24 ms·
Omarchy development practices lead to predictable security issues
- LelouBil 1mo agoI would love for the omarchy shell to be distro-agnostic, just some dotfiles and binaries you can copy to whatever distro if you have all of the required software
- colesantiago 1mo agoI don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?
- thehappyfellow 1mo agoThere's a difference between a few small bugs because software is new and a half dozen eval(untrusted_input) in version 4.0. Maybe this can get fixed, security teams won't make it worse. I worry they're mopping the floor and not fixing the leak: the development practices which lead to the quantity, seriousness and banality of their security issues is the part which needs fixing.
- Aurornis 1mo ago> Wouldn't the security team and the agents just go and fix the security holes? Of course they’re going to react to what is reported and fix it. That’s a given. The concern is the development process that is leading to these types of holes getting shipped. Mainstream Linux distributions have software practices and release cycles designed to be cautious. This project is taking more of a move fast and break things methodology where shipping the vibe coded feature as fast as possible is the priority. Having a crack team of people responding to reports and fixing things (or prompting their agents to fix things) only solves the issues after they’ve been shipped, discovered, and kindly reported back upstream. > I don't know, Omarchy's team really don't care if you're complaining. Controversy is their primary marketing tactic. They prefer that people complain because being divisive and controversial is how DHH has always marketed his products.
- brightball 1mo agoYea, I don’t get the shade. As many have said, it’s just Arch + a very polished UX preconfigured so you can jump right in without a lot of setup overhead. Why it’s security would be on a different level than any other Linux distro isn’t clear.
- eviks 1mo agoBecause the "polish" is done in an insecure way?
- MarkSweep 1mo agoIt’s a bit more than Arch. There are a bunch of programs written in shell and QML/JavaScript. I guess at least they are using memory-safe languages, but shell scripts make it easier to write the type of shell-injection bug mentioned in the article. Personally if I started a new project in 2026, I would not choose bash and vanilla JavaScript as the languages to write it in. The repo for reference: https://github.com/basecamp/omarchy https://github.com/basecamp/omarchy
- shevy-java 1mo agoIf they are interested in complaints. Probably they do not, so people write blogs on their own. This kind of also happened in the rails world; some people got upset at DHH and then started writing complaints; and many of these complaints are by themselves also total garbage (some are more objective criticism, these tend to be better). It's kind of agenda-based everywhere. > I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing? Well, we can note the time and look again in half a year or so. Personally I am in general happy with security in the linux ecosystem. I am more worried about e. g. systemd adding age sniffing as component. In another entry at hackernews, yesterday I think, we learned that Microsoft automatically tags all images with invisible watermarks. One just can not trust companies - they always feel a need to abuse data from the users and tags everyone. Next step will be mandatory chips into the brain.
- orwin 1mo agoNo, I don't like the style,but author is right here, you cannot secure insecure design. It needs to be reworked from scratch.
- thehappyfellow 1mo agoI'll take that.
- fidotron 1mo agoThis tumblr level of discourse is precisely what the Linux community needs to leave behind.
- pessimizer 1mo ago[flagged]
- cr3ative 1mo agoWhat would you characterise the two linked security reports as, if not holes?
- Cakez0r 1mo agoThe two links are the same same bug. Hardly "full of security holes"
- deleted 1mo ago[deleted]
- pessimizer 1mo agoI would characterize them as "links." As opposed to a discussion of security holes.
- cr3ative 1mo agoI think I would argue that linking to the security problem(s) and then writing about their style and how they probably came to be counts as discussion, but to each their own.
- pessimizer 1mo agoI didn't know security holes had a "style." I suppose their style is "literal Nazi" judging by this thread.
- bewareofscams 1mo ago[flagged]
- jackb4040 1mo ago[flagged]
- colinbartlett 1mo agothis is why i use arch btw
- jehnnysmith 1mo agoIs it pronounced as Omar Chy?
