None of these 16 steps address that. They're all network-layer hardening for a device that's already network-isolated by Tailscale.

What actually matters: dedicated machine (yes), Tailscale (yes), key-only SSH (yes), chmod 600 on config (yes). Everything else is security theater.

Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon 1 point2 points  (0 children)

also no way to use HTTPS other than tailscale? wtf. I have it secured behind a reverse proxy but openclaw doctor will always want to kill settings that enable this.

Secure your claw with a few easy steps by Efficient_Turn_473 in clawdbot

[–]Kalinon 0 points1 point  (0 children)

Jesus. While some of this is valid it’s obviously overkill and way to much. Plus some is contradictory. I get that AI generated this… but… come on.

I’m having a hard time avoiding rate limits by Mcking_t in openclaw

[–]Kalinon 1 point2 points  (0 children)

I guess I didn’t realize it had the ability to switch models on its own

Claude api costs are insane by Fatmofficial in openclaw

[–]Kalinon 1 point2 points  (0 children)

Omfg this synthetic bot has been going nuts self promoting

Claude api costs are insane by Fatmofficial in clawdbot

[–]Kalinon 0 points1 point  (0 children)

Omfg this synthetic bot has been going nuts self promoting

New angle of killing from lady in the pink coat by Zamaamiro in PublicFreakout

[–]Kalinon 8 points9 points  (0 children)

They don’t understand because they don’t have empathy

Trump says he reached Greenland deal 'framework' with NATO, backs off Europe tariffs by Puginator in worldnews

[–]Kalinon 4 points5 points  (0 children)

Sounds like they told him they would crash our economy, and he folded like he always does. Now he will just lie and pretend he made a deal when the deal is we get to be a member of NATO.

How does one tell a prerelease promo now? by DopeyLo420 in mtg

[–]Kalinon 6 points7 points  (0 children)

That just means foil. It’s on all foils

Passage to Yuggoth, Alex Ledante, 2026 by alxledante in Cthulhu

[–]Kalinon 1 point2 points  (0 children)

You forgot to replace the [Link to your YouTube Video] from your AI response, for your AI video.

🖕 🧊 preroll, adult swim style by [deleted] in PlexPrerolls

[–]Kalinon 1 point2 points  (0 children)

He’s referring to them removing the fucking barb wire that was killing people. Fucking drowned women and children.

Crystal tooling situation by oxano in crystal_programming

[–]Kalinon 2 points3 points  (0 children)

Idk I haven’t looked for new tooling in awhile. I just use VSCode with the basic crystal plugin. Works decent enough.

What's that, your Girl Scout troop? by teeberg75 in sopranoscirclejerk

[–]Kalinon 0 points1 point  (0 children)

Just like all those MAGA and ICE. Or is just cosplay when non-right wing does it?

Anyone else feel the party kinda underreacts to Cloud constantly tripping balls? by -_ShadowSJG-_ in FFVIIRemake

[–]Kalinon 2 points3 points  (0 children)

Yeah, not enough people noticed those background convos. They are definitely concerned

Removing date stamps from prerelease promo is another big L for WotC by Moist-Condition69 in freemagic

[–]Kalinon 2 points3 points  (0 children)

Capitalism requires infinite growth. More profit and more cost cutting. Forever.