Grok Bot

(x.ai)

291 points | by rvz 17 hours ago ago

104 comments

  • agnosticmantis an hour ago

    We need more and stronger open source/weight models considering how deeply and intimately these bots are going to be integrated in our lives.

    I hope that Dario Amodei fails in his quest to regulate open models out of existence to line his pocket under the guise of safety. Amodei/anthropic will end up being the most harmful force in the next few decades where progress in AI is concerned.

    I hope people realize sooner than later that this is a replay of early Microsoft vs open source situation and Amodei is the new Gates on a crusade against open source/Linux.

  • anthonyskipper 12 hours ago

    The scariest part of the interaction is the first video at https://x.ai/bot where the bot just snags your creds from the browser and takes over. So many people are going to give x all their data and creds.

    • roughly 4 hours ago

      The world ends not with a bang, but with a “you’re right, I shouldn’t have done that. It’s right there in my agents.md file.”

    • miguelspizza 3 hours ago

      AI Session Hijacking is such a dead end and I think this will be the thing that kills it. Just register these things in the IDP and let them sign into their own accounts.

      Maybe if we give these things their own identity people will stop letting their AIs post as them in linkedin

      • 0x3f 3 hours ago

        > Just register these things in the IDP and let them sign into their own accounts.

        And when you get blocked by whatever anti-bot tech the site is running?

        • miguelspizza 3 hours ago

          Not sure I understand the point your are making. how is this unique for bots with their own identity? Bots hijacking a user session can also be blocked

          • ACCount37 an hour ago

            Bots skinwalking their users inherit the behavioral scoring of that user. As a rule, they'll take a lot longer to get blocked than new bot accounts would.

      • ares623 3 hours ago

        But then whoever added them to the IDP becomes accountable for what the bots do.

        By hijacking a real person's credentials, that person becomes the accountability sink. Very neat. Very deliberate.

    • kylecazar 11 hours ago

      I assume they store your session state/token for whatever SaaS it needs to work with but not the creds.

      • bakies 10 hours ago

        Many people assumed they didnt upload your whole home dir when you launched their IDE

        • solid_fuel 9 hours ago

          Yeah, assuming that X is doing the honest and well-behaved thing is a mistake given their past actions.

    • xyzsparetimexyz an hour ago

      it's crazy that we have multi-user computers and all this permission stuff on linux and none of it is used

    • edoceo 11 hours ago

      What? How? Just the x.com creds or other ones too?

    • nozzlegear 7 hours ago

      Well, it's the "Everything App" after all!

      /s

  • XCSme 12 hours ago

    The eternal fight between bots and anti-bot systems.

    The difference now is that big companies themselves promote/offer bots, but they also don't like to be scraped and use captchas.

    What do we do now? Is it allowed to use automated tools to interact with any system? Is it allowed to scrape data? Are there any laws for this?

    If we do things manually it is ok, but not if we use a bot?

    Confusing (legal) times...

    • akersten 12 hours ago

      > Is it allowed to use automated tools to interact with any system?

      I'd hope so, because that's what we're doing right now. Your browser is automatically speaking HTTP for you so that you don't have to.

      Am I having a bit of a laugh? Maybe. But really, services should be user-agent agnostic. That's the whole "agent" part of User Agent and the founders of the Internet had incredible foresight to name it this way.

      > Is it allowed to scrape data?

      You mean, request data and receive what the other server voluntarily transmits?

      > Are there any laws for this?

      There was a court case that said the above is fine, thankfully, since that's how the internet works. There's probably other cases going on and I'm sure at least one of them will have some unfortunate tech-illiterate result that makes things worse for anyone who understands this stuff.

      • userbinator 4 hours ago

        That's the whole "agent" part of User Agent and the founders of the Internet had incredible foresight to name it this way.

        Now it's the Agentic User Agent.

      • akoboldfrying 11 hours ago

        > request data and receive what the other server voluntarily transmits?

        Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.

