The scariest part of the interaction is the first video at https://x.ai/bot where the bot just snags your creds from the browser and takes over. So many people are going to give x all their data and creds.
AI Session Hijacking is such a dead end and I think this will be the thing that kills it. Just register these things in the IDP and let them sign into their own accounts.
Maybe if we give these things their own identity people will stop letting their AIs post as them in linkedin
Not sure I understand the point your are making. how is this unique for bots with their own identity? Bots hijacking a user session can also be blocked
Bots skinwalking their users inherit the behavioral scoring of that user. As a rule, they'll take a lot longer to get blocked than new bot accounts would.
We need more and stronger open source/weight models considering how deeply and intimately these bots are going to be integrated in our lives.
I hope that Dario Amodei fails in his quest to regulate open models out of existence to line his pocket under the guise of safety. Amodei/anthropic will end up being the most harmful force in the next few decades where progress in AI is concerned.
I hope people realize sooner than later that this is a replay of early Microsoft vs open source situation and Amodei is the new Gates on a crusade against open source/Linux.
> Is it allowed to use automated tools to interact with any system?
I'd hope so, because that's what we're doing right now. Your browser is automatically speaking HTTP for you so that you don't have to.
Am I having a bit of a laugh? Maybe. But really, services should be user-agent agnostic. That's the whole "agent" part of User Agent and the founders of the Internet had incredible foresight to name it this way.
> Is it allowed to scrape data?
You mean, request data and receive what the other server voluntarily transmits?
> Are there any laws for this?
There was a court case that said the above is fine, thankfully, since that's how the internet works. There's probably other cases going on and I'm sure at least one of them will have some unfortunate tech-illiterate result that makes things worse for anyone who understands this stuff.
> request data and receive what the other server voluntarily transmits?
Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.
In many cases, what the other server voluntarily transmits has so far been based on the tacit assumption that a person, with person-level time and computational power, is doing the receiving. While in principle a machine could be doing it even in pre-LLM times, in practice many websites, including all the biggest ones, have implemented a wide range of approaches to try to curb machine access, starting with user agent checks and rate limits but by no means ending there.
The question is: Given the new landscape, where this assumption increasingly does not hold (because AI agents are increasingly able to simulate anything a person could do online), would those servers voluntarily transmit that data? In many cases, the answer is no.
> Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.
Not really. At any time you can, and should, choose not to reply to traffic that is wasting your bandwidth - ban IPs, use DDOS mitigation services, etc. My position is simply that regulation doesn't belong in this space, and it's ok for the 'net to be a dog eat dog world. Kind of what keeps technology advancing and exciting.
But who decides what comprises "wasting [my] bandwidth"? This is subjective.
Is it me (the site owner in this example)? If so: Since it's my subjective decision to make, couldn't I equally legitimately decide that traffic I serve to non-human entities is "wasting my bandwidth"?
To be clear, I'm not trying to make the case that there should be some law in place that prevents scraping or machine access across the board -- only that it would make sense for website operators to be able, optionally, to include that kind of usage restriction in an ordinary contract and legally enforce it by the usual means (lawsuits), in addition to any kind of technical restrictions they are able to put in place.
> Your browser is automatically speaking HTTP for you so that you don't have to.
Yes, but it's not filling in the forms or clicking the buttons for me. HTTP is just infrastructure. Are LLMs infrastructure? Are we too maybe infrastructure? Where do we draw the line?
> You mean, request data and receive what the other server voluntarily transmits?
I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.
Regarding scraping, considering that this whole AI phase was built on illegal scraping, I don't think they can say anything now...
> I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.
I've always called that "learning" but I guess it's called something else when a robot does it :)
... The same way I might call something "gardening" or "weeding" when I do it, but for some reason, environmentalists call it "destroying the Amazon rainforest" when bulldozers do it to 27,000 km2 of vegetation in a year.
The internet sucks. Yesterday, I had my agent search for openings for The Odyssey that fit my requirements and then book them. It was way better than manually looking at seat maps for 20 different showtimes and going through 10 steps just to buy the tickets.
The monopoly movie chain in my country "updated" their pages to be "better".
Now it's so bad that some chad created their own overlay for the site where you can actually see all the showtimes for a specific movie on a single page instead of having to click through 42 different showings one by one.
