Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

411–420 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#411

ot fyi: "omarchy" is fine as a creative spelling for omachi , but "omacon" / "omacom" has extremely low Levenshtein distance with the honorific form of the word for human female reproductive component in japanese

And the word "pine" is kinda close to "penis", what of it? Words in languages sometimes sound kinda like rude or sexual vocabulary, especially in a language like Japanese with a relatively small phoneme inventory.

Re: Omarchy: Any User Process Can Escalate to Root

#412

I hate to be defending Omarchy but I think for the modern desktop OS like Linux or Windows or Mac OS, "root" is not what it used to be. Like if I have something on my dev machines which is important from an enterprise perspective it is the credentials that I use to check things into the git repository or log into the postgresql database that are in some file or keyring or the credentials I used to log into some corpo…

I would say that the traditional notion of Unix root and normal user accounts is outdated, no longer useful for how people use computers today. On my personal laptop, malicious code having access to my user files is as bad as having root access - I'm the only user of my machine - and I don't have any convenient way to create more granular security zones among software running as my own Unix user.

Re: Omarchy: Any User Process Can Escalate to Root

#413

ot fyi: "omarchy" is fine as a creative spelling for omachi , but "omacon" / "omacom" has extremely low Levenshtein distance with the honorific form of the word for human female reproductive component in japanese

And the word "pine" is kinda close to "penis", what of it? Words in languages sometimes sound kinda like rude or sexual vocabulary, especially in a language like Japanese with a relatively small phoneme inventory.

Those two aren't as close

Re: Omarchy: Any User Process Can Escalate to Root

#415

Earlier quoted context omitted.

i don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.

DHH created a distro for what he personally needs for work, and his company uses Zoom. It's that simple.

There are far better ways to handle setting up a workstation for one's needs than spinning a new distro.

Re: Omarchy: Any User Process Can Escalate to Root

#416

Earlier quoted context omitted.

> people who want to use Arch Linux but have it configured the way DHH does Then they don't actually want to use Arch Linux. The Arch Linux way is to read the excellent wiki documentation, learn about all the choices available, and then make all of those choices so the system is configured the user's way instead of some celebrity's way.

installing arch is enough of a pain that I've been putting off installing it on my desktop for months.

archinstall comes preinstalled on the official iso. It’s a normal install flow and takes 5 mins.

Re: Omarchy: Any User Process Can Escalate to Root

#417

I can't fathom why it's so common to run docker as root instead of as an unprivileged user. Docker has supported running rootless mode for years. I packaged the docker-rootless into Arch/AUR over 4 years ago, so it's been around and stable that long. Sure, on a server dedicated to running docker containers, maybe it makes sense for the marginal improvements to network latency. But otherwise, rootless should always be…

Inertia. All the guides tell you to set it up the "easy" way.

Re: Omarchy: Any User Process Can Escalate to Root

#418
post #18

I was expecting a more sophisticated attack and then I scrolled down… > Omarchy configured its default user as a member of the Linux docker group. What the fuck? Docker makes it VERY, VERY clear this is unsafe. Feel free to verify the documentation. https://docs.docker.com/engine/install/linux-postinstall/ Why would you want to make this the default for your users, without even telling them? Did someone configured hi…

I don't use Omarchy, nor would I, but I think that "VERY, VERY" is a little hyperbolic, no? It's a simple `admonish-yellow` warning box that says something vague about root-level privileges and wants me to read more about what this actually means. I would wager that a large amount of people scroll past that with no second thought because it really doesn't come off as that bad. I know I configure most, if not all, of my systems this way. Many people probably don't actually understand the implications of what they are doing, and perhaps the Docker team should actually put a little bit more effort into scaring users off.

Perhaps Omarchy shouldn't have shipped this by default, but the whole point of the system is to be DHH's personal computer just the way he likes it (to include not 1, but 2 shortcuts to Twitter!) - all his products are that way and largely the reason why I don't ever think I could use one long term.

Re: Omarchy: Any User Process Can Escalate to Root

#419
post #394

My most controversial opinion by far in tech circles is that I still just use a standard Windows gaming PC as my home desktop. My current machine I just bought pre-built from Microcenter, complete with a 5090 and everything. I can fire up a Linux terminal with WezTerm and WSL2 at any point. It's customized and beautiful and totally fine. I have Codex running in one right now. I can listen to Dolby Atmos music through…

Has it restarted losing your session to install an "Intel Corporation - Extension - 22.1120.5.12" yet?

Re: Omarchy: Any User Process Can Escalate to Root

#420

Omarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)

i don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.

[deleted]
Post reply on HN