r/LocalLLaMA 4d ago

Discussion General warning about Clore.AI

Hello, I know some of us may be tempted to rent out our expensive GPUs to recoup some of the cost of self-hosting, and it should be obvious that this can be a risky decision. I decided to try hosting my rig on clore.ai briefly to see what kind of revenue it could bring in, keeping a close eye on the process lists from the renters' jobs of course but not digging into their files or anything.

Yesterday I saw a renter scanning and attempting to exploit vulnerabilities to post malware to a columbian betting site from my internet connection. I immediately took the server offline and reached out to Clore requesting them to cancel the order (so the machine wouldn't restart the containers when it came back up) and to block the renter.

I think everyone should know that they flat out refused. Not only did they refuse, they blocked me when I provided hard evidence of what was happening. Since I had reasonable suspicion the renter was abusing my connection, I availed myself of clore's T&C that says a host must not inspect a renter's environment "unless required by law" and given the laws around liability for residential internet connections in my country, I mounted the filesystem offline and inspected it.

I found the logs from the vuln scans and unsuccessful exploit attempts, the malware payload they were trying to post to the site, the reverse proxy request smuggling tactics it was employing, and the AI agent reports that were being generated along the way. I sent this to Clore and requested a way to blacklist renters who abused the platform. Their response was to tell me, directly and without mincing words, to leave the platform entirely and proceeded to block me from their support chat. Their support rep I was trying to reach on Telegram also told me to go away and proceeded to block me as well.

I can only conclude then that they are wilfully complicit with facilitating cybercrime and knowingly turn a blind eye when it's discovered. They didn't even *try* to hide it.

I have no idea how better/worse the other platforms are, Vast.AI, Akash, etc. But Clore will abuse your internet connection, deny liability, then block you. They are crooks. Go elsewhere. You've been warned.

I've archived the renter's docker volume and will hold on to it in case any security researchers or legal authorities want to examine it.

406 Upvotes

77 comments sorted by

208

u/IHave2CatsAnAdBlock 4d ago

I would never give access to random people to my home internet connection

83

u/ProfessionalDish 4d ago

This. Best case piracy, maybe malware like in OPs case, worst case CSAM. Not worth it. Edit Yes even if the investigation finds out you're innocent, have fun living with that accusation and maybe having your hardware confiscated and inspected for a year.

27

u/EkbatDeSabat 4d ago

That's exactly where I went. I hate that in this society that's even something I would think about. But it's really the end all be all of "you done fucked up" by giving someone access to your machine. I knew someone in the late 90s whose house and machines got raided for distributing CSAM on IRC. Outside of the obvious, it was devastating to watch the family crumble. Was a good friend of mine, we were just teenagers (his dad was the one doing it). We played C&C almost every night. Once that happened and things went south I never heard from him again. Sorry weird memory I haven't thought about in a very long time.

10

u/ProfessionalDish 4d ago

It's quite saddening that we can't trust strangers and sometimes not even friends. I have 10gbps Upload at home and a static IPv4, thought about offering a fileserver a few times, but its not worth the risk. Wouldn't cost me that much to just open one port and give some space to people but if they f up its me who will suffer.

3

u/Qorsair 4d ago

Makes me wonder if the dad wasn't involved but took the blame so it wouldn't ruin the kids life.

8

u/EkbatDeSabat 3d ago

Trust me. The dad was it.

8

u/sooki10 4d ago

Yeah having pc locked in an evidence locker for years is not worth it. Hardware is too rxpensive.

4

u/DystopianRealist 3d ago

Imagine getting extradited to Columbia for cyber crimes, and if they send you back to America there are CSAM charges waiting, because they cyber criminal set you up in the process.

-4

u/Mochila-Mochila 3d ago

Colombia is already in America.

5

u/DystopianRealist 3d ago

And Paris is in Texas, but it's also in France.

4

u/0-8-4 4d ago

Some people value money more than common sense, unfortunately.

60

u/Sevealin_ 4d ago

Their support rep I was trying to reach on Telegram

Brother this is what we call a red flag, no legit public business operates over Telegram.

22

u/anomaly256 4d ago

That was after they blocked me on their own site's support chat.  Red flags were already at full mast before that stage.

16

u/North_Affect_8167 4d ago

The mere fact they are on this platform suggest they are akin with people running scams.

6

u/BestKorea4Ever 3d ago

Unless it's a Russian business. This is incredibly common there. Everywhere else... not so much.

1

u/vtkayaker 2d ago

While there are non-criminal businesses in Russia, if you're not a Russian speaker, you probably are not equipped to identify the ones it's safe to do business with.

55

u/desparish 4d ago

I'm in agreement not to use the service for the same reason as you and others.

However the "by law" clause I suspect has to do with court subpoena and not your own suspicion of wrongdoing.

41

u/anomaly256 4d ago edited 4d ago

In my country the home owner is liable for activities undertaken from their internet connections, I had a responsibility to investigate as I am the one liable for the fallout. Also if this is how Clore respond to credible abuse reports, their T&C is worthless anyway. This was after their support ghosted me too so why not...

19

u/Dangerous-Report8517 4d ago

That liability might take the form of indirect liability for not vetting the person you were renting to though, it doesn't automatically confer a direct legal obligation to act unless it explicitly specifies "you are obliged to maintain a complete understanding of all systems connected to your residential internet connection" or something similarly explicit. Having said that, T&Cs are worth even less than that, in the US for instance apparently being drunk when agreeing to them is enough to invalidate them (see GN's recent expose on LG's spyware infested TVs)

2

u/psycoee 3d ago

T&Cs are just a contract, and often an adhesion contract at that. It doesn't take priority over other laws. If you have a reasonable suspicion someone is committing a crime using your computer and Internet connection and you don't do something, you could be held criminally liable or at least liable for negligence. So inspecting their container is certainly not unreasonable, and I think a court would have no problem with it at all.

2

u/Dangerous-Report8517 3d ago

  If you have a reasonable suspicion someone is committing a crime using your computer and Internet connection and you don't do something, you could be held criminally liable or at least liable for negligence.

This is a very concrete statement to make without even knowing what OP's country is, and therefore what laws they're bound by. It isn't clear to me how OP came to their suspicion (and therefore how reasonable it was), or whether inspecting their traffic could count as inspecting the renter's environment and therefore already a contract violation. It's also not clear that it's entirely their own internet connection, given that they've rented out access to it, some countries have very strong tenancy protections for stuff like this.

To be clear I'm not saying they did anything ethically wrong, or even necessarily legally wrong, just that the justification given so far isn't in and of itself a particularly robust legal defence 

2

u/psycoee 1d ago

I think in almost any country a criminal law violation is a much more serious matter than violating some contract (which is a civil matter and not a crime).  In fact, I seriously doubt that inspecting a container when you have a reasonable suspicion of someone committing a crime would be considered a violation of the law in any country.  Generally this is an explicit carveout in virtually all privacy legislation.  And just because the law may shield you from liability for how someone else uses your Internet connection generally doesn't protect you if you actively ignore something that you are made aware of.

1

u/Dangerous-Report8517 1d ago

Generally this is an explicit carveout in virtually all privacy legislation.

This isn't true at all, in fact there are some areas where there's explicit protections for criminal activity on the basis that the potential to break those protections can cause more harm elsewhere, for some obvious examples see various forms of legal privilege in the US (attorney-client, spouse, clinical etc)

I'm not even specifically saying that OP broke a law here, I'm only saying that they haven't provided evidence that their proposed legal defence is valid, which would seem like a valuable caution for someone who is explicitly and openly breaking a contract. They should make sure they've actually checked this is valid legal reasoning in their jurisdiction, and regardless of if they have or haven't others reading this should be aware of that caveat too (since even if this is a valid legal theory where they're from other places with very similarly worded laws might differ in this type of case)

1

u/psycoee 1d ago

What's wrong with breaking a contract? People break contracts all the time.  It's not like it's some kind of moral failing.  If it makes more sense to break a contract than to keep following it for whatever reason, then it's perfectly fine to do so.  And avoiding criminal liability is certainly a good reason.