        In many cases, what the other server voluntarily transmits has so far been based on the tacit assumption that a person, with person-level time and computational power, is doing the receiving. While in principle a machine could be doing it even in pre-LLM times, in practice many websites, including all the biggest ones, have implemented a wide range of approaches to try to curb machine access, starting with user agent checks and rate limits but by no means ending there.

        The question is: Given the new landscape, where this assumption increasingly does not hold (because AI agents are increasingly able to simulate anything a person could do online), would those servers voluntarily transmit that data? In many cases, the answer is no.

        • akersten 9 hours ago

          > Taking your position to its logical conclusion implies that we shouldn't try to mitigate DDoSes either.

          Not really. At any time you can, and should, choose not to reply to traffic that is wasting your bandwidth - ban IPs, use DDOS mitigation services, etc. My position is simply that regulation doesn't belong in this space, and it's ok for the 'net to be a dog eat dog world. Kind of what keeps technology advancing and exciting.

          • akoboldfrying 8 hours ago

            But who decides what comprises "wasting [my] bandwidth"? This is subjective.

            Is it me (the site owner in this example)? If so: Since it's my subjective decision to make, couldn't I equally legitimately decide that traffic I serve to non-human entities is "wasting my bandwidth"?

            To be clear, I'm not trying to make the case that there should be some law in place that prevents scraping or machine access across the board -- only that it would make sense for website operators to be able, optionally, to include that kind of usage restriction in an ordinary contract and legally enforce it by the usual means (lawsuits), in addition to any kind of technical restrictions they are able to put in place.

            • lelandbatey 7 hours ago

              Yes, you e always been able to do this, as long as you get an actual contract that's enforceable.

              The thing about most sites is they're public and you don't need to sign a real contract to use them. Can't have it both ways.

      • XCSme 11 hours ago

        > Your browser is automatically speaking HTTP for you so that you don't have to.

        Yes, but it's not filling in the forms or clicking the buttons for me. HTTP is just infrastructure. Are LLMs infrastructure? Are we too maybe infrastructure? Where do we draw the line?

        > You mean, request data and receive what the other server voluntarily transmits?

        I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.

        Regarding scraping, considering that this whole AI phase was built on illegal scraping, I don't think they can say anything now...

        • akersten 9 hours ago

          > I mean to go over a large collection of publicly or privately (to you) available pages and parse and collect the data, with idea of using it in other purposes.

          I've always called that "learning" but I guess it's called something else when a robot does it :)

          • sebastiennight 4 hours ago

            ... The same way I might call something "gardening" or "weeding" when I do it, but for some reason, environmentalists call it "destroying the Amazon rainforest" when bulldozers do it to 27,000 km2 of vegetation in a year.

  • dylanhouli 11 hours ago

    I feel like we'd be better off if we just stopped at chatbots...why are we so eager to make the internet even more botted

    • redox99 9 hours ago

      The internet sucks. Yesterday, I had my agent search for openings for The Odyssey that fit my requirements and then book them. It was way better than manually looking at seat maps for 20 different showtimes and going through 10 steps just to buy the tickets.

      • werdnapk 8 hours ago

        So why didn't you just do it manually? Why use an agent in the first place?

        • theshrike79 2 hours ago

          The monopoly movie chain in my country "updated" their pages to be "better".

          Now it's so bad that some chad created their own overlay for the site where you can actually see all the showtimes for a specific movie on a single page instead of having to click through 42 different showings one by one.

        • Gareth321 3 hours ago

          Poor UX. The internet used to be designed around ease of use. Now it's dark patterns, advertising, nag windows, and "engagement." Retailers don't offer a way to aggregate info easily, so it means wading through piles of shit to find relevant information. Bots can eliminate all the shitty parts about using the internet. That's a big time saver, but it's also a big headache saver.

        • throw-the-towel 7 hours ago

          Because doing it manually sucks? Every website shoves a different bunch of dark patterns in your face, everything is buggy, nobody ever thinks about UX.