Because doing it manually sucks? Every website shoves a different bunch of dark patterns in your face, everything is buggy, nobody ever thinks about UX.
Poor UX. The internet used to be designed around ease of use. Now it's dark patterns, advertising, nag windows, and "engagement." Retailers don't offer a way to aggregate info easily, so it means wading through piles of shit to find relevant information. Bots can eliminate all the shitty parts about using the internet. That's a big time saver, but it's also a big headache saver.
Yeah I'm a bit baffled too... the world is so, so much worse now because of AI.
More scams/spam, lower quality software everywhere, development is no longer fun, many interactions with coworkers are just "have my people talk to your people" behind the scenes, except it's "have my LLM read the huge document your LLM generated". Every business is trying to cut corners by using AI, so customer service sucks, products suck, prices are optimized to be the absolute maximum people will pay regardless of the actual value being provided (including food)...
The problem these model providers have now is there software is basically useless.
Tell me one reason why I would use this at my company? I basically have to bet on Grok being the best models for this.
Or I can use an open source version and use whatever model I want.
You see this with coding agents, everyone used Claude Code and then realized holy shit this is expensive and now use open source agents and they can use open source models and cut costs.
One advantage of code over many other use cases is that github is often the source of truth, so whatever is in Claude Code or Codex is ultimately replaceable.
It's for this reason I am bullish on text formats in general. Or maybe sqlite wrappers where databases are necessary. But I want a separation between the worker and the work through some data contract that allows me to easily move my stuff around.
> Tell me one reason why I would use this at my company?
I believe the selling point here is these run on their own VMs, so you don't need to set up your own harnesses, models, and security infrastructure to run agents.
Historically people tend to pay for single-click commercial solutions for complex technical set ups like that.
I was talking about why would I use a Grok specific version of this instead of one that I can switch models.
What if Grok models become horrible or they increase the pricing of the subscriptions now you have to migrate off. Instead you could just use the open source version that allows you to choose your providers and switch cost is just the time to switch those providers.
yeah, it really feels like the economics of AI are going to settle on trust - who do you trust to act on your behalf, because that's where the real value comes in.
and at the same time, it feels like all the AI companies - not just elon - are doing everything they can to burn trust.
Elon wanted X to be a universal app like WeChat. Communication, payment, government services (and probably one-shop stop for user surveillance)... Wahey, looking forward to Grokbot telling its users "we logged in to your bank account and moved all your money to BankX, it's got the best interest rate!"
This is obviously the future, where this will all end up. But just like when I saw the demos for Google's "AI build the interface dynamically", I wonder how much of the demo actually translates to real usage.
One thing that this highlights for me even more than before is that having accounts for my bots is what I really want. I want SaaS providers to catch up to bot use. They need their own accounts on a lot of these services and per-seat pricing works against this.
How does per-seat pricing work against bots? If anything it's a great deal because SaaS providers set per-seat pricing with the expectation that on average most seats are idle. Bots working 24x7 can get a lot more value out of a seat than humans working 9-5.
I just mean for me as a solo dev I guess. For example, github gives 2 users as part of a basic org and charges extra per seat, so if I want seats for individual agents so I can track them separately then I have to pay more. Same with Google Workspace, where I have to pay for additional users if I want to have multiple accounts.
As an example, I wanted to set up users in AWS identity center so I can give view only access to bots for my infrastructure, but that requires different email addresses. I set up an alias on my existing user so I didn't have to do that, but ideally I could have accounts for agent1 and agent2.
I can usually find workarounds like this but I feel I shouldn't have to. I don't want the agents to share my permissions in general since I'm often the admin. I want to give them limited scopes whenever possible.
edit: for reference, a Google Workspace user is ~220CAD/year and a github user is ~50USD/year. That is quite expensive if I want to add a couple of agents (well over 500CAD/year).
From FAQ: How is Grok Bot different from AI assistants? Bots have their own computer, so they can work inside your apps and tools. They also run in parallel, 24/7, even when your laptop is closed.
How does it work with login-walled sites like LinkedIn then? And what does "own computer" mean? X provisions a "private cloud" a'la Apple for your Bot?