- reverius42 1mo agoOmar Chai?
- jehnnysmith 1mo agoOmar might as well have some Chai
- Sharlin 1mo agoIs it not supposed to be om-archy? (This is the first time I even hear about the project.)
- _august 1mo agoapparently, the r is silent. "oh-mah-chee" https://x.com/dhh/status/2016912045124305303 https://x.com/dhh/status/2016912045124305303
- al_borland 1mo agoDHH pronounces it oo-mah-chi.
- micromacrofoot 1mo agolol of course he does
- shevy-java 1mo agoJust read DHH's blog and then you may quickly realise that other distributions may be a better choice. There is a difference between "opinionated" and ... whatever the content criteria is for DHH nowadays to write stuff on his blog. Younger DHH was more impressive than the TechBro aged later variant, in my personal opinion. Arch is in general a good base though - I mostly use Manjaro as base, then customize it via a ton of scripts and compile about 99% from source anyway, using an extended set of ruby scripts (a bit similar to homebrew, but one big difference is that I wanted versioned AppDirs like in GoboLinux; my scripts originated from GoboLinux's philosophy since I did not want to use shell scripts but retain versioned AppDirs. Manjaro is in some ways a bit similar to oldschool slackware, which unfortunately kind of died - it is not really fully dead, but look at the homepage and then tell me how many years past the last .iso release still counts as alive. So to me it is dead, despite the changelogs still being updated or others, such as alienbob, pushing out new releases.)
- poulpy123 1mo agoGobolinux was really a missed opportunity!
- lab14 1mo agoSurely those won't ever get fixed...
- Hugsbox 1mo agoI'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?
- tonyhart7 1mo agoit get picked up by Hype because DHH
- barkerja 1mo agoIt's being largely driven by DHH (creator of Rails, and co-founder of 37signals). He has a massive following and a lot of influence (and money).
- cogman10 1mo agoLooks like nothing. It's arch with a bunch of pre installed apps and a few goodies on top. My guess is relationships and fame went a long way towards getting those funds.
- theshrike79 1mo agoAnd Dropbox is just rsync and cron =) Packaging and marketing matters.
- Retr0id 1mo agoIt's a political statement disguised as a FOSS project (which itself is fine, all software is political). The funders are not funding the development of a Linux distro, they are co-signing the political statement.
- ngcazz 1mo ago[flagged]
- raverbashing 1mo agoOk I think I see the issue It's lines, lines and more lines of bash script sigh big sigh Using bash for all this stuff is like trying to wash your car with sandpaper instead of soap and water. Yes it can work if you're really careful with it, but in practice no
- rfgplk 1mo agoYep. Considering LLMs spit out Rust/C++ faster & better than Bash no idea why they went this route.
- TiredOfLife 1mo agoWhich distro is not full of bash scripts? It's also funny that all the systemd critics call that bash scripts is all you need
- raverbashing 1mo agoNot in the amount I see there And yes while I got more favourable to Systemd I cannot say bash is all you need, no
- Qbtaumai 1mo agoheh... i still remember the very first time when it came out with it's opinionated branding and all that, looked good and went ahead to try it out but was so annoyed with all the bloats and promoting their software's in it which made me their intentions already clear. I got to know that recently they've added option to remove all the bloats but IDC anymore. not gonna try that ever. Not to mention it was just dotfiles painted on top of arch iso and documentation itself included archinstall guides - if that's a distro then my system with dotfiles are a distro in itself lol... though it looks like they've changed things up now, it looks like it has a iso's and all the stuffs to be called a distro now.
- okinternets 1mo agoI have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.
- dgellow 1mo agoThat feels very astroturfed, it’s just too much too fast
- dewey 1mo agoDHH has a large following, so do many people in this network. His blog posts are often discussed here, it's not really surprising that it gets attention and you don't need secret astroturfing or sneaky marketing if people just share / interact with it themselves organically.
