360 旗下 OpenClaw 助手安装包泄露 SSL 私钥,周鸿祎此前曾承诺“绝不泄露密码”

BitPush
Mar 16

比推消息, 安全研究员 Lukasz Olejnik 在 X 平台发文表示,360 推出的 AI OpenClaw 助手“360 安全龙虾”在安装包中泄露了 SSL 私钥。该私钥对应域名为*.myclaw.360.cn,有效期至 2027 年 4 月。攻击者可利用该私钥冒充 360 服务器、拦截用户流量或伪造登录页面。此前 360 创始人周鸿祎曾在推出该产品时承诺“绝不泄露密码”。值得一提的是,目前 360 拥有 4.61 亿用户,公司估值约 100 亿美元。该消息也得到了部分中文区开发者的佐证。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10