The very first thing in their demo shows Grok logging in with the user's username and password to a website, presumably so it can perform actions and the human can get the blame for them. Apparently this is marketing and not terrifying to people.
How my bots do it is chrome dev tools or puppeteer or w/e. I've got chrome vnc (for monitoring) and headless X in the container with them. Works pretty flawlessly.
Does it have access to X API? One limitation in CC, Codex etc. is that they don't have access to X which sometimes has an answer not available via their search providers.
How do they stop providers (like Amazon, etc.) from detecting and blocking these agents if they are running on cloud? I know that openai wasn't able to avoid this which is why they moved to 'computer use' on your local machine.
I almost wonder if this is a place where SpaceX, as an internet provider through starlink, has a unique advantage because websites are unable to block their networking as it could be residential starlink consumers.
I think it creates a loop back connection, basically a reverse socks5 or a VPN if they are more sophisticated. That’s how I would do it. Note that I am also working on a such bot/AI os and mine is better (for now) . If you have trillions, billions to or millions to invest feel free to reach out.
This would imply you need to have your computer on in order for it to function, which seems like a deal breaker for many consumer usecases imo. I'd like to be able to say "order my groceries" and then I hop on the subway.
Not a big deal at all. Claude Code and Codex both support keeping your computer awake. That'll just be a default thing that gets turned on when you install one of these apps.
i just completely disagree. lots of people don't even have laptops and how will they keep my laptop alive and performing tasks while it's in my backpack on the subway not connected to internet?
i feel like there's an obvious advantage if your agent can work truly in the background
I agree, but I made myself laugh pondering a solution to this in which I came up with a Raspberry Pi like device that acts as the loopback for the agent. Always keep it on and plugged in.
I actually have set up something similar myself and it is much easier now that codex desktop for linux just came out (which has computer use/browser driving abilities). The issue is that on an rpi, I have to usually manually log into everything once.
I used to think if all else fails I'd take the path of a Cynic and retire in a giant vase. I'm not quite sure anymore. If you're done with society and the world you might as well prompt inject from a beach somewhere, and we're so not ready for this.
Interesting how everyone seems to be following OpenAI on UX. When I used Antigravity and they suddenly switched to Codex type UI I was very annoyed because I kept checking if this is Codex or Antigravity.
Either way, I still don't think that computer use is solved. It worked horribly on Codex and Antigravity the last time I tried. Maybe I was doing something wrong.
It's quite a bit different, namely that ChatGPT Work has both local conversations and cloud agents. But for each cloud agent, you are spinning up and tearing down a new VM each time. This is an always-on Linux box, which stays logged in. Additionally, your bots can talk to each other (although Codex did have the ability to reference threads, I am not sure if one thread could send messages to other threads).
My initial impression is strong: Agent-to-Agent comms are clearly a first-class citizen of this tech. There's a cohesion that's palpable. Maybe it just fits my workflow better than other tools. I have some routines set up for tomorrow morning that will tell me if the juice is worth the squeeze.
48% weekly usage left after 3 hours of experimenting, tough.
I've already been doing something very similar to this with OpenClaw, where I set up multiple different Telegram bots each with different system prompts to tune their personalty & behavior.
It's not trivial to do, and I never managed to get bot-to-bot communication working. Even with my janky setup, the experience is honestly pretty great. Grok Bot simplifies the setup for this about as far as I imagine is possible, and frankly it's a pretty slick experience.
It's a great idea, but the problem is with the latest versions of Grok. It's like xAI copied Google's Gemini. Grok now minimizes its effort. Like Gemini "Pro", it's become a flash model that provides shallow answers quickly.
There are two companies that have lost my trust, probably forever: X and Meta. I don't see myself ever trusting anything coming out of either of these companies ever again
Meta feels more like your traditional 'greedy corporation' that's fairly amoral and as a consequence ends up doing some bad things in pursuit of more profits.
The other one feels pretty explicitly evil at this point.
It should be studied how we reached a point where we trust more a Chinese company, that's well know for being state controlled, vs an American company because it seems they could do worse. Still no idea what "worse" it could do because we've reached the threshold where plague and cholera are intertwined and every possible outcome seems abusive.
Perhaps people are deciding that the impact a nefarious foreign government can have on them is less of a risk than their own government acting the same way. So Chinese should feel safer interacting with American companies and Americans safer interacting with Chinese companies.