- tfrancisl 1mo agoLiterally funded by Michael Dell and Jack Dorsey. And DHH is just coasting on his ruby on rails clout.
- arrowsmith 1mo agoThey just announced the new "Omacom foundation" last Friday, with $8 million of funding from prominent tech people. That's why it's getting current flurry of attention
- noir_lord 1mo agoIt's been showing up all over YT for a while if you do any searches for Linux. I took a look at it when I kept seeing it, realised what it is and who it's by and carried on moving, putting aside DHH as a person, it doesn't really do anything I want or in a way I'd care about but then I'm also not the target demographic/user, after 30 years of using Linux, I don't need it.
- kristofferR 1mo agoJust hype, it's Kagi all over again. People said the same thing there, we're just too cynical, not used to people getting excited about really cool stuff anymore.
- 1970-01-01 1mo ago>DHH loves to say he's making the year of Linux on desktop happen. I'd stay away just for this reason alone. Anybody that says this is either joking or has no clue how the real world works.
- rvz 1mo ago> Anybody that says this is either joking or has no clue how the real world works. So the "real world" is that Linux failed on the desktop and it is not worth trying, meaning that raising $10M to do this a joke? Would you say the same thing if another distro raised that amount of money? Or is it because DHH is the one doing it. This sort of thinking is why Linux on the Desktop worked for Windows, instead of it becoming mainstream with its own distro.
- 1970-01-01 1mo agoThe "real world" is long term results. Yes, this is a joke amount of money for building an OS if the goal is conquering desktops and holding the territory. It is obvious to everyone the "Year of the Linux Desktop" attitude with only $10M in funding isn't going to end the way they want.
- 1GZ0 1mo agoPretty embarrassing, but its nice to see them actually putting effort into security. https://omarchy.org/security/ https://omarchy.org/security/ Too few upstarts realize that proper security is core to a good experience.
- rfgplk 1mo agoIf they're going agentic and using the stack that they're using (qt/shell scripts?) they'll never patch it in full, if ever. The thing is almost certainly full of injection/forgery attacks, on top of being bloated to oblivion.
- underdeserver 1mo ago"In full" is a tall order that no other OS or distro claims. No reason Qt or quickshell is any different from any other software. Bash is... harder, not impossible. I wouldn't rely on it.
- 0xb0565e486 1mo agoWhen I was a kid my mom had a daycare and had access to a program where she could buy older and used desktops at a discount. I loved installing different operating systems on them and try to customize it. Better window management, better animations, nicer colours etc. Of course, the results were always marginally better or worse than the stock version of that distribution. Seems as this is the case for Omarchy here as well.
- jstimpfle 1mo agoNot following Omarchy, not even sure what it is trying to be compared to existing distros (other than an incredibly hyped up product). Not hating on DHH. But hasn't he become famous for developing a web framework (20 years ago), rather than for his technical prowess as a systems-level engineer? Seeing these kinds of bugs is not exactly unexpected.
- petesergeant 1mo agoI suspect his pitch here is that he knows UX and is technical enough to make it happens, rather than that this is a serious server OS.
- tfrancisl 1mo agoIt has nothing special compared to Arch. In fact, I would argue its just dotfiles for Arch.
- Cakez0r 1mo ago"full of security holes" but the author could only name one (the two links in the opening paragraph are the same issue). Some people just hate DHH and can't separate the art from the artist
- thehappyfellow 1mo agoThey point to two separate issues, what are you about?
- Cakez0r 1mo agoThey're both the same root cause. Command injection in notifications
- omnimus 1mo agoThe artist here being the huge community of linux, arch, hyprland, wayland developers.
- well_ackshually 1mo ago"the artist" the man shat out a collection of half working shell scripts and bad synthwave background images and every wannabe VC bro felt like a haxxor installing it. Fucking hell, even Hannah Montana Linux is of higher quality than Omarchy, the bar is low.
