Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

431–440 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#431

Earlier quoted context omitted.

"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).

It’s that age old “start a docker container with the docker socket in the container and you are effectively root”. What are we talking about here? This is not new?

Apparently is for some people. Not sure why.

Re: Omarchy: Any User Process Can Escalate to Root

#432

Omarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)

i don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.

[flagged]

Re: Omarchy: Any User Process Can Escalate to Root

#433

Earlier quoted context omitted.

Wow. This never crossed my mind but of course that's so simple. There really needs to be a better solution.

on Windows the UAC (GUI sudo equivalent) requires actual user input (keyboard, mouse) on a dialog presented in a secure way (can't be faked by malware)

UAC is only a sudo equivalent when running under a non-admin user account, at which point it's nearly as convenient to simply run admin commands from a command prompt running as a separate user, or a separate desktop session entirely.

Re: Omarchy: Any User Process Can Escalate to Root

#434

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

Other than hype, what's the appeal here? I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.

I recently customized my own Bazzite install to use hyprland plus other customizations, there's really not much different than what omarchy did. It's pretty much that with some pre installed apps. Anyone that gave them funding is an idiot IMO.

Re: Omarchy: Any User Process Can Escalate to Root

#436
post #285
post #171

Earlier quoted context omitted.

> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. As a QubesOS user, I beg to differ. Just because most Linux distros are negligent with sandboxing does not mean all of them are.

Funny because there is a 101 level Qubes RCE on front page right now.

Sigh. Qubes had some great security design and implemented it the only way time/funds would allow: by cobbling together a lot of unfortunately very complex and broken things built for a different security model decades ago.

Qubes is the least bad option for laptops (until Stagex Work ships which I am designing) but there is no reasonable server OS.

I am ripping off the best ideas from xen/Qubes and starting over with: https://distrust.co/blog/enclaveos.html

Re: Omarchy: Any User Process Can Escalate to Root

#437
post #96

Earlier quoted context omitted.

Homebrew is like giving a bunch of wikipedia randos remote shell access to your computer. There is no enforced code review policy. Any maintainer can make a commit under a pseudonym and merge their own code to main without review. Homebrew should not be allowed near any machine you need to be able to trust.

> Homebrew is like giving a bunch of wikipedia randos... And I'm guessing you go to https://www.britannica.com/ when you want to learn something about a new topic, right?

I love wikipedia for research. It is great that anon randos can help keep a common encyclopedia maintained with high accountability. If a mistake happens it is quickly corrected.

But that trust model does not work with software.

It is negligent that MacOS users, even those with prod access, all let any anon randos that sign up to be Homebrew maintainers execute any code they want on their computers with no accountability. By the time someone figures that out and corrects it, the damage is done.

What is worse, is almost zero MacOS users I talk to are aware of this risk. Even security engineers. Many say "no worse than NPM" as if that is a defense.

Re: Omarchy: Any User Process Can Escalate to Root

#438

Omarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)

(Not a Rails developer, just an outside observer)

Isn't Rails highly opinionated with a focus on being batteries-included? I'm not defending the choice to include Zoom but a batteries-included (for better or for worse) distro is exactly what I would expect from the creator of Rails.

Re: Omarchy: Any User Process Can Escalate to Root

#440

Earlier quoted context omitted.

I don't care what he's doing, I care about what he is.

What he is or what random blog posts present him as?

Does his own blog count as "random"?

https://world.hey.com/dhh/as-i-remember-london-e7d38e64

Post reply on HN