That's probably bullshit.
Could also just be yet another wave of information warfare. I'm like 87.9% sure that bad actors explains nearly every aspect of this awful timeline we are on.
On a personal level, your own government can absolutely, 100% be more likely to do you harm than a foreign government, for simple jurisdictional reasons. They have more power over your life. And with an administration as corrupt and degenerate as the current US administration, it's an extremely reasonable perspective to have.
When it comes to the World Economic Forum et al, they certainly are. Supposedly socialist administration structures can be eerily similar to the capitalist ones. Down to the committees, or the consultative groups which are steered/controlled by certain individuals for their own ends, and the appeal to the public to gaslight them into thinking they backed whatever all along.
Both are top down structures that disenfranchise common people.
in case you are interested in ~this for your team, but dont want to either be vendor-locked to grok or give mecha-hitler extra money, consider trying what we've been building at https://noriagentic.com/ (or any of the other startups working in the same space)
I'm a little baffled by this, it's basically like the remote Claude instances I already use every day except it has absolutely no safeguards? If I wanted to make a claude could post to linkedin it would be like one prompt to spin that with playwright. Like you can just have persistent Claude code sessions, if you aren't cost sensitive you can just keep restarting the session whenever.
They're clearly targeting less technical users but in exchange are asking you to upload every login you have to Elon's servers which is an insane thing to do imo. What a world where people are giving their Instagram sign in to the bot formerly known as mechahitler.
The scariest part of the interaction is the first video at https://x.ai/bot where the bot just snags your creds from the browser and takes over. So many people are going to give x all their data and creds.
The world ends not with a bang, but with a “you’re right, I shouldn’t have done that. It’s right there in my agents.md file.”
AI Session Hijacking is such a dead end and I think this will be the thing that kills it. Just register these things in the IDP and let them sign into their own accounts.
Maybe if we give these things their own identity people will stop letting their AIs post as them in linkedin
> Just register these things in the IDP and let them sign into their own accounts.
And when you get blocked by whatever anti-bot tech the site is running?
Not sure I understand the point your are making. how is this unique for bots with their own identity? Bots hijacking a user session can also be blocked
Bots skinwalking their users inherit the behavioral scoring of that user. As a rule, they'll take a lot longer to get blocked than new bot accounts would.
But then whoever added them to the IDP becomes accountable for what the bots do.
By hijacking a real person's credentials, that person becomes the accountability sink. Very neat. Very deliberate.
I assume they store your session state/token for whatever SaaS it needs to work with but not the creds.
Many people assumed they didnt upload your whole home dir when you launched their IDE
Yeah, assuming that X is doing the honest and well-behaved thing is a mistake given their past actions.
it's crazy that we have multi-user computers and all this permission stuff on linux and none of it is used
What? How? Just the x.com creds or other ones too?
Well, it's the "Everything App" after all!
/s
IDK, it's the same problem I had with OpenClaw: I can't think of anything I need done that I want it to do for me.
We need more and stronger open source/weight models considering how deeply and intimately these bots are going to be integrated in our lives.
I hope that Dario Amodei fails in his quest to regulate open models out of existence to line his pocket under the guise of safety. Amodei/anthropic will end up being the most harmful force in the next few decades where progress in AI is concerned.
I hope people realize sooner than later that this is a replay of early Microsoft vs open source situation and Amodei is the new Gates on a crusade against open source/Linux.
The eternal fight between bots and anti-bot systems.
The difference now is that big companies themselves promote/offer bots, but they also don't like to be scraped and use captchas.
What do we do now? Is it allowed to use automated tools to interact with any system? Is it allowed to scrape data? Are there any laws for this?
If we do things manually it is ok, but not if we use a bot?
Confusing (legal) times...
> Is it allowed to use automated tools to interact with any system?
I'd hope so, because that's what we're doing right now. Your browser is automatically speaking HTTP for you so that you don't have to.
Am I having a bit of a laugh? Maybe. But really, services should be user-agent agnostic. That's the whole "agent" part of User Agent and the founders of the Internet had incredible foresight to name it this way.
> Is it allowed to scrape data?