    • seattle_spring 11 hours ago

      Yeah I'm a bit baffled too... the world is so, so much worse now because of AI.

      More scams/spam, lower quality software everywhere, development is no longer fun, many interactions with coworkers are just "have my people talk to your people" behind the scenes, except it's "have my LLM read the huge document your LLM generated". Every business is trying to cut corners by using AI, so customer service sucks, products suck, prices are optimized to be the absolute maximum people will pay regardless of the actual value being provided (including food)...

  • stillpointlab 7 hours ago

    This is obviously the future, where this will all end up. But just like when I saw the demos for Google's "AI build the interface dynamically", I wonder how much of the demo actually translates to real usage.

    One thing that this highlights for me even more than before is that having accounts for my bots is what I really want. I want SaaS providers to catch up to bot use. They need their own accounts on a lot of these services and per-seat pricing works against this.

    • ralph84 4 hours ago

      How does per-seat pricing work against bots? If anything it's a great deal because SaaS providers set per-seat pricing with the expectation that on average most seats are idle. Bots working 24x7 can get a lot more value out of a seat than humans working 9-5.

      • stillpointlab 4 hours ago

        I just mean for me as a solo dev I guess. For example, github gives 2 users as part of a basic org and charges extra per seat, so if I want seats for individual agents so I can track them separately then I have to pay more. Same with Google Workspace, where I have to pay for additional users if I want to have multiple accounts.

        As an example, I wanted to set up users in AWS identity center so I can give view only access to bots for my infrastructure, but that requires different email addresses. I set up an alias on my existing user so I didn't have to do that, but ideally I could have accounts for agent1 and agent2.

        I can usually find workarounds like this but I feel I shouldn't have to. I don't want the agents to share my permissions in general since I'm often the admin. I want to give them limited scopes whenever possible.

        edit: for reference, a Google Workspace user is ~220CAD/year and a github user is ~50USD/year. That is quite expensive if I want to add a couple of agents (well over 500CAD/year).

      • bulder 3 hours ago

        Presumably it'll either mean selling "agent seats", or billing seats for every started hour of use. With a monthly minimum, of course.

  • drop_star 12 hours ago

    So OpenClaw that steals your data and profiles you for the US gov. No thanks.

    • notatoad 9 hours ago

      yeah, it really feels like the economics of AI are going to settle on trust - who do you trust to act on your behalf, because that's where the real value comes in.

      and at the same time, it feels like all the AI companies - not just elon - are doing everything they can to burn trust.

    • narrator 11 hours ago

      A tool that only people who trust Elon can use.

      • netsharc 11 hours ago

        Elon wanted X to be a universal app like WeChat. Communication, payment, government services (and probably one-shop stop for user surveillance)... Wahey, looking forward to Grokbot telling its users "we logged in to your bank account and moved all your money to BankX, it's got the best interest rate!"

        • m463 10 hours ago

          I wonder what grok "unhinged" would do to your social calendar/bank account.

  • whimsicalism 12 hours ago

    How do they stop providers (like Amazon, etc.) from detecting and blocking these agents if they are running on cloud? I know that openai wasn't able to avoid this which is why they moved to 'computer use' on your local machine.

    I almost wonder if this is a place where SpaceX, as an internet provider through starlink, has a unique advantage because websites are unable to block their networking as it could be residential starlink consumers.

    • therealdrag0 6 hours ago

      I use Hermes locally and it’s constantly hitting bot blocks. Just trying to shop clothes for me it gets blocked.

    • theplumber 12 hours ago

      I think it creates a loop back connection, basically a reverse socks5 or a VPN if they are more sophisticated. That’s how I would do it. Note that I am also working on a such bot/AI os and mine is better (for now) . If you have trillions, billions to or millions to invest feel free to reach out.

      • whimsicalism 11 hours ago

        This would imply you need to have your computer on in order for it to function, which seems like a deal breaker for many consumer usecases imo. I'd like to be able to say "order my groceries" and then I hop on the subway.

