OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
OpenClaw has unveiled its most significant update yet, version 2.0, focusing on usability and introducing some security updates. The release of version 2.0 of its AI agent harness has been described as far more extensive than ever intended. Community manager Hannes Rudolph explained that the update touches every part of OpenClaw, starting with a simplified installation process and a redesigned browser app interface.
The aim was to get more people using OpenClaw by reducing configuration and simplifying the setup. The browser app now feels more familiar to users of popular AI services like ChatGPT, Claude, Gemini, or Perplexity, with conversations displayed in a sidebar and the active chat in the center. A new feature, shared cloud sessions, allows multiple team members to interact with a single instance without losing memory, giving OpenClaw feature parity with other AI agent harnesses.
However, security improvements are limited. While a new protected credentials feature has been added, secret values are not encrypted at rest and rely on filesystem permissions. Additionally, shared session controls are not considered a security boundary. As such, OpenClaw's update brings usability improvements but does not address critical security concerns, highlighting the need for caution when granting powerful tools access to systems and credentials.
Written by urgent.news from The Register Software's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.