You mean, request data and receive what the other server voluntarily transmits?
> Are there any laws for this?
There was a court case that said the above is fine, thankfully, since that's how the internet works. There's probably other cases going on and I'm sure at least one of them will have some unfortunate tech-illiterate result that makes things worse for anyone who understands this stuff.
That's the whole "agent" part of User Agent and the founders of the Internet had incredible foresight to name it this way.
Now it's the Agentic User Agent.
> request data and receive what the other server voluntarily transmits?
Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.
In many cases, what the other server voluntarily transmits has so far been based on the tacit assumption that a person, with person-level time and computational power, is doing the receiving. While in principle a machine could be doing it even in pre-LLM times, in practice many websites, including all the biggest ones, have implemented a wide range of approaches to try to curb machine access, starting with user agent checks and rate limits but by no means ending there.
The question is: Given the new landscape, where this assumption increasingly does not hold (because AI agents are increasingly able to simulate anything a person could do online), would those servers voluntarily transmit that data? In many cases, the answer is no.
> Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.
Not really. At any time you can, and should, choose not to reply to traffic that is wasting your bandwidth - ban IPs, use DDOS mitigation services, etc. My position is simply that regulation doesn't belong in this space, and it's ok for the 'net to be a dog eat dog world. Kind of what keeps technology advancing and exciting.
But who decides what comprises "wasting [my] bandwidth"? This is subjective.
Is it me (the site owner in this example)? If so: Since it's my subjective decision to make, couldn't I equally legitimately decide that traffic I serve to non-human entities is "wasting my bandwidth"?
To be clear, I'm not trying to make the case that there should be some law in place that prevents scraping or machine access across the board -- only that it would make sense for website operators to be able, optionally, to include that kind of usage restriction in an ordinary contract and legally enforce it by the usual means (lawsuits), in addition to any kind of technical restrictions they are able to put in place.
Yes, you e always been able to do this, as long as you get an actual contract that's enforceable.
The thing about most sites is they're public and you don't need to sign a real contract to use them. Can't have it both ways.
> Your browser is automatically speaking HTTP for you so that you don't have to.
Yes, but it's not filling in the forms or clicking the buttons for me. HTTP is just infrastructure. Are LLMs infrastructure? Are we too maybe infrastructure? Where do we draw the line?
> You mean, request data and receive what the other server voluntarily transmits?
I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.
Regarding scraping, considering that this whole AI phase was built on illegal scraping, I don't think they can say anything now...
> I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.
I've always called that "learning" but I guess it's called something else when a robot does it :)
... The same way I might call something "gardening" or "weeding" when I do it, but for some reason, environmentalists call it "destroying the Amazon rainforest" when bulldozers do it to 27,000 km2 of vegetation in a year.
I feel like we'd be better off if we just stopped at chatbots...why are we so eager to make the internet even more botted
The internet sucks. Yesterday, I had my agent search for openings for The Odyssey that fit my requirements and then book them. It was way better than manually looking at seat maps for 20 different showtimes and going through 10 steps just to buy the tickets.
So why didn't you just do it manually? Why use an agent in the first place?
The monopoly movie chain in my country "updated" their pages to be "better".
Now it's so bad that some chad created their own overlay for the site where you can actually see all the showtimes for a specific movie on a single page instead of having to click through 42 different showings one by one.
Because doing it manually sucks? Every website shoves a different bunch of dark patterns in your face, everything is buggy, nobody ever thinks about UX.
Poor UX. The internet used to be designed around ease of use. Now it's dark patterns, advertising, nag windows, and "engagement." Retailers don't offer a way to aggregate info easily, so it means wading through piles of shit to find relevant information. Bots can eliminate all the shitty parts about using the internet. That's a big time saver, but it's also a big headache saver.
Yeah I'm a bit baffled too... the world is so, so much worse now because of AI.
More scams/spam, lower quality software everywhere, development is no longer fun, many interactions with coworkers are just "have my people talk to your people" behind the scenes, except it's "have my LLM read the huge document your LLM generated". Every business is trying to cut corners by using AI, so customer service sucks, products suck, prices are optimized to be the absolute maximum people will pay regardless of the actual value being provided (including food)...
The problem these model providers have now is there software is basically useless.