        • edot 11 hours ago

          Not a big deal at all. Claude Code and Codex both support keeping your computer awake. That'll just be a default thing that gets turned on when you install one of these apps.

          • whimsicalism 10 hours ago

            i just completely disagree. lots of people don't even have laptops and how will they keep my laptop alive and performing tasks while it's in my backpack on the subway not connected to internet?

            i feel like there's an obvious advantage if your agent can work truly in the background

            • s900mhz 6 hours ago

              I agree, but I made myself laugh pondering a solution to this in which I came up with a Raspberry Pi like device that acts as the loopback for the agent. Always keep it on and plugged in.

              I would like to introduce the Grok Box

              • whimsicalism 5 hours ago

                I actually have set up something similar myself and it is much easier now that codex desktop for linux just came out (which has computer use/browser driving abilities). The issue is that on an rpi, I have to usually manually log into everything once.

  • wiradikusuma 15 hours ago

    From FAQ: How is Grok Bot different from AI assistants? Bots have their own computer, so they can work inside your apps and tools. They also run in parallel, 24/7, even when your laptop is closed.

    How does it work with login-walled sites like LinkedIn then? And what does "own computer" mean? X provisions a "private cloud" a'la Apple for your Bot?

    • VariousPrograms 15 hours ago

      The very first thing in their demo shows Grok logging in with the user's username and password to a website, presumably so it can perform actions and the human can get the blame for them. Apparently this is marketing and not terrifying to people.

    • jjcm 15 hours ago

      It'll ask you to take over its computer to log in:

      https://image.non.io/4022ec77-be07-4baa-97e8-ad9d8d9aeb8a.we...

      After you do you just tell the bot you're done logging in and it'll keep driving. And yea, it's a separate VM for each bot.

      Source: had access for the last few weeks.

    • ryanmerket 4 hours ago

      dont forget the "Elon-Only Settings" makes it different too https://runtimewire.com/article/grok-bot-s-hidden-elon-only-...

    • bakies 10 hours ago

      How my bots do it is chrome dev tools or puppeteer or w/e. I've got chrome vnc (for monitoring) and headless X in the container with them. Works pretty flawlessly.

  • damsta 2 hours ago

    Does it have access to X API? One limitation in CC, Codex etc. is that they don't have access to X which sometimes has an answer not available via their search providers.

  • blahblaher 3 hours ago

    don't use the hitler bot please and thank you.

  • impulser_ 8 hours ago

    The problem these model providers have now is there software is basically useless.

    Tell me one reason why I would use this at my company? I basically have to bet on Grok being the best models for this.

    Or I can use an open source version and use whatever model I want.

    You see this with coding agents, everyone used Claude Code and then realized holy shit this is expensive and now use open source agents and they can use open source models and cut costs.

    • stillpointlab 7 hours ago

      One advantage of code over many other use cases is that github is often the source of truth, so whatever is in Claude Code or Codex is ultimately replaceable.

      It's for this reason I am bullish on text formats in general. Or maybe sqlite wrappers where databases are necessary. But I want a separation between the worker and the work through some data contract that allows me to easily move my stuff around.

    • dmix 8 hours ago

      > Tell me one reason why I would use this at my company?

      I believe the selling point here is these run on their own VMs, so you don't need to set up your own harnesses, models, and security infrastructure to run agents.

      Historically people tend to pay for single-click commercial solutions for complex technical set ups like that.

      • impulser_ 4 hours ago

        I was talking about why would I use a Grok specific version of this instead of one that I can switch models.

        What if Grok models become horrible or they increase the pricing of the subscriptions now you have to migrate off. Instead you could just use the open source version that allows you to choose your providers and switch cost is just the time to switch those providers.

      • smoke4sanity 5 hours ago

        I assume he meant an actual use case. Its architecture alone is not a reason to use it.

  • kerv 12 hours ago

    Are there any opensource app/system that directly competes with a solution like this?

    • mellosouls 4 hours ago

      Grokbot is another derivative of open source originals like Open Claw

      https://en.wikipedia.org/wiki/OpenClaw

    • lukebuehler 12 hours ago

      Im working on one here: https://github.com/smartcomputer-ai/lightspeed

      The core is there. But there is some work to be done to have a nicer shell and all, which I’m currently focusing on.

      • redrove 7 hours ago

        Oh this looks very interesting, both for personal and work; I’ve been looking for something similar for quite a while.

        However, no OpenAI API support (just Anthropic + openai.com) means I can’t use it for either.

        • lukebuehler 38 minutes ago

          The OpenAI API style (completions) support is coming this week. Currently working on it.

    • blehn 12 hours ago
      • redrove 7 hours ago

        I’ve tried using this as a self hosted instance and it’s been a little rough around the edges with Hermes.

    • kanwisher an hour ago

      openclaw and hermes

  • wraptile 4 hours ago

    I used to think if all else fails I'd take the path of a Cynic and retire in a giant vase. I'm not quite sure anymore. If you're done with society and the world you might as well prompt inject from a beach somewhere, and we're so not ready for this.

  • mrtksn 12 hours ago

    Interesting how everyone seems to be following OpenAI on UX. When I used Antigravity and they suddenly switched to Codex type UI I was very annoyed because I kept checking if this is Codex or Antigravity.

    Either way, I still don't think that computer use is solved. It worked horribly on Codex and Antigravity the last time I tried. Maybe I was doing something wrong.

    • leerob 9 hours ago

      It's quite a bit different, namely that ChatGPT Work has both local conversations and cloud agents. But for each cloud agent, you are spinning up and tearing down a new VM each time. This is an always-on Linux box, which stays logged in. Additionally, your bots can talk to each other (although Codex did have the ability to reference threads, I am not sure if one thread could send messages to other threads).

    • redox99 9 hours ago

      Computer use will suck until we get 500+ tk/s

  • jujube3 13 hours ago

    Grok lobster! (Rock lobster music starts playing)

  • madebywelch 6 hours ago

    My initial impression is strong: Agent-to-Agent comms are clearly a first-class citizen of this tech. There's a cohesion that's palpable. Maybe it just fits my workflow better than other tools. I have some routines set up for tomorrow morning that will tell me if the juice is worth the squeeze.

    48% weekly usage left after 3 hours of experimenting, tough.

    • Pungsnigel 3 hours ago

      What plan are you on? Does the bot have its own usage, or does it count against cursor/grok code usage?

  • arjie 8 hours ago

    This looks amazing. Lots of good ideas here. The human in the loop story is quite good here. I will shamelessly lift it for myself.

  • virgildotcodes 3 hours ago

    This is basically openclaw with browser access, or am I missing something?

  • rw2 2 hours ago

    how does this compare to Hermes which is much cheaper?

  • johndhi 10 hours ago

    Do you have to pay the companies for a second login for the bot...?

  • indigodaddy 8 hours ago

    This seems like a disaster waiting to happen

  • h14h 12 hours ago

    I've already been doing something very similar to this with OpenClaw, where I set up multiple different Telegram bots each with different system prompts to tune their personalty & behavior.

    It's not trivial to do, and I never managed to get bot-to-bot communication working. Even with my janky setup, the experience is honestly pretty great. Grok Bot simplifies the setup for this about as far as I imagine is possible, and frankly it's a pretty slick experience.

    I fully expect this paradigm to catch on quickly.

    • CGamesPlay 8 hours ago

      > I never managed to get bot-to-bot communication working.

      Were you attempting to get them to message amongst themselves over Telegram, or something different?

  • ls612 7 hours ago

    So this is a Hermes Agent plus a credential proxy it sounds like?

  • chaostheory 6 hours ago

    It's a great idea, but the problem is with the latest versions of Grok. It's like xAI copied Google's Gemini. Grok now minimizes its effort. Like Gemini "Pro", it's become a flash model that provides shallow answers quickly.

