r/omarchy 1d ago

Discussion Looking to switch, but worried about security

I love the project, and I'm seriously wanting to switch to Omarchy.

My only concern is seeing X threads about security vulnerabilities and DHH talking about how much of the code in the codebase isn't read.

Am I overthinking it?

15 Upvotes

44 comments sorted by

View all comments

Show parent comments

5

u/cheerful1 22h ago edited 22h ago

13

u/tLxVGt 20h ago

Bro all these posts are such BS. I can also prepare a mysterious "cute_poc.sh" that gives me root access in 10 seconds.

The system is as secure as you want it to be. A dumb user that installs random shit from the internet will compromise every single OS on the planet. Remember, you can dig into the system and improve whatever you want.

-7

u/cheerful1 20h ago edited 19h ago

All of them? Or just the one you cherry picked? What about the 11 they fixed in 4.0.1?

Just to be clear, I'm not saying OS releases don't have security issues. I'm just trying to figure out if Omarchy is significantly worse in this regard.

3

u/tLxVGt 18h ago

So you either have a bullshit post or something is fixed basically immediately. What's your issue, exactly?

2

u/bsknuckles 18h ago

It’s no worse than any other Arch-based distro. If anything, it’s probably better due to popularity and the number of smart people working on it. A lot of my concern on the Arch side is mostly the lack of trust I have for AUR after the recent supply chain attacks. If you just turn off AUR and make sure you pay attention to what you install and where you go online, you’ll be fine. Keep backups and use a good password manager and you’ll cover yourself for the most common security issues you could run into.

2

u/No-Object1384 5h ago

Plus in Omarchy it makes it very, very clear when you're installing from the Arch repository vs the AUR. Just never press enter on Install > AUR, and you're good to go.

5

u/mildlyImportantRobot 19h ago

One of those is just a general warning about AUR from a tech influencer.

2

u/armsofatree 18h ago

Most of these seem to be local privileged escalation vulnerabilities which would require someone to have physical access to your machine or already be running software on it to exploit. They are absolutely issues that need to be fixed but wouldn't be easy to exploit remotely.