Omarchy development practices lead to predictable security issues

arn3n 282 points 416 comments August 26, 2026
blog.happyfellow.dev · View on Hacker News

Discussion Highlights (20 comments)

colesantiago

I don't know, Omarchy's team really don't care if you're complaining. Wouldn't the security team and the agents just go and fix the security holes? They have a dedicated security team now that is being paid for this: https://omarchy.org/security/ But having a dedicated security team is marketing? I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant. I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?

fidotron

This tumblr level of discourse is precisely what the Linux community needs to leave behind.

jackb4040

What is the point of a new desktop Linux distro if you're gonna give it another dogsh* name no one can pronounce?

shevy-java

Just read DHH's blog and then you may quickly realise that other distributions may be a better choice. There is a difference between "opinionated" and ... whatever the content criteria is for DHH nowadays to write stuff on his blog. Younger DHH was more impressive than the TechBro aged later variant, in my personal opinion. Arch is in general a good base though - I mostly use Manjaro as base, then customize it via a ton of scripts and compile about 99% from source anyway, using an extended set of ruby scripts (a bit similar to homebrew, but one big difference is that I wanted versioned AppDirs like in GoboLinux; my scripts originated from GoboLinux's philosophy since I did not want to use shell scripts but retain versioned AppDirs. Manjaro is in some ways a bit similar to oldschool slackware, which unfortunately kind of died - it is not really fully dead, but look at the homepage and then tell me how many years past the last .iso release still counts as alive. So to me it is dead, despite the changelogs still being updated or others, such as alienbob, pushing out new releases.)

lab14

Surely those won't ever get fixed...

Hugsbox

I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?

raverbashing

Ok I think I see the issue It's lines, lines and more lines of bash script sigh big sigh Using bash for all this stuff is like trying to wash your car with sandpaper instead of soap and water. Yes it can work if you're really careful with it, but in practice no

Qbtaumai

heh... i still remember the very first time when it came out with it's opinionated branding and all that, looked good and went ahead to try it out but was so annoyed with all the bloats and promoting their software's in it which made me their intentions already clear. I got to know that recently they've added option to remove all the bloats but IDC anymore. not gonna try that ever. Not to mention it was just dotfiles painted on top of arch iso and documentation itself included archinstall guides - if that's a distro then my system with dotfiles are a distro in itself lol... though it looks like they've changed things up now, it looks like it has a iso's and all the stuffs to be called a distro now.

okinternets

I have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.

1970-01-01

>DHH loves to say he's making the year of Linux on desktop happen. I'd stay away just for this reason alone. Anybody that says this is either joking or has no clue how the real world works.

1GZ0

Pretty embarrassing, but its nice to see them actually putting effort into security. https://omarchy.org/security/ Too few upstarts realize that proper security is core to a good experience.

0xb0565e486

When I was a kid my mom had a daycare and had access to a program where she could buy older and used desktops at a discount. I loved installing different operating systems on them and try to customize it. Better window management, better animations, nicer colours etc. Of course, the results were always marginally better or worse than the stock version of that distribution. Seems as this is the case for Omarchy here as well.

jstimpfle

Not following Omarchy, not even sure what it is trying to be compared to existing distros (other than an incredibly hyped up product). Not hating on DHH. But hasn't he become famous for developing a web framework (20 years ago), rather than for his technical prowess as a systems-level engineer? Seeing these kinds of bugs is not exactly unexpected.

Cakez0r

"full of security holes" but the author could only name one (the two links in the opening paragraph are the same issue). Some people just hate DHH and can't separate the art from the artist

dzonga

effects of vibe coding + the zealotry like passion of DHH & this is the result.

thehappyfellow

Yo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!

rvz

At this point, it looks like some here in the Linux community have a new found hobby of actually liking to get angry at things instead of building, now that AI took away their identity. This is just a person having fun building their own distro. If you don't like it why are you giving them so much attention even though you will never use it?

sbinnee

It is probably true that it has a big attack surface. But omarchy is no doubt a huge driving force. A few days ago I listened to a podcast dhh talking about the latest major release and its huge donation. I believe it’s now 10m usd or something. I am hopeful that dhh is serious enough to address the security issues plus a lot of ux improvement on linux. In the episode he emphasized 17 layers of security layers where I remember the number solely because I found hard to believe to be honest. You can find the podcast episode in this one https://thestanduppod.com/

fnoef

There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff. The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.

UK-Al05

Isn't most of the security holes still there if used arch and installed the packages yourself. A lot of people complained ssh had security issues in omarchy because it used the default settings. That would still be the same on arch?

Semantic search powered by Rivestack pgvector
4,560 stories · 41,176 chunks indexed