Tell me one reason why I would use this at my company? I basically have to bet on Grok being the best models for this.
Or I can use an open source version and use whatever model I want.
You see this with coding agents, everyone used Claude Code and then realized holy shit this is expensive and now use open source agents and they can use open source models and cut costs.
One advantage of code over many other use cases is that github is often the source of truth, so whatever is in Claude Code or Codex is ultimately replaceable.
It's for this reason I am bullish on text formats in general. Or maybe sqlite wrappers where databases are necessary. But I want a separation between the worker and the work through some data contract that allows me to easily move my stuff around.
> Tell me one reason why I would use this at my company?
I believe the selling point here is these run on their own VMs, so you don't need to set up your own harnesses, models, and security infrastructure to run agents.
Historically people tend to pay for single-click commercial solutions for complex technical set ups like that.
I was talking about why would I use a Grok specific version of this instead of one that I can switch models.
What if Grok models become horrible or they increase the pricing of the subscriptions now you have to migrate off. Instead you could just use the open source version that allows you to choose your providers and switch cost is just the time to switch those providers.
I assume he meant an actual use case. Its architecture alone is not a reason to use it.
So OpenClaw that steals your data and profiles you for the US gov. No thanks.
yeah, it really feels like the economics of AI are going to settle on trust - who do you trust to act on your behalf, because that's where the real value comes in.
and at the same time, it feels like all the AI companies - not just elon - are doing everything they can to burn trust.
like creating "Elon-Only Settings" https://runtimewire.com/article/grok-bot-s-hidden-elon-only-...
do these guys not know we can reverse this stuff in 10min?
A tool that only people who trust Elon can use.
Elon wanted X to be a universal app like WeChat. Communication, payment, government services (and probably one-shop stop for user surveillance)... Wahey, looking forward to Grokbot telling its users "we logged in to your bank account and moved all your money to BankX, it's got the best interest rate!"
I wonder what grok "unhinged" would do to your social calendar/bank account.
This is obviously the future, where this will all end up. But just like when I saw the demos for Google's "AI build the interface dynamically", I wonder how much of the demo actually translates to real usage.
One thing that this highlights for me even more than before is that having accounts for my bots is what I really want. I want SaaS providers to catch up to bot use. They need their own accounts on a lot of these services and per-seat pricing works against this.
How does per-seat pricing work against bots? If anything it's a great deal because SaaS providers set per-seat pricing with the expectation that on average most seats are idle. Bots working 24x7 can get a lot more value out of a seat than humans working 9-5.
I just mean for me as a solo dev I guess. For example, github gives 2 users as part of a basic org and charges extra per seat, so if I want seats for individual agents so I can track them separately then I have to pay more. Same with Google Workspace, where I have to pay for additional users if I want to have multiple accounts.
As an example, I wanted to set up users in AWS identity center so I can give view only access to bots for my infrastructure, but that requires different email addresses. I set up an alias on my existing user so I didn't have to do that, but ideally I could have accounts for agent1 and agent2.
I can usually find workarounds like this but I feel I shouldn't have to. I don't want the agents to share my permissions in general since I'm often the admin. I want to give them limited scopes whenever possible.
edit: for reference, a Google Workspace user is ~220CAD/year and a github user is ~50USD/year. That is quite expensive if I want to add a couple of agents (well over 500CAD/year).
Presumably it'll either mean selling "agent seats", or billing seats for every started hour of use. With a monthly minimum, of course.
From FAQ: How is Grok Bot different from AI assistants? Bots have their own computer, so they can work inside your apps and tools. They also run in parallel, 24/7, even when your laptop is closed.
How does it work with login-walled sites like LinkedIn then? And what does "own computer" mean? X provisions a "private cloud" a'la Apple for your Bot?
The very first thing in their demo shows Grok logging in with the user's username and password to a website, presumably so it can perform actions and the human can get the blame for them. Apparently this is marketing and not terrifying to people.
It'll ask you to take over its computer to log in:
https://image.non.io/4022ec77-be07-4baa-97e8-ad9d8d9aeb8a.we...
After you do you just tell the bot you're done logging in and it'll keep driving. And yea, it's a separate VM for each bot.
