Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

571–580 of 590 posts

Re: Omarchy: Any User Process Can Escalate to Root

#571
post #557

Earlier quoted context omitted.

I'm missing something then, are you talking about the code your shared or an another slightly more complicated one you are just imagining now?

A 3 line change to my above code would do for your case. Obviously that is not production ready malware, it is just a minimum viable example for the most common target. You type "sudo" and it runs an unprivileged sudo wrapper, and prepends your sudo command and runs real sudo. You tap, and your intended command runs as root alongside the attackers command. You need a separate trusted OS to do privileged workflows fro…

Right but that's my point, since 99.99% of users don't rely on U2F I doubt it would be covered or even be rational to cover such edge cases and thus most likely wouldn't work. I'm not saying it's a magical perfect solution, only that being outside of the most popular flow is in itself a protection for the most automated attacks.

Re: Omarchy: Any User Process Can Escalate to Root

#572

Earlier quoted context omitted.

DHH made Ruby on Rails and lots of people love it (not for me, personally).

Everyone knows that, but that was 20 years ago. Why do people still care?

Care should age? At what rate, do you propose?

Re: Omarchy: Any User Process Can Escalate to Root

#573
post #555

Earlier quoted context omitted.

Ah, neat. I did something like Caution a few years ago but for Intel SGX, called Conclave. It made it much easier to deploy apps to enclaves, get remote attestations and communicate with them securely. Unfortunately it's a difficult space to work in. SGX tries to remove the kernel and hardware from the TCB but there are a lot of obscure attacks to do with tampering with the enclave's sense of time. It's not an SGX pr…

> It's not an SGX problem, it's inherent to enclaves not having enough trusted hardware like signed clocks, tamper-resistant counters and so on. Those things all exist now in several forms. You were just too early! (I know the feeling from past companies). SGX is a giant pile of design flaws I abandoned pretty early, but _TDX_ is what SGX should have been, and AMD sev-snp is wildly ahead allowing hardware memory encr…

Now I'm curious, how do TDX enclaves get secure time and prevent rollback attacks on the VM? NTPS? Where's the secure counter you'd need to stop the disk image being rolled back? A lot of the attacks I discovered on SGX (the concept, not the implementation) were to do with the adversarial operator being able to roll back and replay inputs to the enclave. For example, you couldn't use a password to protect anything, because the enclave couldn't detect brute force attacks as it had no reliable forward sense of time.

Re: Omarchy: Any User Process Can Escalate to Root

#574

Earlier quoted context omitted.

The whole point of Omarchy is for people who want to use Arch Linux but have it configured the way DHH does. So I think it's a little different. Anybody using an opinionated respin should understand what they're getting.

> people who want to use Arch Linux but have it configured the way DHH does Then they don't actually want to use Arch Linux. The Arch Linux way is to read the excellent wiki documentation, learn about all the choices available, and then make all of those choices so the system is configured the user's way instead of some celebrity's way.

I didn't realise there was a correct way to use Arch, or that there were people authorised to explain what it is. Is that an Arch-exclusive service, or is it available for other distros as well?

You say the whole point is ending up with a system configured the user's way instead of some celebrity's way, and then you go on to tell us what we are actually allowed to want. That's a bit rich.

Starting from someone else's config and then changing whatever annoys you is making the choice, it just skips the part where you spend a weekend reading about display managers to arrive at the same place. That is what dotfiles have been for since roughly forever.

By your standard, anyone who used archinstall from the official ISO isn't really using Arch either, and I suppose the truly enlightened path is Linux From Scratch, compiled this morning, on hardware you soldered yourself.

Re: Omarchy: Any User Process Can Escalate to Root

#575

I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does. (example: NetworkChuck, Primeagen? and a few others) also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it [1] - https://wiki.archlinux.org/title/Archinstall

Everything hyped is usually a counter quality signal

I disagree. I think it's more that most things aren't high quality, and hype doesn't reliably select for things that are.

Re: Omarchy: Any User Process Can Escalate to Root

#576
post #569

Earlier quoted context omitted.

> Ubuntu has the exact same vulnerability out of the box, just with lxd instead. No, it does not[1]. LXD: - explicitly warns against this mode of vulnerability. Of course, there's no protection against people who blindly run commands copied from the internets, but the official documentation, at least, for as far back as I can recall, has had clear warning boxes against this, with explanations. - does not have the tra…

Yes, it does. None of this information changes the fact that, on a fresh install of Ubuntu Server 24+, the default user can privilege escalate to root using a few LXD commands. https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-... And yes, I've tried it myself, it works as advertised.

Ah, Ubuntu _Server_. I'm tempted to dismiss this by simply saying "Server Linux != Desktop Linux", but yeah, I don't like that this is on by default either.

I mean, this is a setup that ships with a default password that's the same as the username, and the first thing I do on all my server installs is disable all default user accounts and enable passwordless sudo.

From reading other docs of Ubuntu Server, it appears they relax the root/non-root distinction in other ways too. But I'd probably never have suspected this particular vector of vulnerability.

Re: Omarchy: Any User Process Can Escalate to Root

#577
post #69

Earlier quoted context omitted.

Why doesn't Ubuntu fit the bill? You can even install hombrew on it. Everything works like a mac with no fuss. Also the only reason I left Linux was due to hardware. Ubuntu was convenient enough.

There's no reason to use homebrew on Linux. Your package manager is better in every respect. Just don't.

Package managers are often out of date.

Re: Omarchy: Any User Process Can Escalate to Root

#578

Earlier quoted context omitted.

> if you choose to master the art of video production, then you are probably not spending that much time on mastering the thing What? Its perfectly possible to master two things. Video production isnt _that_ hard. Especially as lighting, shooting adding graphics and editing film is much much easier than 10 years ago.

I was watching one guy explaining the xv6 code and it was pretty much one shot with a single camera pointing at the listing on paper. Not sure if you need professional video if you want to really expound on something.

That is also a strong point. fancy visuals are nice, but if you can't explain, then there is little point

mind you it also feeds into LLM output. Confident bullshit is better than "I dunno"

Re: Omarchy: Any User Process Can Escalate to Root

#579

Earlier quoted context omitted.

What exactly is special about rolling a custom arch in this instance? Like, why does this get so much attention? Do web developers really care about what DHH does that much? Like, I get it if thats the case. Say, if Chris Lattner or Andrej Karpathy rolled some ML GPU programming distro I'd probably care about it and try and see if it made me more productive.

He leveraged his past success as a web developer to get into online culture war punditry. Now he's a prominent race-baiting reactionary. There's a sort of cult of personality around him at this point. His acolytes follow him for his nativist views, and then adopt his technology unthinkingly. I don't know why my comment was downvoted above. This isn't a serious distribution and you shouldn't expect it to be. It's a va…

Yeah that’s exactly it. Seems he’s manufacturing a lot of culture war bullshit just to bring attention to a less than interesting distro. If it wanted to be the “hyperland“ distro as so many distros are (built to bring one de/wm to users prepackaged) that’d be one thing. If he wanted to show people how to roll their own opinionated distro the way gentoo or lfs kinda did that’d be another too! But seems it’s neither of these, and purely vanity to me.

Re: Omarchy: Any User Process Can Escalate to Root

#580

Earlier quoted context omitted.

Everyone knows that, but that was 20 years ago. Why do people still care?

Care should age? At what rate, do you propose?

I thought that’s pretty much the way all technology goes. Just seems silly to take promotion an operating system that’s essentially a lot of config files atop existing work seriously from someone that made a popular web development framework 20 years ago. That’d be like me caring about a distro Gavin king made because he made hibernate in the 2000s at jboss.
Post reply on HN