Live data from Hacker News

Omarchy development practices lead to predictable security issues

blog.happyfellow.dev

201–210 of 480 posts

Re: Omarchy development practices lead to predictable security issues

#201
post #68

There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.

The right side is Nix

Re: Omarchy development practices lead to predictable security issues

#202
post #146

Earlier quoted context omitted.

I don't think it's aimed at them. I think it's mostly aimed at windows and mac users who are computer enthusiasts but never really made the jump to Linux as a desktop daily driver. Just supposed to be a cool on-ramp - basically mint but different and with some marketing behind it?

Then why chose a distro that is being maintained by one person. I would NEVER recommend a Windows/Mac and first time Linux user to switch to such a distro. Not just his political views no quite practical implications are key here: what if this guy has a heart-attack? The distro will be abandoned. What if his development PC gets compromised? The distro is fried in both cases. The more developers are on the team holdin…

I wasn't making a value judgement on who should respond to the offer, just commenting on who the offer was probably aimed at. Though I do think the sudden spike in investment and the little foundation around it now means probably more than "just one guy".

Re: Omarchy development practices lead to predictable security issues

#204
post #26

Earlier quoted context omitted.

It's a political statement disguised as a FOSS project (which itself is fine, all software is political). The funders are not funding the development of a Linux distro, they are co-signing the political statement.

[flagged]

“Europe was better when it was more white” isn’t “conservative leanings”

Re: Omarchy development practices lead to predictable security issues

#205

I have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.

It's been showing up all over YT for a while if you do any searches for Linux.

I took a look at it when I kept seeing it, realised what it is and who it's by and carried on moving, putting aside DHH as a person, it doesn't really do anything I want or in a way I'd care about but then I'm also not the target demographic/user, after 30 years of using Linux, I don't need it.

Re: Omarchy development practices lead to predictable security issues

#206

Earlier quoted context omitted.

I ran it daily like up to 4 months ago. Updates would regularly break hyprland and most games I wanted to play needed much more tinkering than on vanilla arch with the same dependencies installed.

I've run it since launch without issue. That is: to each their own really

Not really: as far as we know, you use it for nothing; the person you replied to gave examples.

Re: Omarchy development practices lead to predictable security issues

#207
post #114

Earlier quoted context omitted.

Care to elaborate on "fascist agitator" or are you just going to smear a person with a truly serious epithet without anything to back it up?

He literally calls openly for the ethnic cleansing of undesirable populations from Europe. Just read his blog. There's no subtlety or nuance.

I think there's such a strong difference between remigration and ethnic cleansing. And if you are misinformed, maybe take a minute to actually read his blog posts. But if you are and willingly misrepresenting his viewpoints, then maybe take a step back and think about what that says about you.

Not an endorsement of his viewpoints, but if we're going to debate people, we should do it on the actual words they say rather than the things we make up in our head about them.

Re: Omarchy development practices lead to predictable security issues

#208
post #26
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

It's a political statement disguised as a FOSS project (which itself is fine, all software is political). The funders are not funding the development of a Linux distro, they are co-signing the political statement.

> The funders are not funding the development of a Linux distro, they are co-signing the political statement.

It's not even a Linux distro. It's an Arch respin with tweaks that DHH likes.

This is for people who want to work like DHH.

Re: Omarchy development practices lead to predictable security issues

#209
post #151

Earlier quoted context omitted.

The same kind as a similar recent post [1] where a person pointed out a bunch of problems with Omarchy's shell scripts as examples of it being terrible. Open a pull request. That's how this is supposed to work. Wisdom of the crowd and what not. 1. https://xn--gckvb8fzb.com/a-word-on-omarchy/

Why would I do that? It's a crazy non-sequitur. My opinion is that the way Omarchy is developed leads to gigantic security holes. I wanted people to be aware of it. In my opinion, there are much better choices both for me and I'd imagine for other people as well. I don't want to help Omarchy succeed, I don't care about them.

Because you could make the world a better place instead of just complaining about it? I don't understand the "all I wanna do is complain" process at all.

Fix it. If you see a problem in the world, fix it.

If they reject the fix, that's when you complain.

Re: Omarchy development practices lead to predictable security issues

#210

Apparently the Omarchy plugin ecosystem is also a free for all like the Arch AUR, except the audience includes people who are new to Linux and less likely to understand the risks.

A lot of plugin systems are like that. (See the hyprland, noctalia, or vim/neovim's plugin systems).

More generally, how else would a small project allow plugins that isn't "here is a way to add code" and then anyone can release the code they added? Hell, the linux ecosystem in general is a "free for all", and that is the nature of the platform

Post reply on HN