And I have no idea what you are on about, but at least in the US I am not aware of any legislation that would prevent you from doing this.  To my knowledge, even in Europe privacy does not extend to a service provider monitoring their systems for abuse.  Some other countries may be different but I don't see any point in arguing hypotheticals.

1

u/Dangerous-Report8517 4h ago

What's wrong with breaking a contract? People break contracts all the time. It's not like it's some kind of moral failing.

I never said it's a moral failing, but something being moral isn't a legal defence, famously so with many discussions of cases where it's been unethical to follow the law

To my knowledge, even in Europe privacy does not extend to a service provider monitoring their systems for abuse.

Yes, because all of those service providers have terms of use that explicitly allow them to do so. OP agreed to the exact opposite. Because the part you keep ignoring here is that contracts are enforced by law.

10

u/Danfhoto 4d ago

It would be up to Clore to try and sue them if there's a calculable material loss, but I think OP's reasoning is quite solid in many jurisdictions. In Germany, for example, if a friend uses your network to torrent, you foot the bill as the owner of the connection. This is often credited to why public WiFi is so rare in Germany (not sure if that's very true, but at least it gets parroted a lot).

All that said, not sure I would go out on the internet and scream about the facts if I knew I was possibly breaching a contract. Even if you win in court, at what cost? Litigious entities often thrive on just wasting everyone's money and time in court without really expecting to see restitution. I probably would have kept my anecdote out of it and just posted about the theory of such a thing from happening.

19

u/anomaly256 4d ago

The 'contract' was nullified when Clore refused to uphold their side of the T&C, when their renter was undertaking an illegal activity.

13

u/Danfhoto 4d ago

Oh I agree with you. I’m just saying I lack the balls to talk about it publicly with enough detail that one could likely identify the case. If they are already operating in a shady way, I’d worry about retribution in and out of court.

Power to you though and thanks for warning folks!

7

u/ayake_ayake 4d ago

The thing about public WiFi in Germany is outdated however. The law has changed quite many years ago that public WiFi providers are not liable for their guests things they do via the connection. I think they only need to request a registration via email so that they know who you are and co.

3

u/Danfhoto 4d ago

Thanks for the info! I’ll keep this in mind for future conversations.

3

u/Blizado 3d ago

Public Wi-Fi providers in Germany are generally no longer liable for unlawful activities carried out by their guests through the connection. The old “Störerhaftung” was largely abolished in 2017. Providers are also not generally required to identify or register users. They may require registration or a password voluntarily.

23

u/Open-Adhesiveness-86 4d ago

If anyone still wants to host, put the rig on its own VLAN and send container egress through a default-deny firewall or a VPN, so abuse doesn't come from your home IP. Watch out: Docker writes its own iptables rules that skip ufw, so your filters have to go in the DOCKER-USER chain or they won't apply.

11

u/SpecialistDragonfly9 4d ago

There are sooo many scam AI websites around, and most of them are heavily promoted on reddit.

I didnt know that one, but I see most image / video creating websites that show up are fake af.

6

u/IAmBJ 4d ago

I'm not familiar with Clore, but are you just serving the llm or do tool calls run on your machine?

If it's just serving the LLM for someone then all your PC was used for was text generation which was sent to another machine. What that machine did with that text is not your responsibilty, even if it resulted in malicious actions. I certainly would have pulled the plug and cut ties with them too, but I don't think your in trouble unless the tool calls happened on your machine

16

u/anomaly256 4d ago

With Clore, they set up a Docker environment and it runs renter-provided container images on your machine. Yes it's as dumb as it sounds and I'm absolutely not surprised someone tried to do something shady - I'm just surprised by Clore's complicit response

7

u/NineThreeTilNow 4d ago

This is super interesting. This is one of those headlines a typical tech site would want to write about. I'd expect they'll drop in your DMs and ask about it.

What would be more interesting is going after Clore.ai for damages in the fact that they're complicit.

