logoalt Hacker News

Omarchy: Any User Process Can Escalate to Root

482 pointsby trap0xccyesterday at 3:59 PM462 commentsview on HN

Comments

trentoryesterday at 5:39 PM

I genuinely put companies that invested in this on my blacklist. I don't care about the politics behind it. His whole persona is and was to be edgy and cruel so nothing will change here. But there are probably millions of oss projects that deserve the funding more.

ghthoryesterday at 11:58 PM

If you editing your system config with an LLM and tool calls, why wouldn’t you just use NixOS. At least if the agent broke your system, you can basically recreate it from scratch in under 30mins (some things still might be outside the system/home-manager config). But yeah, then you get diffs of what the agent changed in a nixos/home-manager change.

I see almost zero reason for anyone to use anything else for they’re base system at this point.

Mon0t0nyesterday at 9:51 PM

why would anyone use this distro when there are so many options? genuine question.

show 1 reply
Cameriyesterday at 11:46 PM

Was this vulnerability disclosed responsibly by the author?

show 1 reply
porridgeraisinyesterday at 5:22 PM

I mean, I saw this on twitter, and thought ok maybe its a nice exploit. But really? its the usual docker root thing?

I wouldn't even consider that a vulnerability tbh, every personal laptop I had I add myself to docker group. Yes, you can not namespace pids, filesystem, etc, and get root, but it's never mattered.

If someone can run that docker command, they can already read your whole homedir, edit bashrc, etc etc,. and sudo is useless anyways.

Only on a system where you are a user without sudo access, does it even begin to make sense. And if you go to the trouble of intentionally setting up a user without sudo access, you wouldn't be adding that user to the docker group either. In the default install, I assume omarchy adds you to the sudoers as well, making this a perfectly ok thing to do

Even if you participate in the esteemed Red Hat Security Theater and use wayland, flatpaks, etc, most flatpaks can write anywhere in your home dir, so they can do this too.

On standard linux desktop, sudo is not really security, but it is a UX improvement as it adds friction to accidentally doing things to the "system".

[I don't use omarchy]

shevy-javayesterday at 10:41 PM

That's some fame now.

randersonyesterday at 9:16 PM

The likelihood of Omarchy being hacked is no doubt compounded by the number of enemies DHH has created who would love to see him fail.

ThePowerOfFuetyesterday at 9:29 PM

>the most important takeaway is simple: update to 4.0.1.

I gotta say, that is not the most important takeaway for me; rather, "don't walk, run".

lelotayesterday at 5:50 PM

Other day i was hearing DHH talk on Lex's podcast on Omarchy and how he does not look at the code anymore. The guy built solid reputation with his prev contributions but now falling to AI slop.

show 2 replies
zsoltkacsandiyesterday at 6:47 PM

That is what happens when someone without a clue what is he (khm, DHH) doing vibe codes a distro.

misterchephyesterday at 7:25 PM

No way, the vibecoded distro has security problems!?!?! WTF, didn't DHH ask claude to check for security issues?

hollow-moeyesterday at 5:21 PM

10M for a some shell scripts what a steal lmao

0x5150today at 5:36 AM

[dead]

itsObviousToAlltoday at 2:34 AM

[dead]

databusinessaitoday at 12:13 AM

[dead]

coursenumplsyesterday at 11:54 PM

[dead]

remusrmyesterday at 7:15 PM

[dead]

phoronixrlyyesterday at 4:32 PM

[flagged]

rfgplkyesterday at 5:45 PM

I've already stated this on the last Omarchy thread, the way DHH is implementing it is highly irresponsible and insecure. Half of his "distro" are essentially shell scripts where it's extremely easy to create accidental security holes. Considering that probably half of his code would need something like setuid/execute bits set in order to avoid configuration spaghetti, I'd imagine that there are _hundreds_ of vulnerabilities in there. If you think about it logically, just the desktop environment (note that I have no idea if he coded his own or is using an existing one) needs access to input the graphics driver the netstack all of which require priviledges of some kind.

show 1 reply
addajonesyesterday at 6:13 PM

Sad that people just complain about what DHH is doing and how he doesn't know anything. Nobody is forcing anybody to use Omarchy at all. Also $10 million was raised by him for it, did anybody else here raise that for a distro? I'm tired of the constant complaining and criticizing. Nobody said you have to use it.

show 3 replies
numpad0yesterday at 7:21 PM

ot fyi: "omarchy" is fine as a creative spelling for omachi, but "omacon" / "omacom" has extremely low Levenshtein distance with the honorific form of the word for human female reproductive component in japanese

show 1 reply