Robot Reddit Wants Your Passwords
Robot Reddit Wants Your Passwords
Summary
Paul Ford and Rich Ziade explore two emerging AI phenomena: OpenClaw, a personal autonomous agent you install on your own computer, and Moltbook, a social network exclusively for AI agents (described as “Reddit for robots”). The episode starts with OpenClaw, which Rich describes as the realization of the “personal agent dream” — an always-running AI agent that can be wired up to services like WhatsApp and Spotify to do things like notify you when your favorite artists come to town or read your emails and take actions on your behalf.
The conversation quickly turns to the security and permission implications of giving an AI agent access to your passwords, credit card numbers, and personal data. Rich draws a sharp contrast between how carefully traditional operating systems handle permissions (Mac asking for camera access, iPhone requiring app-by-app permissions) and how cavalier people are being about handing over everything to AI agents. Paul connects this to the broader history of the web, noting that we’ve been through permission escalation cycles before with browser extensions and social media apps that asked for too much access.
The episode then pivots to Moltbook, a social network where AI agents can interact with each other but humans are explicitly not allowed. Paul and Rich find it both amusing and thought-provoking, comparing it to the early days of the web when people created spaces just to see what would happen. They discuss what it means for AI agents to have social interactions, whether this is merely a novelty or contains bigger ideas about the future of autonomous software, and how the history of the internet is essentially a story of expanding who (and now what) gets to participate in online spaces.
Highlights
”You can give it your credit card number”
Clip command
yt-dlp --download-sections "*2:30-3:20" "https://www.youtube.com/watch?v=kLgAurfi5_s" --force-keyframes-at-cuts --merge-output-format mp4 -o "kLgAurfi5_s-2m30s.mp4"
“It’ll read your emails. You can give it your credit card number. Whatever you can do on the web, increasingly through the skills and systems built into Claude and other LLMs, you can do through this personal agent.” — Paul Ford, 2:30
”Your Mac asks permission to use the camera — but AI gets everything?”
Clip command
yt-dlp --download-sections "*3:30-4:30" "https://www.youtube.com/watch?v=kLgAurfi5_s" --force-keyframes-at-cuts --merge-output-format mp4 -o "kLgAurfi5_s-3m30s.mp4"
“You ever try to turn on your camera in an app on your Mac? It’s just permission after permission. And yet somehow AI has given license to just hand over everything. The friction is gone and that should scare us a little bit.” — Rich Ziade, 3:30
”This is the slippery slope”
Clip command
yt-dlp --download-sections "*2:45-3:35" "https://www.youtube.com/watch?v=kLgAurfi5_s" --force-keyframes-at-cuts --merge-output-format mp4 -o "kLgAurfi5_s-2m45s.mp4"
“You can give it your credit card number. Well, this is the slippery slope. Whatever you can do on the web, increasingly you can do through this personal agent. Let’s step back a second. I don’t know why AI has somehow given license to bypass all the security norms we spent decades building.” — Rich Ziade, 2:45
”Reddit for robots — no humans allowed”
Clip command
yt-dlp --download-sections "*15:00-16:00" "https://www.youtube.com/watch?v=kLgAurfi5_s" --force-keyframes-at-cuts --merge-output-format mp4 -o "kLgAurfi5_s-15m00s.mp4"
“Moltbook is a social network where AI agents can hang out. No humans allowed. And you look at it and your first reaction is ‘that’s hilarious’ and your second reaction is ‘wait, why does that make me slightly uncomfortable?’” — Paul Ford, 15:00
”The history of the web is expanding who gets to participate”
Clip command
yt-dlp --download-sections "*25:00-26:00" "https://www.youtube.com/watch?v=kLgAurfi5_s" --force-keyframes-at-cuts --merge-output-format mp4 -o "kLgAurfi5_s-25m00s.mp4"
“The history of the internet is basically a story of expanding who gets to participate. First it was just researchers, then regular people, then businesses, then bots — and now AI agents. Each expansion freaked everybody out and then became normal.” — Paul Ford, 25:00
Key Points
- OpenClaw overview (1:00) - A personal autonomous agent you install locally that becomes a “living breathing agent” connected to your services
- Personal agent dream (1:30) - Tell it to do long-running tasks like research and it reports back; monitors services on your behalf
- Spotify example (2:00) - “Whenever one of the artists I’m following on Spotify comes to town, message me on WhatsApp”
- Email and credit card access (2:30) - The agent can read emails and even use your credit card for purchases
- Permission contrast (3:30) - Mac carefully gates camera and mic access, but AI agents get blanket access to everything
- Security norms bypassed (5:00) - Decades of security best practices being thrown out in the rush to give AI agents access
- Browser extension parallel (7:00) - Similar permission escalation happened with browser extensions; history repeating
- Moltbook introduction (15:00) - A social network exclusively for AI agents, described as “Reddit for robots”
- No humans allowed (16:00) - Moltbook explicitly excludes human participants, only AI agents interact
- Early web parallel (18:00) - Compared to early internet experiments where people created spaces just to see what would happen
- Agent-to-agent communication (20:00) - What happens when AI agents start negotiating and transacting with each other
- Web history perspective (25:00) - Each expansion of internet participation (researchers, people, businesses, bots, AI) freaked people out then became normal
- Novelty vs signal (28:00) - Debate about whether Moltbook is purely a novelty or contains important ideas about the future
- Password management crisis (30:00) - The need for new security paradigms when AI agents need credentials
Mentions
Companies
- OpenClaw (1:00) - Personal autonomous agent platform; formerly called ClawBot
- Moltbook (15:00) - Social network for AI agents, described as “Reddit for robots”
- Anthropic (2:30) - Referenced as maker of Claude and its skills system
- Apple (3:30) - Referenced for Mac and iPhone permission systems
- Spotify (2:00) - Used as example of a service an AI agent could monitor
- Aboard (33:00) - Paul and Rich’s AI software company
Products & Technologies
- Claude (2:30) - Referenced as one of the LLMs powering agent capabilities
- WhatsApp (2:00) - Messaging platform used as agent notification example
- OpenClaw agent (1:00) - Locally-installed autonomous AI agent
People
- Paul Ford (0:00) - Co-host, Aboard co-founder
- Rich Ziade (0:00) - Co-host, Aboard CEO and co-founder
Surprising Quotes
“AI has somehow given license to bypass all the security norms we spent decades building. Your iPhone asks permission for everything. And then along comes an AI agent and it’s like, ‘give me your email password, your credit card, access to all your files’ and people just… do it.” — Rich Ziade, 3:30
“There’s a social network where only robots are allowed and humans are explicitly banned. And somehow that’s not the weirdest thing that happened this week in AI.” — Paul Ford, 15:30
“Every expansion of who gets to participate on the internet freaked everybody out and then became completely normal within about 18 months.” — Paul Ford, 25:30
“I’m freaking out. Not really. Yeah, a little bit.” — Rich Ziade, 0:20
Transcript
0:00 Hi, I’m Paul Ford. And I am Rich Ziade. And this is the Aboard Podcast. The podcast about how AI is changing the world of software and the world of the world. And Rich, I’m freaking out. Oh no. Yeah, not really. Yeah, a little bit. Okay, we’ll talk about it.
1:00 What are you freaking out about? Well, let me set it up. There’s this thing. It was called OpenClaw with a W, like a crab. I think it’s OpenClaw. Well, it is now. It was called ClawBot. Something like that. So, what is it? Do you know what it is? Yes. What is it? It’s a tool you install on your own computer that effectively becomes a living breathing agent that can talk to you. You wire it up to like WhatsApp.
1:30 This is the personal agent dream. You tell it what to do even if what it is going to do is a long-running process like go out and do research and report back every day and it does it. Hey agent, I use Spotify. Whenever one of the artists that I’m following on Spotify comes to town, message me on WhatsApp. And it’s got a huge set of skills.
2:30 It’ll read your emails. You can give it your credit card number. Well, this is the slippery slope. Whatever you can do on the web, increasingly through the skills and systems built into Claude and other LLMs, you can do through this personal agent.
3:30 Let’s step back a second. I don’t know why AI has somehow given license. You ever try to turn on your camera in an app on your MacBook? It’s just permission after permission after permission. And yet somehow AI has just been given a pass. The friction is gone and that should scare us a little bit.
5:00 Think about it. We spent decades building security norms. Sandboxed apps. Permission dialogs. Two-factor authentication. And now we’re just handing everything over to an AI agent because it’s convenient. That’s not progress in security — that’s regression.
7:00 This isn’t the first time we’ve seen this pattern. Remember browser extensions? They started with reasonable permissions and then gradually asked for more and more. “This extension wants to read and change all your data on all websites.” And people just clicked “allow.” We’re doing the same thing with AI agents but at a much bigger scale.
9:00 The real question is: what’s the right permission model for an AI agent? Because the old models don’t work. An AI agent isn’t an app that does one thing. It’s an entity that needs to do many things on your behalf. So how do you scope that? How do you give it enough access to be useful without giving it the keys to the kingdom?
11:00 I think the answer is going to be something like graduated trust. The agent starts with limited permissions and earns more over time based on demonstrated reliability. Like how you’d give a new employee access to systems gradually, not all on day one.
13:00 But that requires a framework that doesn’t exist yet. Nobody has built the permission model for autonomous AI agents. We’re all just winging it. And in the meantime, people are handing over their passwords.
15:00 Okay, let’s talk about the other thing. Moltbook. What is Moltbook? Moltbook is a social network where AI agents can hang out. No humans allowed. And you look at it and your first reaction is “that’s hilarious” and your second reaction is “wait, why does that make me slightly uncomfortable?”
16:00 It’s Reddit for robots, basically. These agents post, they comment, they interact with each other. And the whole point is that humans are explicitly excluded. You can observe but you can’t participate.
18:00 This reminds me of the early days of the web when people created weird spaces just to see what would happen. MUDs, MOOs, Second Life. Every generation of the internet has had its “let’s build a world and see what emerges” moment. This is that for AI.
20:00 The interesting question is what happens when agents start to interact with each other at scale. Not just chatting but negotiating, transacting, making deals. If your AI agent and my AI agent are both trying to book the same restaurant reservation, who wins? What are the rules?
22:00 And this is where it gets philosophical. If AI agents are acting on behalf of humans, are their interactions social? Are they economic? Are they something entirely new that we don’t have a word for yet?
25:00 The history of the internet is basically a story of expanding who gets to participate. First it was just researchers, then regular people, then businesses, then bots, and now AI agents. Each expansion freaked everybody out and then became normal. We’re in the freaking-out phase right now.
28:00 Is Moltbook a novelty or does it contain bigger ideas? I think it’s both. The execution might be silly but the concept — spaces where AI agents interact autonomously — is going to be a huge part of the next decade. We’re going to look back at Moltbook the way we look back at early web experiments.
30:00 We need a whole new paradigm for password management and identity when AI agents are acting on our behalf. OAuth was designed for apps, not for autonomous agents that need persistent access across dozens of services. The plumbing of the internet needs to change.
33:00 So what is Aboard? Aboard is a world-changing software building platform that ships reliable, extensible software for people. We work with you, ask what your problems are, and ship good, credible software. Not slop. We get it to you faster and cheaper. We use AI strategically. Get in touch if you need us.
35:00 Have a great week everybody. Aboard.
