logoalt Hacker News

concindsyesterday at 5:01 PM11 repliesview on HN

A few days ago someone found they were flowing USB descriptors straight into the shell.

https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8...

Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?


Replies

teekertyesterday at 5:51 PM

But, this “vulnerability” is the thing everybody knows about docker since forever. I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year. What is different here?

Start a docker container with the docker socket mounted in the container and now you can have yourself mount / as rw. Everybody knows this. How is everybody so shocked here. Many instructions online tell you to make yourself part of the docker group for convenience (like the digital ocean one).

show 11 replies
dzongayesterday at 5:26 PM

the unfortunate thing - is the money pumped into omarchy + the hype around it .... a lot of sheepish followers will just follow the hype.

the tech might gets fixed later.

show 2 replies
silisiliyesterday at 5:14 PM

Other than hype, what's the appeal here?

I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.

show 12 replies
zer0zzztoday at 4:25 AM

> It's why you switched away from Windows in the first place, remember?

Really good reminder I gotta say

TZubiritoday at 3:06 AM

>If you use Omarchy, the most important takeaway is simple: update to 4.0.1.

More like, don't use Omarchy, or vibecoded Operating Systems.

Running a descriptor into a shell command is laughably sloppish.

jp_scyesterday at 5:13 PM

It's definitely not why *I* switched away from Windows

show 1 reply
onesandofgrainyesterday at 5:17 PM

This seems to be quite contrarian considering we had this on the front page of HN the other day: "Debian votes to allow "responsible use of generative AI".

I guess this LLM coding wasn't "Responsible" enough. hahaha

Let the AI bubble pop baby

show 1 reply
sergiotapiayesterday at 7:22 PM

On the flipside, once you use an OS that is totally open to agentic stuff, there's no going back really.

I can open Pi and ask it to fix some window tiling issue, help me install shortcuts, help me figure out how to install flatpak vs appimage, etc. the list is endless. I cannot see myself going back to a legacy OS unless I'm forced to by my job for compliance reasons.

show 2 replies
lokipumperyesterday at 6:13 PM

Vibecoded fixes are quicker

mike_hearnyesterday at 5:27 PM

"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).

show 4 replies