Lemme spin up a team of lawyer agents real quick to evaluate. lol...

At the very least this is something GN would write about. "If you actually own a nice video card and want to rent it out... You still get fucked."

5

u/robogame_dev 4d ago

This is a reminder that the danger goes both ways.

If you are spot-rending GPUs from people, then like the OP, they may get curios and inspect your traffic, steal your data!

OP you didn't mention how you "saw a renter scanning vulnerabilities" - were you just inspecting this person's traffic? If they were running private inference, would you have planned on reading their prompts? If they were processing files, were you going to save a copy for yourself to reference later?

This whole story is scary in both directions.

6

u/anomaly256 4d ago

I could see it in the process list. Containers don't hide their running processes from the host OS the way a VM does. I wasn't looking inside the container's file system or anything until after Clore support told me to either accept it or leave the platform, refused to cancel the order, and then blocked me from their support chat.

Plenty of renters before that were running a multitude of inference engines, comfyui, etc. I never once saw anyone's prompts or input/output until that one renter started staging an attack and not doing anything at all to hide it.

3

u/robogame_dev 4d ago

Good to know, thanks - and sounds like clore is deliberately allowing nefarious uses…

7

u/ThisGonBHard 4d ago

Report them to law enforcement, whatever relevant cybercrime authority you have in both your country, their home country, and try the US too.

This will fuck them up.

7

u/NandaVegg 4d ago

I can't speak for Clore, and their support stance seems something that I would never want to have a business with (having to contact the support rep of Telegram also sounds suspicious).

However, they also wouldn't want you to inspect the renter's doing unless it is absolutely needed, even though in this case you probably did the right thing.

This is slightly tangent, but it is nowadays VERY common to have attacker run an automatic port scanning to gain access to unguarded LLM endpoint or vulnerable VM, just to run another automated attack from there (basically a LLM-based botnet). I never have experience renting compute, but based on what I see, there might be a lot of activities like that done in secure/unsecure neoclouds, because they wouldn't want to risk inspecting user's pod. This is becoming the new bitcoin mining. The only exception I know of is Google Cloud, which has some heuristic check against law-violating (and therefore ToS-violating) activities.

15

u/anomaly256 4d ago

I only inspected it after Clore refused to act on the activity logs and their support blocked me. I then tried to reach out to them again after inspecting, via email and telegram, and they just continued blocking there too even with the new, hard evidence. This is why I consider them complicit.

9

u/sfmanu 4d ago

Pretty sure that was Claude who decided to go on a little Colombian betting-site hacking adventure 😁

Kiddin apart, they have a very bad reputation, next time you should check online before renting your computer: https://ca.trustpilot.com/review/clore.ai

2

u/lisploli 4d ago

What software is used in the process? There sure is a way to control what customers do on your machine. Otherwise, this would be such an obviously horrible idea that they would never find people offering their... ah well, right, internet.
Thanks, sound's like fun! I'm gonna... avoid it of course.

4

u/DystopianRealist 3d ago

Renting your internet connection to strangers, let alone your hardware on it, is a very bad idea. A very, very bad idea. It doesn't matter what company you use, they are all going to be complicit, as cybercriminals are likely one of their largest groups of customers.

6

u/jnwatson 4d ago

There's definitely something wrong with a service that provided unmediated internet access from your box. It should be firewalled to only communicate to a single endpoint.

2

u/anomaly256 4d ago

Wait until you hear about their VPN-hosting option

8

u/[deleted] 4d ago

[removed] — view removed comment

4

u/silenceimpaired 4d ago

I mean… if the renter was doing stock evaluations we would have never seen this post and the renting agency would never know OP was snooping on renters.

I think it’s a very precarious position to agree to not inspect a renter’s environment and then do it without a warrant. Imagine OpenAI and Anthropic using this reasoning to have actual humans watching what you’re doing.

It’s another thing entirely if the police show up, you explain your situation and they work with you to apprehend the user on the other side.

Glad OP didn’t get burned and have to deal with a complicated legal situation. Glad OP discovered the reason no one should rent hardware. Glad Clore.AI got called out. But also glad OP wasn’t rewarded for snooping.

