8 ms·
It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
by exitb 18d ago
It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
- gruez 18d ago>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.
- bardsore 18d agoAdding your user to the docker group is in the official Docker install instructions, I wouldn't call that "random copy paste guides".
- gruez 18d agoYou mean the optional post install instructions, which is a separate page from the main install instructions, and contains a giant warning about the security implications? https://docs.docker.com/engine/install/linux-postinstall https://docs.docker.com/engine/install/linux-postinstall If the official sudo project had a guide on how to disable passwords, that shouldn't be taken as endorsement of having that as a default config.
- lrvick 18d agoPer my other comments, it does not really matter if you disable the sudo password or not. If you have a sudo binary at all you effectively are giving every user process root since malware can mask the sudo command and intercept the password so trivially.
- dpkirchner 18d agoThe methods are described on the official docker website, not just random blogs or SO pages. There are caveats about security, of course, but it's not truly discouraged.
- skydhash 18d agoI think there are notes that warn you about the consequences. And they have been written with sys admin in mind which knows about user groups and security.
- ezst 18d agoYou mean, just how it is on Windows?
- deleted 18d ago[deleted]
- pibaker 18d agoIt is one thing to do things the risky way on your own system and another thing to ship an unsafe and unconventional default to your users.
- LinXitoW 18d agoFor a single user, opinionated, modern, developer focussed OS, this is completely and utterly on par. Using docker as a developer without this is just plain annoying.
- pixl97 18d agoThis also seems like one of the more common things LLMs use to priv escalate themselves when not given root access, seems like a rather common misconfiguration.
- steve1977 18d agoUsing Docker instead of podman is the first mistake and that is a distro decision (or a "chef" decision, in Omarchy parlance...)
- hemlock4593 18d ago*rootfull docker. Rootless docker is perfectly fine.
- lrvick 18d agoDocker can be run rootless. It is so easy. No excuse for desktop distros to not do this by default. And that is why all major Linux distros are just as bad as Omarchy (Not recommending MacOS or Windows either as those are wildly worse)
- Aurornis 18d ago> but I’m not sure this should be framed as Omarchy-specific, Adding the user to the docker group by default, out of the box, is Omarchy-specific. EDIT: More accurately, was Omarchy specific, until they realized that it's not a good idea and changed it.
- StrLght 18d agoExactly! I was also surprised by this — that's a sensible default for many people. However, I agree that it should be opt-in. Docs should be more explicit about that too, they should warn users about risks of going with that option. That excerpt mentioned in the article was rather misleading.
- bakugo 18d agoIt's absolutely not Omarchy-specific, Ubuntu has the exact same vulnerability out of the box, just with lxd instead.
- pritambaral 16d ago> Ubuntu has the exact same vulnerability out of the box, just with lxd instead. No, it does not[1]. LXD: - explicitly warns against this mode of vulnerability. Of course, there's no protection against people who blindly run commands copied from the internets, but the official documentation, at least, for as far back as I can recall, has had clear warning boxes against this, with explanations. - does not have the track record of bad design that docker has had (IMO). - supports fine-grained ACLs and user management. ---- [1]: https://ubuntu.com/blog/shared-development-environment-with-lxd https://ubuntu.com/blog/shared-development-environment-with-...
- bakugo 16d agoYes, it does. None of this information changes the fact that, on a fresh install of Ubuntu Server 24+, the default user can privilege escalate to root using a few LXD commands. https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-decade-old-lxd-group-root-re-armed/#the-full-chain https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-... And yes, I've tried it myself, it works as advertised.
- pritambaral 16d agoAh, Ubuntu _Server_. I'm tempted to dismiss this by simply saying "Server Linux != Desktop Linux", but yeah, I don't like that this is on by default either. I mean, this is a setup that ships with a default password that's the same as the username, and the first thing I do on all my server installs is disable all default user accounts and enable passwordless sudo. From reading other docs of Ubuntu Server, it appears they relax the root/non-root distinction in other ways too. But I'd probably never have suspected this particular vector of vulnerability.
- 15d ago
- dawnerd 18d agoDocker itself is such a massive security problem. Like it’ll punch through your firewall. Found out the hard way after a misconfigured redis was exposed to the web.