- dzonga 1mo agoeffects of vibe coding + the zealotry like passion of DHH & this is the result.
- thehappyfellow 1mo agoYo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!
- joelthelion 1mo agoNo offense but your title is not informative at all.
- thehappyfellow 1mo agoIt wasn't supposed to be, I found it amusing. Also, the current title is not what I wanted people to take away from the post.
- boesboes 1mo agoProbably so people can understand what the post is about and can skip the rage-bait?
- thehappyfellow 1mo agoHow is my title a rage bait? The current submission title is terrible, "Omarchy development practices lead to predictable security issues" would be much closer.
- rvz 1mo agoAt this point, it looks like some here in the Linux community have a new found hobby of actually liking to get angry at things instead of building, now that AI took away their identity. This is just a person having fun building their own distro. If you don't like it why are you giving them so much attention even though you will never use it?
- sbinnee 1mo agoIt is probably true that it has a big attack surface. But omarchy is no doubt a huge driving force. A few days ago I listened to a podcast dhh talking about the latest major release and its huge donation. I believe it’s now 10m usd or something. I am hopeful that dhh is serious enough to address the security issues plus a lot of ux improvement on linux. In the episode he emphasized 17 layers of security layers where I remember the number solely because I found hard to believe to be honest. You can find the podcast episode in this one https://thestanduppod.com/ https://thestanduppod.com/
- fnoef 1mo agoThere is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.
- noir_lord 1mo agoYour left side of the curve is missing people like me who use Fedora. Been using Linux since 1997, it's been my primary OS since ~2003 (except for gaming and Microsoft seem determine to end their streak on that one) and I use Fedora because I really don't care that much, it's a reliable tool, it has recent packages and I like that it's semi-rolling in that it's a straight forward update every 6ish months. I had my "I must customise and control every single part of my Linux install" phase early (Slackware and Gentoo et al) and then I realised I didn't actually care all that much, give me sane defaults with the ability to tweak if I want to and stability, I'm at the point where "If I have to think much about my OS it's failed in doing what I want" holds.
- HumansEatHumans 1mo ago[dead]
- yza 1mo agoThe right side is Nix
- 0xffff2 1mo agoI completely agree, except you've mirrored the X axis. Ubuntu/Fedora are on the right side; Arch is on the left.
- stavros 1mo agoThat's the midwit meme.
- UK-Al05 1mo agoIsn't most of the security holes still there if used arch and installed the packages yourself. A lot of people complained ssh had security issues in omarchy because it used the default settings. That would still be the same on arch?
- crote 1mo agoArch doesn't market itself as a newbie-friendly opinionated secure-by-default distro. An Arch package having less-than-ideal default settings is pretty normal: the user is expected to read the manpages and the Arch wiki when making any alterations to their system. They guide you towards making it secure, but if you want to leave it insecure because of reasons then Arch isn't going to stop you from shooting your own foot.
- markstos 1mo agoApparently the Omarchy plugin ecosystem is also a free for all like the Arch AUR, except the audience includes people who are new to Linux and less likely to understand the risks.
- throwaway613746 1mo ago[dead]
- sophrosyne42 1mo agoA lot of plugin systems are like that. (See the hyprland, noctalia, or vim/neovim's plugin systems). More generally, how else would a small project allow plugins that isn't "here is a way to add code" and then anyone can release the code they added? Hell, the linux ecosystem in general is a "free for all", and that is the nature of the platform
- dcchambers 1mo agoGiven the choice between a walled garden like Apple's app store or this, give me something open and more risky any day of the week. It's easy enough for Omarchy folks to add "verified" or "trusted" developers down the line.
- rarisma 1mo agolarp discovered to be a larp more news at 11.
- ricardobeat 1mo agoThe two linked issues are for the same bug report. A friend has been urging me to install Omarchy for months. I’ve finally caved in after a horrible experience with highly-praised CachyOS. All I can say is, I understand the hype. It works. The install is uncomplicated, no selecting from five legacy bootloaders, choosing versions or selecting a window manager. The tiled window manager works pretty much how I already use Mac. I like the terminal-focused system tools. Installing software is easy and lightning-fast.