Source: had access for the last few weeks.
dont forget the "Elon-Only Settings" makes it different too https://runtimewire.com/article/grok-bot-s-hidden-elon-only-...
How my bots do it is chrome dev tools or puppeteer or w/e. I've got chrome vnc (for monitoring) and headless X in the container with them. Works pretty flawlessly.
don't use the hitler bot please and thank you.
Are there any opensource app/system that directly competes with a solution like this?
Grokbot is another derivative of open source originals like Open Claw
https://en.wikipedia.org/wiki/OpenClaw
Im working on one here: https://github.com/smartcomputer-ai/lightspeed
The core is there. But there is some work to be done to have a nicer shell and all, which I’m currently focusing on.
Oh this looks very interesting, both for personal and work; I’ve been looking for something similar for quite a while.
However, no OpenAI API support (just Anthropic + openai.com) means I can’t use it for either.
The OpenAI API style (completions) support is coming this week. Currently working on it.
https://buzz.xyz/
I’ve tried using this as a self hosted instance and it’s been a little rough around the edges with Hermes.
openclaw and hermes
Does it have access to X API? One limitation in CC, Codex etc. is that they don't have access to X which sometimes has an answer not available via their search providers.
How do they stop providers (like Amazon, etc.) from detecting and blocking these agents if they are running on cloud? I know that openai wasn't able to avoid this which is why they moved to 'computer use' on your local machine.
I almost wonder if this is a place where SpaceX, as an internet provider through starlink, has a unique advantage because websites are unable to block their networking as it could be residential starlink consumers.
I use Hermes locally and it’s constantly hitting bot blocks. Just trying to shop clothes for me it gets blocked.
I think it creates a loop back connection, basically a reverse socks5 or a VPN if they are more sophisticated. That’s how I would do it. Note that I am also working on a such bot/AI os and mine is better (for now) . If you have trillions, billions to or millions to invest feel free to reach out.
This would imply you need to have your computer on in order for it to function, which seems like a deal breaker for many consumer usecases imo. I'd like to be able to say "order my groceries" and then I hop on the subway.
Not a big deal at all. Claude Code and Codex both support keeping your computer awake. That'll just be a default thing that gets turned on when you install one of these apps.
i just completely disagree. lots of people don't even have laptops and how will they keep my laptop alive and performing tasks while it's in my backpack on the subway not connected to internet?
i feel like there's an obvious advantage if your agent can work truly in the background
I agree, but I made myself laugh pondering a solution to this in which I came up with a Raspberry Pi like device that acts as the loopback for the agent. Always keep it on and plugged in.
I would like to introduce the Grok Box
I actually have set up something similar myself and it is much easier now that codex desktop for linux just came out (which has computer use/browser driving abilities). The issue is that on an rpi, I have to usually manually log into everything once.
I used to think if all else fails I'd take the path of a Cynic and retire in a giant vase. I'm not quite sure anymore. If you're done with society and the world you might as well prompt inject from a beach somewhere, and we're so not ready for this.
Interesting how everyone seems to be following OpenAI on UX. When I used Antigravity and they suddenly switched to Codex type UI I was very annoyed because I kept checking if this is Codex or Antigravity.
Either way, I still don't think that computer use is solved. It worked horribly on Codex and Antigravity the last time I tried. Maybe I was doing something wrong.
It's quite a bit different, namely that ChatGPT Work has both local conversations and cloud agents. But for each cloud agent, you are spinning up and tearing down a new VM each time. This is an always-on Linux box, which stays logged in. Additionally, your bots can talk to each other (although Codex did have the ability to reference threads, I am not sure if one thread could send messages to other threads).
Computer use will suck until we get 500+ tk/s
Grok lobster! (Rock lobster music starts playing)
My initial impression is strong: Agent-to-Agent comms are clearly a first-class citizen of this tech. There's a cohesion that's palpable. Maybe it just fits my workflow better than other tools. I have some routines set up for tomorrow morning that will tell me if the juice is worth the squeeze.
48% weekly usage left after 3 hours of experimenting, tough.
What plan are you on? Does the bot have its own usage, or does it count against cursor/grok code usage?
This is basically openclaw with browser access, or am I missing something?
This looks amazing. Lots of good ideas here. The human in the loop story is quite good here. I will shamelessly lift it for myself.
how does this compare to Hermes which is much cheaper?