  • archagon 3 hours ago

    Here's some totally normal stuff that Grok’s owner has been posting recently:

    * "Anyone who opposes remigration is a traitor"

    * "She is a traitor to the West, plain and simple" (in reference to his recent interviewer)

    * "Deal with traitors before invaders. They are committing high treason."

    * "First the traitors, then the invaders" (screenshot from Citizen Vigilante pointing gun at camera)

    Yes sirree: just a completely normal tech product without any asterisks.

    • solid_fuel an hour ago

      Mighty big words from Musk, who is himself actually guilty of treason.

  • Computer0 13 hours ago

    I am unsure if this is the end all be all but it appears preferable to claude code desktop to me.

  • c0rruptbytes 10 hours ago

    they probably should kill the grok branding...

  • jjcm 15 hours ago

    Dupe of https://news.ycombinator.com/item?id=49261532#49263241.

    Dang - might be worth merging these two.

    • redox99 13 hours ago

      That one for some reason is [flagged]

  • jesse_dot_id 13 hours ago

    I think perhaps I won't trust anything that ever gets released by this company, likely in perpetuity.

    • thih9 12 hours ago

      Anecdotally, same; recently I stopped using Cursor after learning that XAI now owns it.

    • agile-gift0262 13 hours ago

      There are two companies that have lost my trust, probably forever: X and Meta. I don't see myself ever trusting anything coming out of either of these companies ever again

      • davidw 8 hours ago

        Meta feels more like your traditional 'greedy corporation' that's fairly amoral and as a consequence ends up doing some bad things in pursuit of more profits.

        The other one feels pretty explicitly evil at this point.

    • whynotmaybe 12 hours ago

      It should be studied how we reached a point where we trust more a Chinese company, that's well know for being state controlled, vs an American company because it seems they could do worse. Still no idea what "worse" it could do because we've reached the threshold where plague and cholera are intertwined and every possible outcome seems abusive.

      • rootusrootus 6 hours ago

        Perhaps people are deciding that the impact a nefarious foreign government can have on them is less of a risk than their own government acting the same way. So Chinese should feel safer interacting with American companies and Americans safer interacting with Chinese companies.

        That's probably bullshit.

        Could also just be yet another wave of information warfare. I'm like 87.9% sure that bad actors explains nearly every aspect of this awful timeline we are on.

        • sigmarule 6 hours ago

          On a personal level, your own government can absolutely, 100% be more likely to do you harm than a foreign government, for simple jurisdictional reasons. They have more power over your life. And with an administration as corrupt and degenerate as the current US administration, it's an extremely reasonable perspective to have.

      • gverrilla 7 hours ago

        state controlled is much better than billionaire controlled. a lesson many haven't learned. yet.

        • tristanMatthias 5 hours ago

          aren't these the same thing?

          • nephihaha an hour ago

            When it comes to the World Economic Forum et al, they certainly are. Supposedly socialist administration structures can be eerily similar to the capitalist ones. Down to the committees, or the consultative groups which are steered/controlled by certain individuals for their own ends, and the appeal to the public to gaslight them into thinking they backed whatever all along.

            Both are top down structures that disenfranchise common people.

  • surprisetalk 15 hours ago

    This seems like a very clever product move from X.ai

    I wonder if they're going to try and compete against Slack with X.com chat?

  • WillMorr 11 hours ago

    I'm a little baffled by this, it's basically like the remote Claude instances I already use every day except it has absolutely no safeguards? If I wanted to make a claude could post to linkedin it would be like one prompt to spin that with playwright. Like you can just have persistent Claude code sessions, if you aren't cost sensitive you can just keep restarting the session whenever.

    They're clearly targeting less technical users but in exchange are asking you to upload every login you have to Elon's servers which is an insane thing to do imo. What a world where people are giving their Instagram sign in to the bot formerly known as mechahitler.

  • theahura 8 hours ago

    in case you are interested in ~this for your team, but dont want to either be vendor-locked to grok or give mecha-hitler extra money, consider trying what we've been building at https://noriagentic.com/ (or any of the other startups working in the same space)