13 ms·
Omarchy development practices lead to predictable security issues
- dxsecarch 15d agoI am just worried about the amount of vulnerabilities this development practices introduce
- allthetime 14d agoLol. Just install a solid modern distro (OpenSUSE, Fedora, Mint, etc.) and use an LLM to help you set it up the way you want. It will take you an hour, then you will have a clean system that is yours, and not whatever this is... Seriously, watch this recent interview with DHH about Omarchy https://www.youtube.com/watch?v=MWvH7BRgwL8 https://www.youtube.com/watch?v=MWvH7BRgwL8 and then tell me you want to buy in to this guy vibe coding your entire OS for you. There's all sorts of strong manic/amphetamine vibes oozing off of him.
- colesantiago 22d agoI don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?
- orwin 22d agoNo, I don't like the style,but author is right here, you cannot secure insecure design. It needs to be reworked from scratch.
- thehappyfellow 22d agoI'll take that.
- thehappyfellow 22d agoThere's a difference between a few small bugs because software is new and a half dozen eval(untrusted_input) in version 4.0. Maybe this can get fixed, security teams won't make it worse. I worry they're mopping the floor and not fixing the leak: the development practices which lead to the quantity, seriousness and banality of their security issues is the part which needs fixing.
- Aurornis 22d ago> Wouldn't the security team and the agents just go and fix the security holes? Of course they’re going to react to what is reported and fix it. That’s a given. The concern is the development process that is leading to these types of holes getting shipped. Mainstream Linux distributions have software practices and release cycles designed to be cautious. This project is taking more of a move fast and break things methodology where shipping the vibe coded feature as fast as possible is the priority. Having a crack team of people responding to reports and fixing things (or prompting their agents to fix things) only solves the issues after they’ve been shipped, discovered, and kindly reported back upstream. > I don't know, Omarchy's team really don't care if you're complaining. Controversy is their primary marketing tactic. They prefer that people complain because being divisive and controversial is how DHH has always marketed his products.
- brightball 22d agoYea, I don’t get the shade. As many have said, it’s just Arch + a very polished UX preconfigured so you can jump right in without a lot of setup overhead. Why it’s security would be on a different level than any other Linux distro isn’t clear.
- eviks 22d agoBecause the "polish" is done in an insecure way?
- MarkSweep 22d agoIt’s a bit more than Arch. There are a bunch of programs written in shell and QML/JavaScript. I guess at least they are using memory-safe languages, but shell scripts make it easier to write the type of shell-injection bug mentioned in the article. Personally if I started a new project in 2026, I would not choose bash and vanilla JavaScript as the languages to write it in. The repo for reference: https://github.com/basecamp/omarchy https://github.com/basecamp/omarchy
- shevy-java 22d agoIf they are interested in complaints. Probably they do not, so people write blogs on their own. This kind of also happened in the rails world; some people got upset at DHH and then started writing complaints; and many of these complaints are by themselves also total garbage (some are more objective criticism, these tend to be better). It's kind of agenda-based everywhere. > I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing? Well, we can note the time and look again in half a year or so. Personally I am in general happy with security in the linux ecosystem. I am more worried about e. g. systemd adding age sniffing as component. In another entry at hackernews, yesterday I think, we learned that Microsoft automatically tags all images with invisible watermarks. One just can not trust companies - they always feel a need to abuse data from the users and tags everyone. Next step will be mandatory chips into the brain.
- fidotron 22d agoThis tumblr level of discourse is precisely what the Linux community needs to leave behind.
- pessimizer 22d ago[flagged]
- HumansEatHumans 22d ago[dead]
- cr3ative 22d agoWhat would you characterise the two linked security reports as, if not holes?
- Cakez0r 22d agoThe two links are the same same bug. Hardly "full of security holes"
- deleted 22d ago[deleted]
- pessimizer 22d agoI would characterize them as "links." As opposed to a discussion of security holes.
- cr3ative 22d agoI think I would argue that linking to the security problem(s) and then writing about their style and how they probably came to be counts as discussion, but to each their own.
- pessimizer 22d ago
- bewareofscams 22d ago[flagged]
- jackb4040 22d ago[flagged]
- colinbartlett 22d agothis is why i use arch btw
- jehnnysmith 22d agoIs it pronounced as Omar Chy?
- reverius42 22d agoOmar Chai?
- jehnnysmith 22d agoOmar might as well have some Chai
- Sharlin 22d agoIs it not supposed to be om-archy? (This is the first time I even hear about the project.)