Do you have to pay the companies for a second login for the bot...?
This seems like a disaster waiting to happen
I've already been doing something very similar to this with OpenClaw, where I set up multiple different Telegram bots each with different system prompts to tune their personalty & behavior.
It's not trivial to do, and I never managed to get bot-to-bot communication working. Even with my janky setup, the experience is honestly pretty great. Grok Bot simplifies the setup for this about as far as I imagine is possible, and frankly it's a pretty slick experience.
I fully expect this paradigm to catch on quickly.
> I never managed to get bot-to-bot communication working.
Were you attempting to get them to message amongst themselves over Telegram, or something different?
So this is a Hermes Agent plus a credential proxy it sounds like?
Here's some totally normal stuff that Grok’s owner has been posting recently:
* "Anyone who opposes remigration is a traitor"
* "She is a traitor to the West, plain and simple" (in reference to his recent interviewer)
* "Deal with traitors before invaders. They are committing high treason."
* "First the traitors, then the invaders" (screenshot from Citizen Vigilante pointing gun at camera)
Yes sirree: just a completely normal tech product without any asterisks.
Mighty big words from Musk, who is himself actually guilty of treason.
It's a great idea, but the problem is with the latest versions of Grok. It's like xAI copied Google's Gemini. Grok now minimizes its effort. Like Gemini "Pro", it's become a flash model that provides shallow answers quickly.
I am unsure if this is the end all be all but it appears preferable to claude code desktop to me.
they probably should kill the grok branding...
Dupe of https://news.ycombinator.com/item?id=49261532#49263241.
Dang - might be worth merging these two.
That one for some reason is [flagged]
I think perhaps I won't trust anything that ever gets released by this company, likely in perpetuity.
Anecdotally, same; recently I stopped using Cursor after learning that XAI now owns it.
There are two companies that have lost my trust, probably forever: X and Meta. I don't see myself ever trusting anything coming out of either of these companies ever again
Meta feels more like your traditional 'greedy corporation' that's fairly amoral and as a consequence ends up doing some bad things in pursuit of more profits.
The other one feels pretty explicitly evil at this point.
It should be studied how we reached a point where we trust more a Chinese company, that's well know for being state controlled, vs an American company because it seems they could do worse. Still no idea what "worse" it could do because we've reached the threshold where plague and cholera are intertwined and every possible outcome seems abusive.
Perhaps people are deciding that the impact a nefarious foreign government can have on them is less of a risk than their own government acting the same way. So Chinese should feel safer interacting with American companies and Americans safer interacting with Chinese companies.
That's probably bullshit.
Could also just be yet another wave of information warfare. I'm like 87.9% sure that bad actors explains nearly every aspect of this awful timeline we are on.
On a personal level, your own government can absolutely, 100% be more likely to do you harm than a foreign government, for simple jurisdictional reasons. They have more power over your life. And with an administration as corrupt and degenerate as the current US administration, it's an extremely reasonable perspective to have.
state controlled is much better than billionaire controlled. a lesson many haven't learned. yet.
aren't these the same thing?
When it comes to the World Economic Forum et al, they certainly are. Supposedly socialist administration structures can be eerily similar to the capitalist ones. Down to the committees, or the consultative groups which are steered/controlled by certain individuals for their own ends, and the appeal to the public to gaslight them into thinking they backed whatever all along.
Both are top down structures that disenfranchise common people.
This seems like a very clever product move from X.ai
I wonder if they're going to try and compete against Slack with X.com chat?
in case you are interested in ~this for your team, but dont want to either be vendor-locked to grok or give mecha-hitler extra money, consider trying what we've been building at https://noriagentic.com/ (or any of the other startups working in the same space)
I'm a little baffled by this, it's basically like the remote Claude instances I already use every day except it has absolutely no safeguards? If I wanted to make a claude could post to linkedin it would be like one prompt to spin that with playwright. Like you can just have persistent Claude code sessions, if you aren't cost sensitive you can just keep restarting the session whenever.
They're clearly targeting less technical users but in exchange are asking you to upload every login you have to Elon's servers which is an insane thing to do imo. What a world where people are giving their Instagram sign in to the bot formerly known as mechahitler.