Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

261–270 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#261

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

On the flipside, once you use an OS that is totally open to agentic stuff, there's no going back really.

I can open Pi and ask it to fix some window tiling issue, help me install shortcuts, help me figure out how to install flatpak vs appimage, etc. the list is endless. I cannot see myself going back to a legacy OS unless I'm forced to by my job for compliance reasons.

Re: Omarchy: Any User Process Can Escalate to Root

#262

Earlier quoted context omitted.

But, this “vulnerability” is the thing everybody knows about docker since forever. I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year. What is different here? Start a docker container with the docker socket mounted in the container and now you can have yourself mount / as rw. Everybody knows this. How is everybody so shocked here. Many instructions o…

>Everybody knows this. I didn't know this.

Do you know about docker compose overwriting your carefully set firewall rules? That’s the other docker thing…

Re: Omarchy: Any User Process Can Escalate to Root

#263

Earlier quoted context omitted.

It does warn you. It's an opinionated Linux for a modern developer/user. This modification absolutely makes sense in that context.

I hope this was an attempt at sarcasm. The Omarchy team immediately fixed this because it was a security oversight, not an intentional opinionated choice.

Opinionated choice?

I recently used Arch Linux because I have a 4 GiB Mac Air that I want to use for something but it has too little RAM for UI. The installer was user friendly and fast. I got exactly what I wanted.

I don't think that I need Omarchy.

I have only one answer to this:

I'm too old for this shit.

Re: Omarchy: Any User Process Can Escalate to Root

#264

Earlier quoted context omitted.

It does warn you. It's an opinionated Linux for a modern developer/user. This modification absolutely makes sense in that context.

I hope this was an attempt at sarcasm. The Omarchy team immediately fixed this because it was a security oversight, not an intentional opinionated choice.

Imo they could have sold it like that, in this case. A warning would be in order though.

Re: Omarchy: Any User Process Can Escalate to Root

#267

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

But, this “vulnerability” is the thing everybody knows about docker since forever. I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year. What is different here? Start a docker container with the docker socket mounted in the container and now you can have yourself mount / as rw. Everybody knows this. How is everybody so shocked here. Many instructions o…

“This house has a hole in its roof but I cut several holes into my roof to water my indoor plants so what’s the problem?”

Re: Omarchy: Any User Process Can Escalate to Root

#268
post #148

Earlier quoted context omitted.

> I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Whoa! You have to _learn_ something to use it well? Yikes. Not for me.

conventions are a good things so you can minimise relearning.

Learn emacs once and use ratpoison, readline and rlwrap everywhere.

Re: Omarchy: Any User Process Can Escalate to Root

#269

Why not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.

Rootless docker is also an option.

> Podman works much better than Docker today.

Nah absolutely not. Especially compose files and networking can be an absolute nightmare with podman.

Re: Omarchy: Any User Process Can Escalate to Root

#270
post #201

Earlier quoted context omitted.

No no, be fair -- some of us ridicule everyone using AI and the slop they get it to extrude.

Yes, I know. That is quite juvenile.

In good faith, show me the nice counterexamples of ai-generated software?
Post reply on HN