Earlier quoted context omitted.
"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).
It’s that age old “start a docker container with the docker socket in the container and you are effectively root”. What are we talking about here? This is not new?
Omarchy: Any User Process Can Escalate to Root
431–440 of 590 posts
Re: Omarchy: Any User Process Can Escalate to Root
#432Omarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)
i don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.
Re: Omarchy: Any User Process Can Escalate to Root
#433Earlier quoted context omitted.
Wow. This never crossed my mind but of course that's so simple. There really needs to be a better solution.
on Windows the UAC (GUI sudo equivalent) requires actual user input (keyboard, mouse) on a dialog presented in a secure way (can't be faked by malware)
Re: Omarchy: Any User Process Can Escalate to Root
#434A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?
Other than hype, what's the appeal here? I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.
Re: Omarchy: Any User Process Can Escalate to Root
#435Re: Omarchy: Any User Process Can Escalate to Root
#436Earlier quoted context omitted.
> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. As a QubesOS user, I beg to differ. Just because most Linux distros are negligent with sandboxing does not mean all of them are.
Funny because there is a 101 level Qubes RCE on front page right now.
Qubes is the least bad option for laptops (until Stagex Work ships which I am designing) but there is no reasonable server OS.
I am ripping off the best ideas from xen/Qubes and starting over with: https://distrust.co/blog/enclaveos.html
Re: Omarchy: Any User Process Can Escalate to Root
#437Earlier quoted context omitted.
Homebrew is like giving a bunch of wikipedia randos remote shell access to your computer. There is no enforced code review policy. Any maintainer can make a commit under a pseudonym and merge their own code to main without review. Homebrew should not be allowed near any machine you need to be able to trust.
> Homebrew is like giving a bunch of wikipedia randos... And I'm guessing you go to https://www.britannica.com/ when you want to learn something about a new topic, right?
But that trust model does not work with software.
It is negligent that MacOS users, even those with prod access, all let any anon randos that sign up to be Homebrew maintainers execute any code they want on their computers with no accountability. By the time someone figures that out and corrects it, the damage is done.
What is worse, is almost zero MacOS users I talk to are aware of this risk. Even security engineers. Many say "no worse than NPM" as if that is a defense.
Re: Omarchy: Any User Process Can Escalate to Root
#438Omarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)
Isn't Rails highly opinionated with a focus on being batteries-included? I'm not defending the choice to include Zoom but a batteries-included (for better or for worse) distro is exactly what I would expect from the creator of Rails.
Re: Omarchy: Any User Process Can Escalate to Root
#439Re: Omarchy: Any User Process Can Escalate to Root
#440Earlier quoted context omitted.
I don't care what he's doing, I care about what he is.
What he is or what random blog posts present him as?