- _august 22d agoapparently, the r is silent. "oh-mah-chee" https://x.com/dhh/status/2016912045124305303 https://x.com/dhh/status/2016912045124305303
- al_borland 22d agoDHH pronounces it oo-mah-chi.
- micromacrofoot 22d agolol of course he does
- shevy-java 22d agoJust read DHH's blog and then you may quickly realise that other distributions may be a better choice. There is a difference between "opinionated" and ... whatever the content criteria is for DHH nowadays to write stuff on his blog. Younger DHH was more impressive than the TechBro aged later variant, in my personal opinion. Arch is in general a good base though - I mostly use Manjaro as base, then customize it via a ton of scripts and compile about 99% from source anyway, using an extended set of ruby scripts (a bit similar to homebrew, but one big difference is that I wanted versioned AppDirs like in GoboLinux; my scripts originated from GoboLinux's philosophy since I did not want to use shell scripts but retain versioned AppDirs. Manjaro is in some ways a bit similar to oldschool slackware, which unfortunately kind of died - it is not really fully dead, but look at the homepage and then tell me how many years past the last .iso release still counts as alive. So to me it is dead, despite the changelogs still being updated or others, such as alienbob, pushing out new releases.)
- poulpy123 22d agoGobolinux was really a missed opportunity!
- lab14 22d agoSurely those won't ever get fixed...
- Hugsbox 22d agoI'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?
- throwaway613746 22d ago[dead]
- tonyhart7 22d agoit get picked up by Hype because DHH
- barkerja 22d agoIt's being largely driven by DHH (creator of Rails, and co-founder of 37signals). He has a massive following and a lot of influence (and money).
- cogman10 22d agoLooks like nothing. It's arch with a bunch of pre installed apps and a few goodies on top. My guess is relationships and fame went a long way towards getting those funds.
- theshrike79 20d agoAnd Dropbox is just rsync and cron =) Packaging and marketing matters.
- Retr0id 22d agoIt's a political statement disguised as a FOSS project (which itself is fine, all software is political). The funders are not funding the development of a Linux distro, they are co-signing the political statement.
- 22d ago
- raverbashing 22d agoOk I think I see the issue It's lines, lines and more lines of bash script sigh big sigh Using bash for all this stuff is like trying to wash your car with sandpaper instead of soap and water. Yes it can work if you're really careful with it, but in practice no
- TiredOfLife 22d agoWhich distro is not full of bash scripts? It's also funny that all the systemd critics call that bash scripts is all you need
- raverbashing 22d agoNot in the amount I see there And yes while I got more favourable to Systemd I cannot say bash is all you need, no
- rfgplk 22d agoYep. Considering LLMs spit out Rust/C++ faster & better than Bash no idea why they went this route.
- Qbtaumai 22d agoheh... i still remember the very first time when it came out with it's opinionated branding and all that, looked good and went ahead to try it out but was so annoyed with all the bloats and promoting their software's in it which made me their intentions already clear. I got to know that recently they've added option to remove all the bloats but IDC anymore. not gonna try that ever. Not to mention it was just dotfiles painted on top of arch iso and documentation itself included archinstall guides - if that's a distro then my system with dotfiles are a distro in itself lol... though it looks like they've changed things up now, it looks like it has a iso's and all the stuffs to be called a distro now.
- okinternets 22d agoI have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.
- dgellow 22d agoThat feels very astroturfed, it’s just too much too fast
- dewey 22d agoDHH has a large following, so do many people in this network. His blog posts are often discussed here, it's not really surprising that it gets attention and you don't need secret astroturfing or sneaky marketing if people just share / interact with it themselves organically.
- tfrancisl 22d agoLiterally funded by Michael Dell and Jack Dorsey. And DHH is just coasting on his ruby on rails clout.
- arrowsmith 22d agoThey just announced the new "Omacom foundation" last Friday, with $8 million of funding from prominent tech people. That's why it's getting current flurry of attention
- noir_lord 22d agoIt's been showing up all over YT for a while if you do any searches for Linux. I took a look at it when I kept seeing it, realised what it is and who it's by and carried on moving, putting aside DHH as a person, it doesn't really do anything I want or in a way I'd care about but then I'm also not the target demographic/user, after 30 years of using Linux, I don't need it.
- kristofferR 22d agoJust hype, it's Kagi all over again. People said the same thing there, we're just too cynical, not used to people getting excited about really cool stuff anymore.
- 1970-01-01 22d ago>DHH loves to say he's making the year of Linux on desktop happen. I'd stay away just for this reason alone. Anybody that says this is either joking or has no clue how the real world works.
