Omarchy: Any User Process Can Escalate to Root
501–510 of 590 posts
Re: Omarchy: Any User Process Can Escalate to Root
#502Earlier quoted context omitted.
This is a weird metaphor - why do you think people buy matcha at coffeeshops or use peptides? Those two things don't have anything obvious to do with each other, let alone with Omarchy.
except that all three things are getting a lot of social media clout. they just keep pumping out short form videos or yapping heads talking about how they use x to do y better than any of the old stuff... I think this is the OP's point. they all exist because there is a lot of noise about them existing and being used.
Re: Omarchy: Any User Process Can Escalate to Root
#503Earlier quoted context omitted.
Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.
There is only so much a human can master in his lifetime. And if you choose to master the art of video production, then you are probably not spending that much time on mastering the thing you yap about on camera…
Musician, singer, novelist, comedian, actor, producer
Re: Omarchy: Any User Process Can Escalate to Root
#504Earlier quoted context omitted.
Just don't be in the sudo group.
So the solution is to make your computer basically unusable. I guess that's one way to secure things.
I do have non sudoers groups devices and I also have shared devices with non sudoers users. It works. It's not necessarily for everyone, e.g. not for powerusers who want to go fast very often, but it's definitely usable for most users still.
Re: Omarchy: Any User Process Can Escalate to Root
#505Earlier quoted context omitted.
Funnily enough it wouldn't work for me as I use passwordless sudo thanks to PAM-U2F with a YubiKey Bio. I mean realistically speaking it probably would as I would just type it thinking "Hmmm weird" but still want to proceed forward ¯\_ (ツ)_/¯
Of course this style of attack would work on you. Attacker has the sudo wrapper that hooks your next yubikey tap to running any payload they want as root. Your solution helps mitigate hardware keyloggers, which is great, but for malware in your home directory, it offers no advantages.
Re: Omarchy: Any User Process Can Escalate to Root
#506I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does. (example: NetworkChuck, Primeagen? and a few others) also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it [1] - https://wiki.archlinux.org/title/Archinstall
It's fine if they want to jump on fad distros. After all, Linux is a hobby OS, it's not for serious work.
Re: Omarchy: Any User Process Can Escalate to Root
#507I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does. (example: NetworkChuck, Primeagen? and a few others) also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it [1] - https://wiki.archlinux.org/title/Archinstall
Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.
Average Theo Video: https://www.youtube.com/watch?v=h1p9zdUtUdo
Re: Omarchy: Any User Process Can Escalate to Root
#508Earlier quoted context omitted.
DHH created a distro for what he personally needs for work, and his company uses Zoom. It's that simple.
There are far better ways to handle setting up a workstation for one's needs than spinning a new distro.
Re: Omarchy: Any User Process Can Escalate to Root
#509Earlier quoted context omitted.
There was no oversight and no security. It's vibe-coders pushing unvetted shell scripts and dotfiles. They "immediately fixed it" after it blew up on X/Twitter. Just like all the other issues they've had in the past few weeks. And now they formed a "security team" lol.
DHH was on the Lex Fridman podcast talking about this recent release of Omarchy in that most of it is "vibe coded". It is mostly just a bash script to configure Linux, but his approach is interesting. AI as a core part of the OS that can just change or add anything you want. Linux is great for this because it has access to the source code for everything. He said he didnt review the code line by line, just looked at t…
> He said he didnt review the code line by line, just looked at the shape of it. Whatever that means.
Did... did you even read my comment before replying to it? We know it's vibe-coded, we know it's bash scripts, and we know what it means
Re: Omarchy: Any User Process Can Escalate to Root
#510Earlier quoted context omitted.
The Omarchy team admitted it was a mistake and corrected it quickly. It’s strange that so many people are trying to call this security error intentional.
It might be a mistake but not a serious one, like it's a common setting they had on for convenience of development without being too insecure, but forgot to leave it out of public release. So there's nothing weird. It being on originally was intentional and not crazy. Only it going all they way wasn't.
They didn't forget. They never knew it was there. https://news.ycombinator.com/item?id=49502099