Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

271–280 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#271
post #40

What on earth is an Omarchy

Officially omakase (clueless chef decides your menu with security issues) and arch linux. The fact that it is almost an anagram of monarchy is probably a plus for DHH.

Thank you! Sounds horrible.

I don’t know what a DHH is though, probably not important.

Re: Omarchy: Any User Process Can Escalate to Root

#272

Earlier quoted context omitted.

[flagged]

> As a developer who mostly wants a Mac-like Linux distro without the associated noise I'm required to use Ubuntu at work. Coming from Mac, apart from the menu bar at the top, on Gnome, I've been able to customize the keyboard shortcuts, remap the keyboard so that Ctrl works like Cmd, and use extensions like Dash to Dock[1] and themes like Whitesur[2] to replicate something that almost works like a Mac. The keyboard…

> The only things missing are some keyboard shortcuts like Ctrl+A/V to move to the beginning and end, and the Ctrl+Shift+C/V behavior on the terminal instead of Cmd+C, which I've just worked around by using VSCode's terminal and configuring it to copy when I press Ctrl+C with some text selected.

The fact that you think this is acceptable shows that you don't appreciate the difference. Again, I haven't used Omarchy but the docs claim that Super + C and Super + V work everywhere, not with all the different exceptions you mention.

Re: Omarchy: Any User Process Can Escalate to Root

#273
post #77

Earlier quoted context omitted.

Even if you introduce bugs in your UI (which I think is not very likely if you have a basic understanding of your system), the chance that someone would exploit software that literally only runs on your own machine seems extremely unlikely to me. I've been using arch for over 10 years btw.

Isn't the other half of AI that we can afford to look for exploits in one-off software?

The old human nature tendency of "Just ship it!" and the desire to move on to the next shiny thing on our wishlist doesn't go away with AI. If it anything, it makes it worse.

Re: Omarchy: Any User Process Can Escalate to Root

#274
And the cycle continues. It’s funny seeing Omarchy (DHH) becoming popular when we had LARBS (Luke Smith) 8-10 years ago.

Something about a controversial personality pushing a window manager install script is really appealing to people I guess. At least it brings awareness that other desktop paradigms exist. Although after years of ‘optimizing’ my tiling window manager I just ended up back on KDE.

Re: Omarchy: Any User Process Can Escalate to Root

#275
post #240

Earlier quoted context omitted.

is there a fedora 44 ws with non free package built in ?

You still have to use rpmfusion, which isn’t a huge deal. It’s maybe 5 min one time and then you are set. Or you could use one of the Universal Blue spins. Bluefin and Aurora have non-free stuff built in and you can install pretty much any package from anywhere.

oh thanks a ton

Re: Omarchy: Any User Process Can Escalate to Root

#277

Earlier quoted context omitted.

It does warn you. It's an opinionated Linux for a modern developer/user. This modification absolutely makes sense in that context.

I hope this was an attempt at sarcasm. The Omarchy team immediately fixed this because it was a security oversight, not an intentional opinionated choice.

There was no oversight and no security. It's vibe-coders pushing unvetted shell scripts and dotfiles.

They "immediately fixed it" after it blew up on X/Twitter. Just like all the other issues they've had in the past few weeks.

And now they formed a "security team" lol.

Re: Omarchy: Any User Process Can Escalate to Root

#278

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

[deleted]

Re: Omarchy: Any User Process Can Escalate to Root

#279

And the cycle continues. It’s funny seeing Omarchy (DHH) becoming popular when we had LARBS (Luke Smith) 8-10 years ago. Something about a controversial personality pushing a window manager install script is really appealing to people I guess. At least it brings awareness that other desktop paradigms exist. Although after years of ‘optimizing’ my tiling window manager I just ended up back on KDE.

Debian + KDE is the most effortless setup I've ever used. I also spent years using tiling window managers and I don't see the value

Re: Omarchy: Any User Process Can Escalate to Root

#280

Earlier quoted context omitted.

Shopify forced him to be a vibe coder now. Omarchy is a vibe coding distribution. In the AI world, security issues are just another marketing opportunity. EDIT: Downvote all you want. He was anti-AI, got a board seat at Shopify and then became an AI influencer. Now additional money is rolling in to Omarchy from Lütke and Steinberger.

It's really disturbing that there's a group of these CEO/investor types that are openly white nationalists, and they're joining forces. I'll never touch any of their products, and I hope they continue to expose themselves on social media.

[deleted]
Post reply on HN