- rvz 22d ago> Anybody that says this is either joking or has no clue how the real world works. So the "real world" is that Linux failed on the desktop and it is not worth trying, meaning that raising $10M to do this a joke? Would you say the same thing if another distro raised that amount of money? Or is it because DHH is the one doing it. This sort of thinking is why Linux on the Desktop worked for Windows, instead of it becoming mainstream with its own distro.
- 1970-01-01 22d agoThe "real world" is long term results. Yes, this is a joke amount of money for building an OS if the goal is conquering desktops and holding the territory. It is obvious to everyone the "Year of the Linux Desktop" attitude with only $10M in funding isn't going to end the way they want.
- 1GZ0 22d agoPretty embarrassing, but its nice to see them actually putting effort into security. https://omarchy.org/security/ https://omarchy.org/security/ Too few upstarts realize that proper security is core to a good experience.
- rfgplk 22d agoIf they're going agentic and using the stack that they're using (qt/shell scripts?) they'll never patch it in full, if ever. The thing is almost certainly full of injection/forgery attacks, on top of being bloated to oblivion.
- underdeserver 22d ago"In full" is a tall order that no other OS or distro claims. No reason Qt or quickshell is any different from any other software. Bash is... harder, not impossible. I wouldn't rely on it.
- 0xb0565e486 22d agoWhen I was a kid my mom had a daycare and had access to a program where she could buy older and used desktops at a discount. I loved installing different operating systems on them and try to customize it. Better window management, better animations, nicer colours etc. Of course, the results were always marginally better or worse than the stock version of that distribution. Seems as this is the case for Omarchy here as well.
- jstimpfle 22d agoNot following Omarchy, not even sure what it is trying to be compared to existing distros (other than an incredibly hyped up product). Not hating on DHH. But hasn't he become famous for developing a web framework (20 years ago), rather than for his technical prowess as a systems-level engineer? Seeing these kinds of bugs is not exactly unexpected.
- petesergeant 22d agoI suspect his pitch here is that he knows UX and is technical enough to make it happens, rather than that this is a serious server OS.
- tfrancisl 22d agoIt has nothing special compared to Arch. In fact, I would argue its just dotfiles for Arch.
- Cakez0r 22d ago"full of security holes" but the author could only name one (the two links in the opening paragraph are the same issue). Some people just hate DHH and can't separate the art from the artist
- thehappyfellow 22d agoThey point to two separate issues, what are you about?
- Cakez0r 22d agoThey're both the same root cause. Command injection in notifications
- omnimus 22d agoThe artist here being the huge community of linux, arch, hyprland, wayland developers.
- well_ackshually 22d ago"the artist" the man shat out a collection of half working shell scripts and bad synthwave background images and every wannabe VC bro felt like a haxxor installing it. Fucking hell, even Hannah Montana Linux is of higher quality than Omarchy, the bar is low.
- dzonga 22d agoeffects of vibe coding + the zealotry like passion of DHH & this is the result.
- thehappyfellow 22d agoYo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!
- joelthelion 22d agoNo offense but your title is not informative at all.
- thehappyfellow 22d agoIt wasn't supposed to be, I found it amusing. Also, the current title is not what I wanted people to take away from the post.
- boesboes 22d agoProbably so people can understand what the post is about and can skip the rage-bait?
- thehappyfellow 22d agoHow is my title a rage bait? The current submission title is terrible, "Omarchy development practices lead to predictable security issues" would be much closer.
- rvz 22d agoAt this point, it looks like some here in the Linux community have a new found hobby of actually liking to get angry at things instead of building, now that AI took away their identity. This is just a person having fun building their own distro. If you don't like it why are you giving them so much attention even though you will never use it?
- sbinnee 22d agoIt is probably true that it has a big attack surface. But omarchy is no doubt a huge driving force. A few days ago I listened to a podcast dhh talking about the latest major release and its huge donation. I believe it’s now 10m usd or something. I am hopeful that dhh is serious enough to address the security issues plus a lot of ux improvement on linux. In the episode he emphasized 17 layers of security layers where I remember the number solely because I found hard to believe to be honest. You can find the podcast episode in this one https://thestanduppod.com/ https://thestanduppod.com/
- fnoef 22d agoThere is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.
- noir_lord 22d agoYour left side of the curve is missing people like me who use Fedora. Been using Linux since 1997, it's been my primary OS since ~2003 (except for gaming and Microsoft seem determine to end their streak on that one) and I use Fedora because I really don't care that much, it's a reliable tool, it has recent packages and I like that it's semi-rolling in that it's a straight forward update every 6ish months. I had my "I must customise and control every single part of my Linux install" phase early (Slackware and Gentoo et al) and then I realised I didn't actually care all that much, give me sane defaults with the ability to tweak if I want to and stability, I'm at the point where "If I have to think much about my OS it's failed in doing what I want" holds.
