Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

471–480 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#471

Earlier quoted context omitted.

The whole point of Omarchy is for people who want to use Arch Linux but have it configured the way DHH does. So I think it's a little different. Anybody using an opinionated respin should understand what they're getting.

> people who want to use Arch Linux but have it configured the way DHH does Then they don't actually want to use Arch Linux. The Arch Linux way is to read the excellent wiki documentation, learn about all the choices available, and then make all of those choices so the system is configured the user's way instead of some celebrity's way.

Actually we do. I like pacman for example. And don't mind going thru archinstall for a test install once to learn. But my workstation, I'd not like to have to develop, even if I do like configuring minimal installs for other uses like kiosks.

Re: Omarchy: Any User Process Can Escalate to Root

#472

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

Other than hype, what's the appeal here? I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.

Then it's not for you, or you can't vision how 5 minutes of learning can save you hours of future time.

Having to know like 5 keybinds and no taskbar is absolutely the point and it's a beautiful concept of how to use your computer. And it works, if you are open to relearning just a bit.

Re: Omarchy: Any User Process Can Escalate to Root

#473
post #338
post #329

Earlier quoted context omitted.

Github is awash with people's dotfiles including fully featured DEs built on top of things like Hyprland and Noctalia, and they don't require you to use a mess of a distro to use them.

100% this, either use a DE like GNOME or Cosmic if you can't be bothered, or spend a little time looking at someone's dotfiles. No need to use a whole distribution with 1000 other poor decisions made for you.

There's a way to have 1000 poor decisions with your arch sure. I use Omarchy to avoid just that.

Re: Omarchy: Any User Process Can Escalate to Root

#474

Earlier quoted context omitted.

Its opposite. Windows and MacOS lacks proper sandboxing. While openbsd has pinsyscalls and linux has seccomp-bpf. Windows and MacOS only have filesystem and worse version of user namespace sandboxes, anything else and you need to write a kernel extension or rely on a hypervisor. > Unfortunately implementing an Apple style architecture on Linux would be very difficult. The apple apps kind of thing already exists and i…

Windows has virtualisation based sandboxing and NT has object-level security (albeit not often used correctly and granularly) and macOS has (among other things) SIP and a subsystem called sandbox that does exactly what it says: it sandboxes. It can sandbox in comparable namespace terms (like cgroups v1 or v2, but more in translocation style execution since it's a MAC framework) yet it also does it a much more fine-gr…

Hello, can you tell me if I can filter syscalls made from a memory address in macos without virtualizing the process, or requiring special entitlements and root? I currently have a project where sandboxing is important and i need to prevent all syscalls from a region. This is very simple in linux, and on openbsd i dont have to do anything because openbsd by default does not allow untrusted callsites from making syscalls (and the region in this case is not loaded by openbsd's dynamic loader).

On macos i currently virtualize the process itself, but this has virtualization overhead and some emulation overhead because macos does not let you map all the host process pages to a guest.

Re: Omarchy: Any User Process Can Escalate to Root

#475

Earlier quoted context omitted.

> etc. the list is endless. Why is the list endless? I don’t even remember the last time I check or change any on my mac settings. And my unix things haven’t been touched in months. My debian server is basically frozen at this point.

I encourage you to think more outside of the box and dream. There is much more you are able to do now, that would have been impossible 2 years ago! :D https://x.com/SergioTapiaDev/status/2094187967900266573

I can't tell if this is performance art or not.

"Think outside the box and dream!"

"Here's a world clock widget."

Re: Omarchy: Any User Process Can Escalate to Root

#476

Earlier quoted context omitted.

What he is or what random blog posts present him as?

His own blog posts present him as what he is. Have you read them?

Some yes. I am not american, so i don't see anything particularly wrong with them. The main thing americans forget is that they are the invaders that replaced the local population and erased local culture.

Re: Omarchy: Any User Process Can Escalate to Root

#477

A few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

> It's why you switched away from Windows in the first place, remember?

Really good reminder I gotta say

Re: Omarchy: Any User Process Can Escalate to Root

#478

Earlier quoted context omitted.

> What is different here? I don’t understand how this is a question. What’s different is that it comes configured this way out of the box, silently, without warning. It’s functionally equivalent to opting in to giving all user accounts root privileges, which is not what anyone expects the default configuration to be. You can choose to configure your installs this way if you choose to do so. It should not come this wa…

More like a company that had hundreds of millions of dollars and a couple decades should have fixed it by now. If only Podman could beat Docker in advertising…

First they should try making a solution that works as well as Docker. Every time I use Podman or Podman Desktop I run into the most basic problems. Docker works out of the box everywhere.

Re: Omarchy: Any User Process Can Escalate to Root

#479
I am a little unsure why folks keep getting convinced one new distro or another is gonna come and finally solve the Linux desktop adoption problem?

The fundamental problem linux distros have is that they dont agree on a fundamental set of libraries, user experience, or have a stable abi. We've had minimal disros before, we've had maximal install-everything distros before, and we've had special purpose distros before (ie knoppix, mythbuntu, Kali). But the same adoption problem remains.

Afaict Google and Valve have managed to meaningfully move things forward with chromeos, android, and steam OS. Tools like flatpak and others also have made a difference.

But if you're really going the typical distro route, it confounds me what the point of going outside of the typical and common debian/redhat/arch systems are especially when its one guy. Hell, I still remember SprezzOS (Nick Black's Distro) and that thing had more real goals worth praising than anything I see from Omarchy.

Re: Omarchy: Any User Process Can Escalate to Root

#480

I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does. (example: NetworkChuck, Primeagen? and a few others) also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it [1] - https://wiki.archlinux.org/title/Archinstall

It's fine if they want to jump on fad distros. After all, Linux is a hobby OS, it's not for serious work.
Post reply on HN