Live data from Hacker News

A Word on Omarchy

xn--gckvb8fzb.com

61–70 of 105 posts

Re: A Word on Omarchy

#61
post #2

This blog pranks you with changing titles when you switch tabs (some nsfw), then welcomes you back with a paragraph inciting you to disable Javascript. That's nice, but I actually need Javascript in my browser to do real stuff.

got to admit, as a prank it's pretty funny.

fwiw, it's trivially easy to block javascript per site today with uBlock Origin. Firefox + UBlock Origin really is the panacea of a de-shittified web.

Re: A Word on Omarchy

#62
post #7

These criticisms all feel very nitpicky and subjective. So many of them seem to boil down to, "this is an opinionated configuration, but their opinions differ from my opinions." This part was where I stopped taking the article seriously: > Moreover, taking into account that the system relies heavily on sudo (instead of the more modern doas), and also considering that the default installation configures the maximum nu…

>This is such a reflexive and petty critique. How many real world security breaches happened because a login prompt that requires physical access limited to 10 tries instead of the "more cautious" limit of 3? God, this comment is funny to me. This is pulled straight from this website ( https://learn.omacom.io/2/the-omarchy-manual/93/security ) > Omarchy takes security extremely seriously. This is meant to be an opera…

>lol Are you saying that a distro that makes this kind of claim shouldn't be concerned with the amount of times you can type in a wrong password? Especially since it's not vetting that actual security of the password itself?

It should, but anything below 100 guesses or so is kind of fine, unless the attacker knows you and has good guesses about your password.

Let's be generous and assume a six character password of all lowercase letters. That's 26^6 possible passwords. That's 3x10^8 possible passwords.

3 guesses means that you have a 0.000001% chance of guessing the password, whereas 10 guesses means your chances are 0.0000032%. Are you worried about a 0.0000022% difference?

The odds are slightly scarier if you limit it to English words, but I still doubt that 3 vs. 10 has any meaningful difference in practical terms.

Re: A Word on Omarchy

#63
post #24
post #2

This blog pranks you with changing titles when you switch tabs (some nsfw), then welcomes you back with a paragraph inciting you to disable Javascript. That's nice, but I actually need Javascript in my browser to do real stuff.

That's what NoScript is for, so you can whitelist the things that need it. Do modern browsers even still offer the built-in option to disable JavaScript unilaterally?

Chrome does

Re: A Word on Omarchy

#64
post #3

I guess Omarchy looks cool but I remember Linux distros being just as cool in 2002 with Enlightenment and many other custom scripts and setups. Unfortunately, Linux on the desktop hasn't moved on much.

On the contrary, linux desktops have IMHO vastly regressed since then (in regards to "cool" factor). I remember when the compiz cube desktop was everywhere; now it feels like everything is bland in comparison.

Yup that was a great demonstration of 3d graphics too. That reminds me all those years in the late 90s and early 2000s when I spent countless hours trying to get the graphics driver working properly with X. Kept running the Gears demo to see if it had sped up, but no, it was still extremely slow.

Still have muscle memory of commands like glxinfo, xdpyinfo etc. ;-)

Re: A Word on Omarchy

#65

Earlier quoted context omitted.

>This is such a reflexive and petty critique. How many real world security breaches happened because a login prompt that requires physical access limited to 10 tries instead of the "more cautious" limit of 3? God, this comment is funny to me. This is pulled straight from this website ( https://learn.omacom.io/2/the-omarchy-manual/93/security ) > Omarchy takes security extremely seriously. This is meant to be an opera…

> lol Are you saying that a distro that makes this kind of claim shouldn't be concerned with the amount of times you can type in a wrong password? I will absolutely say that a distro making that claim should not worry about the difference between 3 and 10 password attempts on sudo (i.e. when you're already logged in). > Especially since it's not vetting that actual security of the password itself? Yes, that should be…

> Yes, that should be fixed. But it's a separate matter.

Sure, because the complexity of your password and the amount of times you get before you're locked out historically don't effect each other lol.

Re: A Word on Omarchy

#66
post #64

Earlier quoted context omitted.

On the contrary, linux desktops have IMHO vastly regressed since then (in regards to "cool" factor). I remember when the compiz cube desktop was everywhere; now it feels like everything is bland in comparison.

Yup that was a great demonstration of 3d graphics too. That reminds me all those years in the late 90s and early 2000s when I spent countless hours trying to get the graphics driver working properly with X. Kept running the Gears demo to see if it had sped up, but no, it was still extremely slow. Still have muscle memory of commands like glxinfo, xdpyinfo etc. ;-)

Actually, that's the funny thing - the reason I qualified that we've regressed specifically in the cool factor is that the rest of it has (mostly) done great, and today the drivers (and hardware, I guess) are in a great place, so we easily could do the fanciest graphics you could ask for, but...

Re: A Word on Omarchy

#67

Earlier quoted context omitted.

> lol Are you saying that a distro that makes this kind of claim shouldn't be concerned with the amount of times you can type in a wrong password? I will absolutely say that a distro making that claim should not worry about the difference between 3 and 10 password attempts on sudo (i.e. when you're already logged in). > Especially since it's not vetting that actual security of the password itself? Yes, that should be…

> Yes, that should be fixed. But it's a separate matter. Sure, because the complexity of your password and the amount of times you get before you're locked out historically don't effect each other lol.

At this scale? No, no they do not. Even if you know my password is a single dictionary word in lower case, the odds of you guessing it in 3 vs 10 guesses is negligible.

In fact, let's do this right now: I've just thought of a random english word and written it down. I'll give you 20 guesses. Guess it right and I'll agree with you.

Re: A Word on Omarchy

#68

Earlier quoted context omitted.

> Yes, that should be fixed. But it's a separate matter. Sure, because the complexity of your password and the amount of times you get before you're locked out historically don't effect each other lol.

At this scale? No, no they do not. Even if you know my password is a single dictionary word in lower case, the odds of you guessing it in 3 vs 10 guesses is negligible. In fact, let's do this right now: I've just thought of a random english word and written it down. I'll give you 20 guesses. Guess it right and I'll agree with you.

This has to be satire. HAS TO BE.

"Hey guys, I'm going to prove that an OS that claims that you don't have to worry about security anymore is actually secure by asking a total stranger to guess my password"

lol.

Re: A Word on Omarchy

#69

Earlier quoted context omitted.

At this scale? No, no they do not. Even if you know my password is a single dictionary word in lower case, the odds of you guessing it in 3 vs 10 guesses is negligible. In fact, let's do this right now: I've just thought of a random english word and written it down. I'll give you 20 guesses. Guess it right and I'll agree with you.

This has to be satire. HAS TO BE. "Hey guys, I'm going to prove that an OS that claims that you don't have to worry about security anymore is actually secure by asking a total stranger to guess my password" lol.

Since it's so flimsy and insecure, you should guess so you can prove how insecure it is. Alternatively, you could fail to do that, because 10 guesses is safe even against an awful password.

Re: A Word on Omarchy

#70

Earlier quoted context omitted.

This has to be satire. HAS TO BE. "Hey guys, I'm going to prove that an OS that claims that you don't have to worry about security anymore is actually secure by asking a total stranger to guess my password" lol.

Since it's so flimsy and insecure, you should guess so you can prove how insecure it is. Alternatively, you could fail to do that, because 10 guesses is safe even against an awful password.

lol But what if, and I know this sounds absolutely insane, the person who stole your laptop knows you and isn't a total stranger on the internet? In your security guru mind, would that effect the probability of them guessing right? Or are you of the opinion that you don't need to worry about people close to you breaking into your stuff?
Post reply on HN