- HumansEatHumans 22d ago[dead]
- yza 22d agoThe right side is Nix
- 0xffff2 22d agoI completely agree, except you've mirrored the X axis. Ubuntu/Fedora are on the right side; Arch is on the left.
- stavros 21d agoThat's the midwit meme.
- UK-Al05 22d agoIsn't most of the security holes still there if used arch and installed the packages yourself. A lot of people complained ssh had security issues in omarchy because it used the default settings. That would still be the same on arch?
- crote 22d agoArch doesn't market itself as a newbie-friendly opinionated secure-by-default distro. An Arch package having less-than-ideal default settings is pretty normal: the user is expected to read the manpages and the Arch wiki when making any alterations to their system. They guide you towards making it secure, but if you want to leave it insecure because of reasons then Arch isn't going to stop you from shooting your own foot.
- markstos 22d agoApparently the Omarchy plugin ecosystem is also a free for all like the Arch AUR, except the audience includes people who are new to Linux and less likely to understand the risks.
- throwaway613746 22d ago[dead]
- sophrosyne42 22d agoA lot of plugin systems are like that. (See the hyprland, noctalia, or vim/neovim's plugin systems). More generally, how else would a small project allow plugins that isn't "here is a way to add code" and then anyone can release the code they added? Hell, the linux ecosystem in general is a "free for all", and that is the nature of the platform
- dcchambers 22d agoGiven the choice between a walled garden like Apple's app store or this, give me something open and more risky any day of the week. It's easy enough for Omarchy folks to add "verified" or "trusted" developers down the line.
- rarisma 22d agolarp discovered to be a larp more news at 11.
- ricardobeat 22d agoThe two linked issues are for the same bug report. A friend has been urging me to install Omarchy for months. I’ve finally caved in after a horrible experience with highly-praised CachyOS. All I can say is, I understand the hype. It works. The install is uncomplicated, no selecting from five legacy bootloaders, choosing versions or selecting a window manager. The tiled window manager works pretty much how I already use Mac. I like the terminal-focused system tools. Installing software is easy and lightning-fast.
- gilrain 22d agoSo, a Linux distribution.
- simlevesque 22d agoIt's a bash script over a distribution.
- KeplerBoy 22d agoIsn't Omarchy very, very similar to cachyos?
- TiredOfLife 22d agoCachyOS has a choice of 3 bootloaders and 17 desktop environments On omarchy it's one and one
- aloisdg 22d agoBoth are arched-based. CachyOS is not made by a fascist.
- KetoManx64 19d ago> Guy says he doesn't want peoples political beliefs barfed all over his project. HE'S A FASCIST.
- 18d ago
- dborovikov 22d ago“Full of security holes" - and two examples in the article have been swiftly addressed, ignoring that there is a whole dedicated security team https://omarchy.org/teams/ https://omarchy.org/teams/ What kind of blogging is this?
- thehappyfellow 22d ago> What kind of blogging is this? Happy to explain: it's personal blogging, for writing down what's on my mind. The fact that it was addressed swiftly doesn't affect the claims in the post at all: I'm worried about development practices which produce code like that. Also, the "full of security holes" is not my framing, someone else choose this submission title.
- hypfer 22d agoThe problem with those two picked examples is that their nature displays a lack of basic care and due diligence. Of course, this is a culture war, but the point the blog post is making is that the Omarchy side is not exactly at the forefront of merit.
- dborovikov 22d agoThey move fast, that's for sure. But it also means they explore and fix problems fast. I don't think there is only "slow and careful" way to create things.
- donatj 22d agoThe same kind as a similar recent post [1] where a person pointed out a bunch of problems with Omarchy's shell scripts as examples of it being terrible. Open a pull request. That's how this is supposed to work. Wisdom of the crowd and what not. 1. https://xn--gckvb8fzb.com/a-word-on-omarchy/ https://xn--gckvb8fzb.com/a-word-on-omarchy/
- thehappyfellow 22d agoWhy would I do that? It's a crazy non-sequitur. My opinion is that the way Omarchy is developed leads to gigantic security holes. I wanted people to be aware of it. In my opinion, there are much better choices both for me and I'd imagine for other people as well. I don't want to help Omarchy succeed, I don't care about them.