- KeplerBoy 1mo agoIsn't Omarchy very, very similar to cachyos?
- TiredOfLife 1mo agoCachyOS has a choice of 3 bootloaders and 17 desktop environments On omarchy it's one and one
- aloisdg 1mo agoBoth are arched-based. CachyOS is not made by a fascist.
- KetoManx64 29d ago> Guy says he doesn't want peoples political beliefs barfed all over his project. HE'S A FASCIST.
- NewJazz 27d agoYeah that's not what he said.
- KetoManx64 27d agoCachyOS team has very openly pushed its politics and believes that parents should have the right to transition the gender of their children and if you disagree you get permanently banned from their forums. DHH said he think that too many projects are spewing their politics all over their projects and its gross and they should focus on their code.
- dborovikov 1mo ago“Full of security holes" - and two examples in the article have been swiftly addressed, ignoring that there is a whole dedicated security team https://omarchy.org/teams/ https://omarchy.org/teams/ What kind of blogging is this?
- thehappyfellow 1mo ago> What kind of blogging is this? Happy to explain: it's personal blogging, for writing down what's on my mind. The fact that it was addressed swiftly doesn't affect the claims in the post at all: I'm worried about development practices which produce code like that. Also, the "full of security holes" is not my framing, someone else choose this submission title.
- hypfer 1mo agoThe problem with those two picked examples is that their nature displays a lack of basic care and due diligence. Of course, this is a culture war, but the point the blog post is making is that the Omarchy side is not exactly at the forefront of merit.
- dborovikov 1mo agoThey move fast, that's for sure. But it also means they explore and fix problems fast. I don't think there is only "slow and careful" way to create things.
- donatj 1mo agoThe same kind as a similar recent post [1] where a person pointed out a bunch of problems with Omarchy's shell scripts as examples of it being terrible. Open a pull request. That's how this is supposed to work. Wisdom of the crowd and what not. 1. https://xn--gckvb8fzb.com/a-word-on-omarchy/ https://xn--gckvb8fzb.com/a-word-on-omarchy/
- thehappyfellow 1mo agoWhy would I do that? It's a crazy non-sequitur. My opinion is that the way Omarchy is developed leads to gigantic security holes. I wanted people to be aware of it. In my opinion, there are much better choices both for me and I'd imagine for other people as well. I don't want to help Omarchy succeed, I don't care about them.
- tangue 1mo agoHey and Basecamp suck. Basic features like search barely work, the iOS and Android apps are embarrassingly bad, and the UI looks like it was designed for Netscape Navigator 4. With Rails, dhh spent years trying to work around JavaScript , leaving the framework increasingly difficult to recommend in 2026. Why on earth would you trust him with your OS ? Even if you share his politics, you deserve better software.
- zvmaz 1mo agoThe "distribution" made by... DHH. No, I can't, thanks. For people who don't know, just read "As I Remember London" by this person. Sure, arguments can be made in favor of being "above all these things," but profound moral disgust can also be a legitimate argument.
- pelagicAustral 1mo agoObviously every single loaded take on this distro has already been taken, on this thread alone. So there is little anybody can add to it... all I would say is that no publicity is bad publicity and if that's the intention, then well done. I am happy that the Linux ecosystem is getting attention, traction and funding. People that dont like and want to choose to go die on another hill, so be it, their prerogative.
- vcryan 1mo agoLook - I'm am the opposite of DHH fan -- that said -- they could fix all these bugs/security issues that same way they created them. It makes sense to some extent to create a product that emphasized what is different about it from a feature/UX perspective so people can consider if it would even be useful to them at all. If they can prove that they have created something useful - then they can fix all these issues. Fixing these issues is not hard. Creating a useful product that people want -- this is the hard part.
