<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Kevin Wu: Quiet CISO]]></title><description><![CDATA[Cybersecurity insights from the field. A practitioner's view from Shanghai, China.]]></description><link>https://www.kwu.sg/s/quiet-ciso</link><image><url>https://substackcdn.com/image/fetch/$s_!wDVN!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08e65c85-57ce-4aa2-8c39-d6cf2549f31c_500x500.png</url><title>Kevin Wu: Quiet CISO</title><link>https://www.kwu.sg/s/quiet-ciso</link></image><generator>Substack</generator><lastBuildDate>Sun, 12 Apr 2026 06:15:48 GMT</lastBuildDate><atom:link href="https://www.kwu.sg/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kevin Wu]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[kwusg@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[kwusg@substack.com]]></itunes:email><itunes:name><![CDATA[Kevin Wu]]></itunes:name></itunes:owner><itunes:author><![CDATA[Kevin Wu]]></itunes:author><googleplay:owner><![CDATA[kwusg@substack.com]]></googleplay:owner><googleplay:email><![CDATA[kwusg@substack.com]]></googleplay:email><googleplay:author><![CDATA[Kevin Wu]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Raising Lobsters 🦞]]></title><description><![CDATA[OpenClaw is here and everybody wants to raise a lobster in China.]]></description><link>https://www.kwu.sg/p/raising-lobsters</link><guid isPermaLink="false">https://www.kwu.sg/p/raising-lobsters</guid><dc:creator><![CDATA[Kevin Wu]]></dc:creator><pubDate>Fri, 13 Mar 2026 08:07:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wDVN!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08e65c85-57ce-4aa2-8c39-d6cf2549f31c_500x500.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!txOS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!txOS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 424w, https://substackcdn.com/image/fetch/$s_!txOS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 848w, https://substackcdn.com/image/fetch/$s_!txOS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 1272w, https://substackcdn.com/image/fetch/$s_!txOS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!txOS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png" width="728" height="408.8767123287671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:287,&quot;width&quot;:511,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:282820,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kwusg.substack.com/i/190794743?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!txOS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 424w, https://substackcdn.com/image/fetch/$s_!txOS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 848w, https://substackcdn.com/image/fetch/$s_!txOS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 1272w, https://substackcdn.com/image/fetch/$s_!txOS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71123f87-d2a6-487b-8062-84fcee5d0a44_511x287.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image is AI generated. The writing is not, this is KI, Kev Intelligence.</figcaption></figure></div><p>I have Jamiroquai&#8217;s Virtual Insanity playing in the background as I write this. Feels appropriate. Nowadays it&#8217;s AI this and AI that. Aiyoh!</p><p>The latest hype is none other than our agentic bot friend, OpenClaw. Or maybe Fiend, since it never sleeps, never complains, and is coming for our jobs. OpenClaw is so hyped that the Chinese Internet gave it a nickname &#8220;Lobster&#8221;.</p><p>Cloud platforms are rushing to offer OpenClaw as a service. Thousands of people, young and old lined up outside Tencent headquarters in Shenzhen to have it installed on their laptops. You read it right, people are queuing up to install Lobster, not to buy Labubus. Amazing times! And just like that a new trend was born, &#8220;Raising Lobsters&#8221;. Everybody wants to raise a lobster!</p><p>Because of FOMO, I had to try and see it for myself. I did not want to buy a Mac Mini just to raise one, so I opted to deploy OpenClaw on a virtual server. I used the Alibaba Cloud one-click deployment on a Simple Application Server (because why not?). Default settings throughout, exactly as most users would do it.</p><p>The result surprised me. Not because OpenClaw did not deliver, but because of what I found on the security side. There was ZERO security.</p><p>No authentication. API keys stored in plaintext. The web console sitting open on the public internet for anyone to find.</p><p>And this is our new bot friend who will be entrusted with access to our files and calendar, to execute tasks while we sleep. With the default settings, anyone can find and interact with the agent. Sounds like a nightmare.</p><p>Don&#8217;t get me wrong, AI is fantastic and agents are the future. But the speed at which things are moving can put us at serious risk if we&#8217;re not careful. </p><p>If you have OpenClaw running, here is what you should check right now:</p><ul><li><p>Make sure it&#8217;s not exposed to the public internet</p></li><li><p>Enable authentication</p></li><li><p>Change your API Keys, if your server was ever publicly accessible</p></li><li><p>Connect only what OpenClaw needs, start with the minimum, you can always add more later</p></li></ul><p>Spend some time securing the lobster before handing it the keys to your digital life. &#129302;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.kwu.sg/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>