- tangue 22d agoHey and Basecamp suck. Basic features like search barely work, the iOS and Android apps are embarrassingly bad, and the UI looks like it was designed for Netscape Navigator 4. With Rails, dhh spent years trying to work around JavaScript , leaving the framework increasingly difficult to recommend in 2026. Why on earth would you trust him with your OS ? Even if you share his politics, you deserve better software.
- zvmaz 22d agoThe "distribution" made by... DHH. No, I can't, thanks. For people who don't know, just read "As I Remember London" by this person. Sure, arguments can be made in favor of being "above all these things," but profound moral disgust can also be a legitimate argument.
- pelagicAustral 22d agoObviously every single loaded take on this distro has already been taken, on this thread alone. So there is little anybody can add to it... all I would say is that no publicity is bad publicity and if that's the intention, then well done. I am happy that the Linux ecosystem is getting attention, traction and funding. People that dont like and want to choose to go die on another hill, so be it, their prerogative.
- vcryan 22d agoLook - I'm am the opposite of DHH fan -- that said -- they could fix all these bugs/security issues that same way they created them. It makes sense to some extent to create a product that emphasized what is different about it from a feature/UX perspective so people can consider if it would even be useful to them at all. If they can prove that they have created something useful - then they can fix all these issues. Fixing these issues is not hard. Creating a useful product that people want -- this is the hard part.
- thehappyfellow 22d agoThey are amazingly good at creating hype (non-derogatory) and getting users. Their docs say "Omarchy takes security very seriously" - I think that's straight up incorrect. Saying "go and use it, wanting: its prototype quality and likely to have many security bugs" would be fair game. That's not what they're doing.
- vcryan 22d agoYes, 37Signals DHH have an amazing gift for taking something that is old and not interesting and getting a lot of attention for making it seem new and innovative. That is a gift!
- kristofferR 22d ago> Creating a useful product that people want -- this is the hard part. When you do that you'll just a bunch of people clowning on the project due to the politics of the founder.
- samsep0il 22d agothis is not what they say https://github.com/basecamp/omarchy/blob/quattro/manual/48-security.md https://github.com/basecamp/omarchy/blob/quattro/manual/48-s...
- TacticalCoder 22d ago> ... collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine. Bash injection using video... Titles !? Moterfucking shit (mom's not there anymore to ask me to swear less, RIP)
- LelouBil 22d agoI would love for the omarchy shell to be distro-agnostic, just some dotfiles and binaries you can copy to whatever distro if you have all of the required software
- themacguffinman 22d agoReminds me of the bit about security in Steve Yegge's Google Platforms rant: > But I'll argue that Accessibility is actually more important than Security because dialing Accessibility to zero means you have no product at all, whereas dialing Security to zero can still get you a reasonably successful product such as the Playstation Network.
- chalmovsky 22d agoone cherry on top is that all the agent harnesses installed with omarchy have the “yolo” mode on by default
- vova_hn2 22d agoOkay, but how cool is that this feature (hotkey to pass a video, that is open in the browser, to yt-dlp) exists and works out of the box? It's unfortunate, that it was developed in a weird, insecure way, but I think that the fact that it exists is very cool. I've heard about Omarchy long time ago, but didn't switch, because at some point in my life I started to prefer something that is rock solid and well supported (currently on Fedora Atomic with KDE) to new/shiny/bleeding edge. But still. I think that an overall good UX out of the box is composed of little things like this.
- rideontime 22d agoNot very? Why would a TOS-violating feature like this be included as a default feature of an OS?
- veeti 21d agoGod forbid an operating system existed for its users, not the system.
- easterncalculus 18d agoIt's really incredible how so many of the people that in one thread will talk about workers rights will also come out to bat for some tech company's TOS. Whatever your worldview is it's definitely not about freedom over authoritarianism.
- voidfunc 22d agoIt's a relatively new distro. They'll figure it out. I like what DHH is doing in this space even if I don't plan to use it.
- deleted 22d ago[deleted]
- hello_dang_ 22d ago[dead]
- codaphiliac 22d agoRich tech bros midlife crisis
- bdcravens 22d agoMany of the hot takes on why Omarchy is bad based on the opinions of the creator are coming from those who ironically use JavaScript.
- devops000 21d agoYou can submit a PR to fix security issues.
- spro113 20d agoThe article seem biased against Linux. All major OS had a history of weird security issues. Ubuntu, the most popular Linux distro for desktop, had a lot too: CVE-2019-11482 CVE-2019-11483 CVE-2020-8831 all look like repeating the same mistakes over and over. And if you start digging you'll come over to really strange and bizzare ones like obvious attempts to sneak in exploits into popular libraries like openssl.