
PixelsTech
3.8K posts

PixelsTech
@PixelstechNet
A place for programmers 程序员自留地






China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.







阿里对此高度重视,连夜成立了“统一口径与情绪降噪专项工作小组”,后查明林某此次推特发帖辞职,反映出其仍停留在“把公司当家、把模型当娃、把离职当朋友圈”的认知阶段。公司对此深表遗憾,并已提醒相关同学:真正成熟的职场人,告别都应该先走流程,再走感情。 -坚决杜绝“个人账号先于组织公告”现象再次发 -持续坚持开源开放不动摇,但个人心情不得先于集团节奏开 目前,相关业务运转正常,模型训练正常,参数收敛正常,同事表情管理总体正常。公司将继续本着“事要解决、话要统一、人要体面、网要安静”的原则,妥善做好后续工作。





