Earlier quoted context omitted.
> it doesn't have any kind of proper desktop sandboxing architecture that really works. Bubblewrap works.
Bubblewrap is a less powerful version of sandbox-exec, but the macOS architecture is much larger than just that. In effect macOS runs everything under bubblewrap, in such a way that users don't notice but apps are meaningfully sandboxed and root exploits barely matter.
Omarchy: Any User Process Can Escalate to Root
131–140 of 584 posts
Re: Omarchy: Any User Process Can Escalate to Root
#132Earlier quoted context omitted.
As I said, podman requires effort and thought on the user's side, as the rootless part incurs complexity. I do not think that this aligns with the omakase mantra of omarchy. I do not think that DHH does not take security seriously. I think that Omarchy is not meant to sacrifice devex for security.
Rootless Podman (and rootless Docker for that matter) is not difficult to set up automatically. There is a little complexity involved, namely in configuring subuid and subgid mappings, but not much. That said, I think Arch Linux itself has a culture that values the wrong kind of simplicity (implementation simplicity) that perversely leads to a failure to adequately grapple with inherent complexity. This leads to brit…
I am a fedora/opensuse user and happily use podman with selinux.
Re: Omarchy: Any User Process Can Escalate to Root
#133Earlier quoted context omitted.
Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.
There is only so much a human can master in his lifetime. And if you choose to master the art of video production, then you are probably not spending that much time on mastering the thing you yap about on camera…
or did you think onlyfans?
Re: Omarchy: Any User Process Can Escalate to Root
#134Re: Omarchy: Any User Process Can Escalate to Root
#135Earlier quoted context omitted.
You didn't switch away from windows to get superior software? Also, the statement was valid because it will be true for most. It doesn't matter that you read it and it wasn't true for you, as long as it's true by the numbers, it's true, because it's one-to-many communication not one to one.
While I don't want to discuss the quality of any distro vs Windows, there is a big reason most of us use free software: because it is free . Whether for you it is because of free as in freedom or free as in beer specifically, quality may not have much to do with it.
Re: Omarchy: Any User Process Can Escalate to Root
#136A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?
"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).
Re: Omarchy: Any User Process Can Escalate to Root
#137Earlier quoted context omitted.
You didn't switch away from windows to get superior software? Also, the statement was valid because it will be true for most. It doesn't matter that you read it and it wasn't true for you, as long as it's true by the numbers, it's true, because it's one-to-many communication not one to one.
While I don't want to discuss the quality of any distro vs Windows, there is a big reason most of us use free software: because it is free . Whether for you it is because of free as in freedom or free as in beer specifically, quality may not have much to do with it.
Re: Omarchy: Any User Process Can Escalate to Root
#138Earlier quoted context omitted.
Adding your user to the docker group is in the official Docker install instructions, I wouldn't call that "random copy paste guides".
You mean the optional post install instructions, which is a separate page from the main install instructions, and contains a giant warning about the security implications? https://docs.docker.com/engine/install/linux-postinstall If the official sudo project had a guide on how to disable passwords, that shouldn't be taken as endorsement of having that as a default config.
Re: Omarchy: Any User Process Can Escalate to Root
#139Earlier quoted context omitted.
While I don't want to discuss the quality of any distro vs Windows, there is a big reason most of us use free software: because it is free . Whether for you it is because of free as in freedom or free as in beer specifically, quality may not have much to do with it.
Isn't Windows also basically free? Every laptop I buy has a Windows licence stuck to the bottom of it.
Re: Omarchy: Any User Process Can Escalate to Root
#140Earlier quoted context omitted.
Bubblewrap is a less powerful version of sandbox-exec, but the macOS architecture is much larger than just that. In effect macOS runs everything under bubblewrap, in such a way that users don't notice but apps are meaningfully sandboxed and root exploits barely matter.
[flagged]