Live data from Hacker News

Omarchy development practices lead to predictable security issues

blog.happyfellow.dev

61–70 of 478 posts

Re: Omarchy development practices lead to predictable security issues

#61
post #37

Earlier quoted context omitted.

[flagged]

Care to elaborate on "fascist agitator" or are you just going to smear a person with a truly serious epithet without anything to back it up?

If you, having read his blog, are going to say that, then you're either epically naive, or you're deliberately whitewashing his messaging.

Re: Omarchy development practices lead to predictable security issues

#63
post #3

This tumblr level of discourse is precisely what the Linux community needs to leave behind.

Isn't the rise of AI basically turning software engineering into tumblr? Thats what I see; soon we'll have a forum that's just filled with roblox-but-for-adults.

Seems to be the “dream” the AI leaders want to sell at least

Re: Omarchy development practices lead to predictable security issues

#64
It is probably true that it has a big attack surface. But omarchy is no doubt a huge driving force. A few days ago I listened to a podcast dhh talking about the latest major release and its huge donation. I believe it’s now 10m usd or something. I am hopeful that dhh is serious enough to address the security issues plus a lot of ux improvement on linux.

In the episode he emphasized 17 layers of security layers where I remember the number solely because I found hard to believe to be honest.

You can find the podcast episode in this one https://thestanduppod.com/

Re: Omarchy development practices lead to predictable security issues

#65
post #40

"full of security holes" but the author could only name one (the two links in the opening paragraph are the same issue). Some people just hate DHH and can't separate the art from the artist

They point to two separate issues, what are you about?

They're both the same root cause. Command injection in notifications

Re: Omarchy development practices lead to predictable security issues

#66
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

isn't it a typical SV investor money hype train situation:

- project overpromise to a point of absurdity (e.g. Tesla (still has questionable full self driving), SpaceX (in recent times there had been absurd differences between claimed rocket load and what we then find out the rocket actually could load, like 100 Tons being only 15 Tons IRL level of differences), etc. etc.)

- project jumps on some hype train (e.g. AI)

- project has some eccentric owner which is good at selling it, even if it doesn't do what is sold

- owner also goes with the "move fast break things"

- owner acts widely (likely actually criminally) negligent in "safety" topics, shipping something is more important then the damage the negligence will causes, in some such such cases even if it's close to guaranteed that the negligence will kill people. Another way to phrase this point is they follow the "move at ANY cost so fast that competition can't keep up until you win by default" motto.

- owner has some "Vitamine B" connections to rich risk friendly investors (aka. the "friends help friends", "cartel-like", "kinda looks like corruption" structures we have been seen from time to time in the background of SV-related startup investments)

So I don't think you are missing anything about Omarchy, it's more like the whole investor culture around SV is severely broken, unhealthy and in their recklessness IMHO more damaging to society then its helpful. Not speaking about how this background structures twist the founding/startup marked in a way which may look to the outside to be "fair and open" but in fact isn't, if you don't "bow" to the right people and their ideology you aren't getting anywhere.

Re: Omarchy development practices lead to predictable security issues

#67
post #37

Earlier quoted context omitted.

[flagged]

Care to elaborate on "fascist agitator" or are you just going to smear a person with a truly serious epithet without anything to back it up?

The OP could well be referring to DHH's recent blog post comparing Roma in Copenhagen to a predatory species that needed to be culled.

Re: Omarchy development practices lead to predictable security issues

#68
There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff.

The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.

Re: Omarchy development practices lead to predictable security issues

#69
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

it's amazing from a historical perspective that there are HNers around now who don't know who DHH is, when he was such a prevailing voice in the HN scene back in the day.

He is the author of rails and there are so many founders who were inspired by 37 signals and their takes on things back in the day.

The golden years of HN.

Post reply on HN