提问 HN:如果没有发生提示词注入,就安全了吗?
2 分•作者: sayYayToLife•5 个月前
我使用 open claw 时,更担心提示词注入,而不是糟糕的代码。但我认为我有点杞人忧天。我只是个小人物,单枪匹马,有人想主动黑我,会去利用价值数百万美元的零日漏洞,他们不会把目标放在我身上。<p>如果我们考虑通过终端命令意外删除所有内容,我还没见过这种事真正发生过。<p>从演绎法的角度来看,我能看到 open claw 的所有最坏情况。从归纳法的角度来看,我从未见过它真正发生过。<p>我认为假装 open claw 存在真正的安全风险,有点不理智。<p>等我在 Hacker News 上看到有人被提示词注入攻击了,我才会开始担心。在那之前,我需要像中彩票一样的几率,才能成为第一个被提示词注入攻击的人。
查看原文
As I use open claw I am concerned about prompt injection more than bad code. However I think I'm irrationally paranoid. I'm small fries I'm a single individual, someone actively trying to hack me is exploiting a multi-million dollar zero day and they're not doing that on me.<p>If we're thinking about accidentally deleting everything through a terminal command, I've yet to see this actually occur.<p>Deductively I can see all of the worst case scenarios with open claw. Inductively I've never seen it actually happen.<p>I find it a bit irrational to pretend that open claw is a genuine security risk.<p>The moment I see on Hacker News that someone got prompt injected, I think I'll be concerned. Until then I would need almost a lottery like chance to get hacked as the first person through prompt injection.