Live data from Hacker News

Omarchy development practices lead to predictable security issues

blog.happyfellow.dev

11–20 of 478 posts

Re: Omarchy development practices lead to predictable security issues

#11

I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't…

There's a difference between a few small bugs because software is new and a half dozen eval(untrusted_input) in version 4.0.

Maybe this can get fixed, security teams won't make it worse. I worry they're mopping the floor and not fixing the leak: the development practices which lead to the quantity, seriousness and banality of their security issues is the part which needs fixing.

Re: Omarchy development practices lead to predictable security issues

#12

I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't…

> Wouldn't the security team and the agents just go and fix the security holes?

Of course they’re going to react to what is reported and fix it. That’s a given.

The concern is the development process that is leading to these types of holes getting shipped. Mainstream Linux distributions have software practices and release cycles designed to be cautious. This project is taking more of a move fast and break things methodology where shipping the vibe coded feature as fast as possible is the priority.

Having a crack team of people responding to reports and fixing things (or prompting their agents to fix things) only solves the issues after they’ve been shipped, discovered, and kindly reported back upstream.

> I don't know, Omarchy's team really don't care if you're complaining.

Controversy is their primary marketing tactic. They prefer that people complain because being divisive and controversial is how DHH has always marketed his products.

Re: Omarchy development practices lead to predictable security issues

#13

I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't…

Yea, I don’t get the shade. As many have said, it’s just Arch + a very polished UX preconfigured so you can jump right in without a lot of setup overhead.

Why it’s security would be on a different level than any other Linux distro isn’t clear.

Re: Omarchy development practices lead to predictable security issues

#14
Ok I think I see the issue

It's lines, lines and more lines of bash script

sigh

big sigh

Using bash for all this stuff is like trying to wash your car with sandpaper instead of soap and water. Yes it can work if you're really careful with it, but in practice no

Re: Omarchy development practices lead to predictable security issues

#15

I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't…

If they are interested in complaints. Probably they do not, so people write blogs on their own. This kind of also happened in the rails world; some people got upset at DHH and then started writing complaints; and many of these complaints are by themselves also total garbage (some are more objective criticism, these tend to be better). It's kind of agenda-based everywhere.

> I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?

Well, we can note the time and look again in half a year or so. Personally I am in general happy with security in the linux ecosystem. I am more worried about e. g. systemd adding age sniffing as component. In another entry at hackernews, yesterday I think, we learned that Microsoft automatically tags all images with invisible watermarks. One just can not trust companies - they always feel a need to abuse data from the users and tags everyone. Next step will be mandatory chips into the brain.

Re: Omarchy development practices lead to predictable security issues

#18
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

it get picked up by Hype because DHH

Re: Omarchy development practices lead to predictable security issues

#19
heh... i still remember the very first time when it came out with it's opinionated branding and all that, looked good and went ahead to try it out but was so annoyed with all the bloats and promoting their software's in it which made me their intentions already clear. I got to know that recently they've added option to remove all the bloats but IDC anymore. not gonna try that ever. Not to mention it was just dotfiles painted on top of arch iso and documentation itself included archinstall guides - if that's a distro then my system with dotfiles are a distro in itself lol... though it looks like they've changed things up now, it looks like it has a iso's and all the stuffs to be called a distro now.

Re: Omarchy development practices lead to predictable security issues

#20
post #10

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

It's being largely driven by DHH (creator of Rails, and co-founder of 37signals). He has a massive following and a lot of influence (and money).
Post reply on HN