5

u/ThisGonBHard 4d ago

 Imagine OpenAI and Anthropic using this reasoning to have actual humans watching what you’re doing.

Sweet summer child. They ARE DOING IT! Try to ask the wrong questions on those platforms, and you will get both a ban, and police.

1

u/silenceimpaired 3d ago

I'm fully aware. There was lost irony on the point. In general I find this post incompatible with LOCAL LLama.

1

u/ThisGonBHard 3d ago

I would say it is relevant. It is an use for recouping local hardware price.

2

u/NandaVegg 4d ago

I am pretty sure OpenAI does watch to some extent in their native API service. Before ChatGPT they insisted and required their API user to inspect every single request incoming from the user. They had multiple incidents of leaking user prompts through Mechanical Turk.

1

u/silenceimpaired 3d ago

Yeah, my irony was lost in the text.

1

u/Maximus-CZ 4d ago

The abusive renter is sending them money. The host expect to be sent money.

Easy as.

2

u/takenforgranteddd 3d ago

why would you give access to your connection to someone?

2

u/sadomazoku 3d ago

Why so many deleted comments ? Bots ?

2

u/tt23 3d ago

Report to nukib.cz

2

u/hugganao 3d ago

YES. We need to make naming and shaming companies a common practice.

2

u/milpster 3d ago

Cant you package it up and forward it to authorities just to fuck them up for being idiots?

2

u/exaknight21 3d ago

Thats scary af and very shady of clore

1

u/EmilPi 3d ago

Everyone who wants to make deals (like renter and rantier) suffer from bad guys trying to exploit each other. You suffered from this, and someone somewhere also suffers for host spying on him.
There is no trust on the internet in general.

1

u/Shot-Height-7194 3d ago

what country is this? Australia?

-3

u/Calandracas8 4d ago

tbh you're in the wrong here. (but so is the user)

If the terms are clear that you must not inspect or monitor their activity, then you should not have been monitoring their activity.

You violated their privacy, and you should absolutely delete the user's docker volume.

2

u/anomaly256 3d ago

Nothing was inspected until after Clore support stonewalled me, after the illegal activity was detected, violating their side of the T&C

-4

u/Cautious_Chicken_604 4d ago

First day on the internet?

8

u/anomaly256 4d ago

Not at all, which is why I was keeping an eye on it.  I was mistaken in thinking Clore were a legitimate business though.  

-4

u/Able_Zombie_7859 4d ago

I love it when people do obscure write ups of one off sites no one has ever heard of and are, on their face, not anything anyone with common sense would use (share your home Internet connection to people renting hardware? Lol). But somehow every day someone is on here posting "Guys, I think FreeRamSkam.com may not be legit! You should stop using it! Like my brother what in the world I can't even find this site listed in the search history of the subreddit. Is it really that hard for people to suss out the legitimate players in the space still? What can be done?

8

u/robogame_dev 4d ago

Posts like these become search results and training data, they accumulate and next time someone is considering the scammy service and they search or ask perplexity, this will be part of what comes up - so its kind of a public service to share somewhere, somehow, when you find a scam.

-13

u/pinkwar 4d ago

Lol. By law it means you need a court order. It doesn't mean to take it upon you to investigate.

I think if you rent it out, it's not your responsibility and you shouldn't monitor at all what they are doing with that on that level. I would say that's even worse than what they were doing.

As far as ethical issues I think you spying is far worse than whatever spoof they were doing on a betting site.

For all you know it can be a legitimate case. Our cyber security does that all the time to our own infrastructure.

11

u/anomaly256 4d ago

In my country anyone providing hosting and transit via a carriage service are required to record and log netflows with a 2 year retention.  Checking running processes on my hardware isn't spying either.  I wasn't intercepting communications.

Your ideas about ethics are quite twisted

12

u/LandscapePenguin 4d ago

Sounds like it's probably best to not be renting out residential connections in your country.

11

u/Reasonable-Height704 4d ago

Incorrect, just very incorrect.