- thehappyfellow 1mo agoThey are amazingly good at creating hype (non-derogatory) and getting users. Their docs say "Omarchy takes security very seriously" - I think that's straight up incorrect. Saying "go and use it, wanting: its prototype quality and likely to have many security bugs" would be fair game. That's not what they're doing.
- vcryan 1mo agoYes, 37Signals DHH have an amazing gift for taking something that is old and not interesting and getting a lot of attention for making it seem new and innovative. That is a gift!
- kristofferR 1mo ago> Creating a useful product that people want -- this is the hard part. When you do that you'll just a bunch of people clowning on the project due to the politics of the founder.
- samsep0il 1mo agothis is not what they say https://github.com/basecamp/omarchy/blob/quattro/manual/48-security.md https://github.com/basecamp/omarchy/blob/quattro/manual/48-s...
- TacticalCoder 1mo ago> ... collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine. Bash injection using video... Titles !? Moterfucking shit (mom's not there anymore to ask me to swear less, RIP)
- themacguffinman 1mo agoReminds me of the bit about security in Steve Yegge's Google Platforms rant: > But I'll argue that Accessibility is actually more important than Security because dialing Accessibility to zero means you have no product at all, whereas dialing Security to zero can still get you a reasonably successful product such as the Playstation Network.
- chalmovsky 1mo agoone cherry on top is that all the agent harnesses installed with omarchy have the “yolo” mode on by default
- vova_hn2 1mo agoOkay, but how cool is that this feature (hotkey to pass a video, that is open in the browser, to yt-dlp) exists and works out of the box? It's unfortunate, that it was developed in a weird, insecure way, but I think that the fact that it exists is very cool. I've heard about Omarchy long time ago, but didn't switch, because at some point in my life I started to prefer something that is rock solid and well supported (currently on Fedora Atomic with KDE) to new/shiny/bleeding edge. But still. I think that an overall good UX out of the box is composed of little things like this.
- rideontime 1mo agoNot very? Why would a TOS-violating feature like this be included as a default feature of an OS?
- veeti 1mo agoGod forbid an operating system existed for its users, not the system.
- easterncalculus 27d agoIt's really incredible how so many of the people that in one thread will talk about workers rights will also come out to bat for some tech company's TOS. Whatever your worldview is it's definitely not about freedom over authoritarianism.
- voidfunc 1mo agoIt's a relatively new distro. They'll figure it out. I like what DHH is doing in this space even if I don't plan to use it.
- deleted 1mo ago[deleted]
- hello_dang_ 1mo ago[dead]
- codaphiliac 1mo agoRich tech bros midlife crisis
- bdcravens 1mo agoMany of the hot takes on why Omarchy is bad based on the opinions of the creator are coming from those who ironically use JavaScript.
- devops000 1mo agoYou can submit a PR to fix security issues.
- spro113 29d agoThe article seem biased against Linux. All major OS had a history of weird security issues. Ubuntu, the most popular Linux distro for desktop, had a lot too: CVE-2019-11482 CVE-2019-11483 CVE-2020-8831 all look like repeating the same mistakes over and over. And if you start digging you'll come over to really strange and bizzare ones like obvious attempts to sneak in exploits into popular libraries like openssl.
- dxsecarch 24d agoI am just worried about the amount of vulnerabilities this development practices introduce
- allthetime 24d agoLol. Just install a solid modern distro (OpenSUSE, Fedora, Mint, etc.) and use an LLM to help you set it up the way you want. It will take you an hour, then you will have a clean system that is yours, and not whatever this is... Seriously, watch this recent interview with DHH about Omarchy https://www.youtube.com/watch?v=MWvH7BRgwL8 https://www.youtube.com/watch?v=MWvH7BRgwL8 and then tell me you want to buy in to this guy vibe coding your entire OS for you. There's all sorts of strong manic/amphetamine vibes oozing off of him.