Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

341–350 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#341

Earlier quoted context omitted.

"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).

I think they mean that Omarchy is pretty much vibe-coded. Probably just an assumption.

It is, DHH doesn’t seem too shy about it

Re: Omarchy: Any User Process Can Escalate to Root

#342
post #147

Earlier quoted context omitted.

"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).

The fact comments like this get downvoted because what they say is inconvenient is one of the major signs AI has fundamentally broken HN. It was already hard to have technical conversations in public, now there is a contingent determined to make it utterly impossible, and they are succeeding.

By the HN guidelines, it’s better to avoid discussing downvotes on HN

Re: Omarchy: Any User Process Can Escalate to Root

#343
post #55

Earlier quoted context omitted.

Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.

Not a single mention of Pirate Software yet?

Am I missing something? What does pirating software has to do with that thread?

Re: Omarchy: Any User Process Can Escalate to Root

#344
Once you have a box vibe coding has happened on I wouldn’t trust anything on it. Thats why I vibe code on a fully separate machine.

Im not an Omarchy user but we now live in a world where most of the actions (including ones the llm asks users to run as root) originate from somewhere other than the users brain.

There will be a reckoning in terms of how we think about trust and auth in coming years. It’s just a matter of increasing severity of incidents .

Re: Omarchy: Any User Process Can Escalate to Root

#345
post #121

Earlier quoted context omitted.

There is. Simply do not install sudo and do not allow access to root at runtime. I am serious. There is absolutely nothing you cannot run unprivileged these days. Can even run sshd from a systemd user unit in your home folder, and even assign port 22 to it if needed with Linux Capabilities.

Just don't be in the sudo group.

So the solution is to make your computer basically unusable. I guess that's one way to secure things.

Re: Omarchy: Any User Process Can Escalate to Root

#346

Earlier quoted context omitted.

Wow. This never crossed my mind but of course that's so simple. There really needs to be a better solution.

on Windows the UAC (GUI sudo equivalent) requires actual user input (keyboard, mouse) on a dialog presented in a secure way (can't be faked by malware)

Windows and Mac each have well thought through and secure solutions to these problems. It just doesn't exist on Linux without serious sacrifice of UX.

Re: Omarchy: Any User Process Can Escalate to Root

#347
I can't fathom why it's so common to run docker as root instead of as an unprivileged user.

Docker has supported running rootless mode for years. I packaged the docker-rootless into Arch/AUR over 4 years ago, so it's been around and stable that long.

Sure, on a server dedicated to running docker containers, maybe it makes sense for the marginal improvements to network latency. But otherwise, rootless should always be the default.

Re: Omarchy: Any User Process Can Escalate to Root

#348

Earlier quoted context omitted.

"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).

I think they mean that Omarchy is pretty much vibe-coded. Probably just an assumption.

In a recent long interview with Lex Friedman, DHH explained that he's essentially doing pure agentic dev on Omarchy now.

https://www.youtube.com/watch?v=NYFGCESmikA

Re: Omarchy: Any User Process Can Escalate to Root

#349
post #271

Earlier quoted context omitted.

Officially omakase (clueless chef decides your menu with security issues) and arch linux. The fact that it is almost an anagram of monarchy is probably a plus for DHH.

Thank you! Sounds horrible. I don’t know what a DHH is though, probably not important.

The guy who invented Ruby on Rails. He’s been pretty important in web dev and he’s an excellent engineer, although he’s a polarizing figure. He’s always been opinionated and never afraid to ruffle some feathers. More recently, he’s been posting some controversial right-wing stuff online that pissed off a lot of people.

Re: Omarchy: Any User Process Can Escalate to Root

#350

Earlier quoted context omitted.

On the flipside, once you use an OS that is totally open to agentic stuff, there's no going back really. I can open Pi and ask it to fix some window tiling issue, help me install shortcuts, help me figure out how to install flatpak vs appimage, etc. the list is endless. I cannot see myself going back to a legacy OS unless I'm forced to by my job for compliance reasons.

> etc. the list is endless. Why is the list endless? I don’t even remember the last time I check or change any on my mac settings. And my unix things haven’t been touched in months. My debian server is basically frozen at this point.

I encourage you to think more outside of the box and dream. There is much more you are able to do now, that would have been impossible 2 years ago! :D

https://x.com/SergioTapiaDev/status/2094187967900266573

Post reply on HN