Live data from Hacker News

Omarchy development practices lead to predictable security issues

blog.happyfellow.dev

171–180 of 480 posts

Re: Omarchy development practices lead to predictable security issues

#171
post #87

Earlier quoted context omitted.

I think there is a pretty decent swath of people willing to rally behind someone who says they are trying to make a cool project specifically for people who want to be away from the "insufferable injection of identity politics". How large that swath is relative to the other is up for debate but it doesn't have to be particularly large. You'll get funding from people who are both interested in the actual product AND t…

dhh is very strongly associated with identity politics, though? (as in, "western"/white identity)

[dead]

Re: Omarchy development practices lead to predictable security issues

#172
post #39

Earlier quoted context omitted.

Is it? What's the statement?

That OSS has become too entangled with political activism and ideological gatekeeping, when it should be about making great software, giving people control over their computers, and rediscovering the joy of computing. I don't think Omarchy is anti-political so much as an attempt to revive the enthusiast/hacker ethos of the OSS community.

[deleted]

Re: Omarchy development practices lead to predictable security issues

#173
post #114

Earlier quoted context omitted.

Care to elaborate on "fascist agitator" or are you just going to smear a person with a truly serious epithet without anything to back it up?

He literally calls openly for the ethnic cleansing of undesirable populations from Europe. Just read his blog. There's no subtlety or nuance.

ethnic cleansing?

Re: Omarchy development practices lead to predictable security issues

#174
post #151

“Full of security holes" - and two examples in the article have been swiftly addressed, ignoring that there is a whole dedicated security team https://omarchy.org/teams/ What kind of blogging is this?

The same kind as a similar recent post [1] where a person pointed out a bunch of problems with Omarchy's shell scripts as examples of it being terrible. Open a pull request. That's how this is supposed to work. Wisdom of the crowd and what not. 1. https://xn--gckvb8fzb.com/a-word-on-omarchy/

Why would I do that? It's a crazy non-sequitur.

My opinion is that the way Omarchy is developed leads to gigantic security holes. I wanted people to be aware of it.

In my opinion, there are much better choices both for me and I'd imagine for other people as well. I don't want to help Omarchy succeed, I don't care about them.

Re: Omarchy development practices lead to predictable security issues

#175
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

I'm surprised HN failed to mention the real reason in this thread. It's AI. The goal of the project is to have users build (fix, maintain, expand etc) the distro themselves through AI generated (bug) reports which are then picked up by AI, solved, tested and published in a new release. A full AI loop.

AI sells, this should be obvious by now. The guy behind the project talks about this in more detail, for instance during the interview he recently did with Network Chuck on youtube.

Re: Omarchy development practices lead to predictable security issues

#176
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

It’s a really strong UX that’s rapidly improving without a profit motive and people are excited about it. Closest thing to the “it just works” experience that Mac was always known for and it runs great on older hardware. Even goes so far as to optimize the install time down to about 1 minute. I was running i3 when an Ubuntu update borked my entire setup so I made the switch. The difference is night and day in the lev…

Comparing Wayland anything to OSX-like "it just works" is bizzaro-world-tier delusion.

Re: Omarchy development practices lead to predictable security issues

#177
post #151

“Full of security holes" - and two examples in the article have been swiftly addressed, ignoring that there is a whole dedicated security team https://omarchy.org/teams/ What kind of blogging is this?

The same kind as a similar recent post [1] where a person pointed out a bunch of problems with Omarchy's shell scripts as examples of it being terrible. Open a pull request. That's how this is supposed to work. Wisdom of the crowd and what not. 1. https://xn--gckvb8fzb.com/a-word-on-omarchy/

You're not suggesting that you can't criticize something unless you're willing to fix it yourself, are you?

Re: Omarchy development practices lead to predictable security issues

#178
post #68

There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.

Your left side of the curve is missing people like me who use Fedora. Been using Linux since 1997, it's been my primary OS since ~2003 (except for gaming and Microsoft seem determine to end their streak on that one) and I use Fedora because I really don't care that much, it's a reliable tool, it has recent packages and I like that it's semi-rolling in that it's a straight forward update every 6ish months. I had my "I…

[dead]

Re: Omarchy development practices lead to predictable security issues

#179
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

It's AI and dev forward in a brilliant way. It ships with its own skill [1], so agents actually work way better out of the box than on other distros.

Something crashes? Click the notification and your agent solves the bug.

It also has a very standardized UI library and a good plugin system.

Due to those things the list of plugins is increasing by hundreds a day [2], I made one that adds Exposé like for macOS myself a few days ago.

Most of them are actually good, and unlike other distros they look visually consistent. Customizing your system and participating in the community has never been this easy. Incredibly fun, feels like being a kid in a candyshop.

[1] https://github.com/basecamp/omarchy/blob/quattro/default/age...

[2] https://omarchyplugins.com/

Re: Omarchy development practices lead to predictable security issues

#180

Yo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!

It was (my) main takeaway and I wanted it to be evident in the headline. I didn’t want to bury the lede; I’ll uneditorialize it because it seems it’s causing some fighting in the comments and I don’t really want to instigate anything, more just warn people using the distro. I don’t think it’ll reach the people who need to be warned if it’s not evident that there’s an issue from the start.
Post reply on HN