Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know, Omarchy's team really don't care if you're complaining.

Wouldn't the security team and the agents just go and fix the security holes?

They have a dedicated security team now that is being paid for this:

https://omarchy.org/security/

But having a dedicated security team is marketing?

I'm sure with the $10M cash chest the security will just improve over time and this blog post will be irrelevant.

I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?



There's a difference between a few small bugs because software is new and a half dozen eval(untrusted_input) in version 4.0.

Maybe this can get fixed, security teams won't make it worse. I worry they're mopping the floor and not fixing the leak: the development practices which lead to the quantity, seriousness and banality of their security issues is the part which needs fixing.


> Wouldn't the security team and the agents just go and fix the security holes?

Of course they’re going to react to what is reported and fix it. That’s a given.

The concern is the development process that is leading to these types of holes getting shipped. Mainstream Linux distributions have software practices and release cycles designed to be cautious. This project is taking more of a move fast and break things methodology where shipping the vibe coded feature as fast as possible is the priority.

Having a crack team of people responding to reports and fixing things (or prompting their agents to fix things) only solves the issues after they’ve been shipped, discovered, and kindly reported back upstream.

> I don't know, Omarchy's team really don't care if you're complaining.

Controversy is their primary marketing tactic. They prefer that people complain because being divisive and controversial is how DHH has always marketed his products.


Yea, I don’t get the shade. As many have said, it’s just Arch + a very polished UX preconfigured so you can jump right in without a lot of setup overhead.

Why it’s security would be on a different level than any other Linux distro isn’t clear.


It’s a bit more than Arch. There are a bunch of programs written in shell and QML/JavaScript. I guess at least they are using memory-safe languages, but shell scripts make it easier to write the type of shell-injection bug mentioned in the article. Personally if I started a new project in 2026, I would not choose bash and vanilla JavaScript as the languages to write it in.

The repo for reference:

https://github.com/basecamp/omarchy


Because the "polish" is done in an insecure way?


No, I don't like the style,but author is right here, you cannot secure insecure design. It needs to be reworked from scratch.


I'll take that.


If they are interested in complaints. Probably they do not, so people write blogs on their own. This kind of also happened in the rails world; some people got upset at DHH and then started writing complaints; and many of these complaints are by themselves also total garbage (some are more objective criticism, these tend to be better). It's kind of agenda-based everywhere.

> I don't expect the security to be perfect out of the gate at when Omarchy 4.0 just launched with real backing?

Well, we can note the time and look again in half a year or so. Personally I am in general happy with security in the linux ecosystem. I am more worried about e. g. systemd adding age sniffing as component. In another entry at hackernews, yesterday I think, we learned that Microsoft automatically tags all images with invisible watermarks. One just can not trust companies - they always feel a need to abuse data from the users and tags everyone. Next step will be mandatory chips into the brain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: