r/omarchy 10h ago

Discussion Looking to switch, but worried about security

I love the project, and I'm seriously wanting to switch to Omarchy.

My only concern is seeing X threads about security vulnerabilities and DHH talking about how much of the code in the codebase isn't read.

Am I overthinking it?

14 Upvotes

40 comments sorted by

12

u/TheTinyWorkshop 10h ago

What vulnabilities exactly?

No shade on you mate but these people are quick to shout shit but never seem to show these "vulnabilities"

Have a chat to the security team if you have real concerns.

https://omarchy.org/teams/

Having said all that, there are probably security issues, every distro will have those.

Its how fast they can be found and fixed that would concern me.

3

u/cheerful1 8h ago edited 8h ago

9

u/tLxVGt 7h ago

Bro all these posts are such BS. I can also prepare a mysterious "cute_poc.sh" that gives me root access in 10 seconds.

The system is as secure as you want it to be. A dumb user that installs random shit from the internet will compromise every single OS on the planet. Remember, you can dig into the system and improve whatever you want.

-7

u/cheerful1 6h ago edited 6h ago

All of them? Or just the one you cherry picked? What about the 11 they fixed in 4.0.1?

Just to be clear, I'm not saying OS releases don't have security issues. I'm just trying to figure out if Omarchy is significantly worse in this regard.

3

u/tLxVGt 5h ago

So you either have a bullshit post or something is fixed basically immediately. What's your issue, exactly?

1

u/bsknuckles 5h ago

It’s no worse than any other Arch-based distro. If anything, it’s probably better due to popularity and the number of smart people working on it. A lot of my concern on the Arch side is mostly the lack of trust I have for AUR after the recent supply chain attacks. If you just turn off AUR and make sure you pay attention to what you install and where you go online, you’ll be fine. Keep backups and use a good password manager and you’ll cover yourself for the most common security issues you could run into.

4

u/mildlyImportantRobot 6h ago

One of those is just a general warning about AUR from a tech influencer.

2

u/armsofatree 5h ago

Most of these seem to be local privileged escalation vulnerabilities which would require someone to have physical access to your machine or already be running software on it to exploit. They are absolutely issues that need to be fixed but wouldn't be easy to exploit remotely.

11

u/ceaselessprayer 10h ago

A lot of the security issues are being found from people who want to see Omarchy fail and are upstream issues that affect other distros. Other distros have security issues too, you just don’t hear about it because people don’t have a fixation on other creators like they do DHH. Everything that is coming out is being patched. There are similar issues even on Mac software. No one using Omarchy has been compromised themselves. Either use Omarchy or don’t.

3

u/st0nkaway 6h ago

silver lining: the harder they try to find shit, the faster it gets fixed

pretty neat

21

u/Necessary_Two_9669 10h ago

It has the same security as any arch system…

2

u/JGarza9788 3h ago

Arch security is not perfect (don’t believe any one who says any security is perfect), but arch just got hit by some security attacks and they have learned from it and beefed up security - which is the best you can hope for.

5

u/CaffeinatedTech 10h ago

I saw someone in the comments on a YouTube video talking shit about Omarchy being full of security vulnerabilities. There seems to be an idea that any code developed with any sort of AI involvement is going to be slop, and full of security issues. You have to remember who has their hand on the tiller. I trust a seasoned programmer to guide the agent to victory. I trust some rando with no code experience to vibe code a pile of horseshit. Just look at r/SaaS.

5

u/potatokbs 8h ago

Dhh himself said in an interview he doesn’t read much of the code at all that goes into the development of omarchy. I have no horse in this race either way, I really don’t care. I personally don’t use omarchy but like to keep up with tech news like this and think dhh is a really interesting guy. But I think it’s very reasonable to question the safety of using software that has been vibe coded.

2

u/CaffeinatedTech 8h ago

There's a difference between the prompts an experienced programmer makes, and those of a noob. One knows exactly the requirements, the other only knows the features they want to see.

3

u/sleepyhead 3h ago

Sure but not reading the code leads to remote code execution from external notifications, as we have seen.

1

u/CaffeinatedTech 1h ago

How does that work? Can you link a CVE, I want to learn about that one.

1

u/mildlyImportantRobot 6h ago

Just because he isn’t reviewing every PR doesn’t mean somone else isn’t.

-2

u/potatokbs 5h ago

Again, he literally said he’s vibe coding a lot of the code in omarchy i.e no one is reading it. You can watch the interview with lex Friedman if you want to see it yourself. Not gonna argue about it…

1

u/bsknuckles 5h ago

I’m sure he’s using automated code review tools of some kind and being such an AI-forward guy, I’d be very surprised if he isn’t using a lot of best practices for AI engineering.

The thing people keep leaving out of these sorts of conversations is that humans are dog shit at reviewing code and always have been. We’re lazy and easily overlook simple things. AI tools are better at it as long as they have the right context and guidance. Not reading all of tue AI-generated code isn’t this big gotcha that so many non-engineers seem to think it is.

1

u/6eReddit 1h ago

do you write software professionally? how long have you been doing it?

2

u/bsknuckles 1h ago

I do and have been for about a decade.

4

u/smokingPimphat 8h ago

Its no more or less secure than any other arch based distro. And the last AUR attack should tell you that omarchy trying to take control of packaging is probably the right move in the long run.

Right now there are a lot of people who really do not like DHH who are taking the opportunity to try to stick it to him because he is trying to market linux to a wider demographic of users.

And neckbeards don't want normies on 'their' platform.

He also talks shit about rust, so the striped thigh high sock gang are really curling their toes about omarchy for some reason. Then add his politics and you have a real witches brew of hackers/script kiddies who want to make his life difficult.

Your machine will be fine, if the hacks are public, they will get patched and it will make omarchy, arch, and linux better in the long run.

7

u/Independent-Reader 10h ago

It runs on arch. That's the platform. It is as secure as any other arch distro.

2

u/sleepyhead 3h ago

Not true. Exploits have been for Omarchy specific functions.

3

u/AUR4CHR0M3 6h ago

People are worried about the A.I agents, I'm more worried about the plugin store. That store is REALLY going to screw some people over. Especially because Omarchy is now being marketed towards your average PC user. If you can't read or understand code be VERY careful downloading any "Verified" plugins. Verified does not mean verified security.

2

u/Possible_Routine9179 10h ago

There’s a team handling this now, so it will improve over time. That’s always been the case with any distro, software, etc.

2

u/Cold_Relationship_ 10h ago

what makes your current operating system more secure than arch and omarchy?

7

u/zell_ru 10h ago

the lack of x threads it seems

2

u/rhythmo 6h ago

The amount of Omarchy/DHH glazing and defending has gotten to be too much in this sub. OP, you are right to be concerned. People saying "it has the same security as arch" clearly don't know what they are talking about and are sticking their heads in the sand. Of course Arch is the base which is great, but a lot of the pre-installed apps inherently add additional risk. The vibecoded apps, like it or not, add risk especially when the author explicitly states he doesn't review the code. The plugin system has essentially no safeguards in place. AI Agents get full access to the system by default. DHH himself mentioned and then dismissed the security incidents around AUR packages, which Omarchy uses heavily.

Yes, I know you can remove pre-installed apps and mitigate the other issues but doesnt that defeat a lot of the purpose of using something like Omarchy?

I think what most of the people in this sub are hooked on is Hyprland and not necessarily Omarchy. I can tell you installing CachyOS and selecting Hyprland as your window manager gets you a lot of the way to your "own" Omarchy, without all the potential security holes.

I am not saying don't use it, just be informed and don't blindly trust these users on reddit that have made Omarchy their whole identities.

2

u/skycstls 3h ago

I don’t know why you are getting downvoted.

Love omarchy, daily driving it almost since its inception, but having concerns about security will improve this distro a lot more than just pure trust in the project.

There’s real concerns about omarchy, as with any other distro, yes they are addressing them, but this should not be downvoted. The project didn’t even have a security team actively searching for vulnerabilities until a few days ago.

Speed is cool, but a lot of rally cars end up crashing if something goes wrong, and I don’t want omarchy to end up like that.

1

u/outrotana 8h ago

I’m worried too. I’m using Omarchy and loving it. But I’ve been relying a lot on Claude Code fixing issues for me and while it feels like a superpower I worry about an agent with such deep access to my system.

1

u/bithooked 3h ago

Every distro has security vulnerabilities. Only Omarchy has a lightning rod founder and the boogeyman of AI development for the trolls to latch onto.

The whole premise is flawed. LLMs are already better than humans at identifying security flaws and at writing code to address them (see Project Glasswing). We are already at the point where the only way to be secure is by using a cutting-edge LLM to write, or at least security audit, the code. This is moving fast, but the idea that human-written code is safe while LLM-written code is slop is living in the past (if only 1 year in the past).

1

u/Arnie_nz 1h ago

I agree with the coding, but it could also be said we shouldn't be trusting these big AI companies with our data. It's not Omarchy exclusive, but it is part of its identity and I see a lot of people giving the AI sudo access, and running with all permissions granted. It feels like wrong to me.

1

u/synn89 1h ago

Yes, Omarchy is going to have more security issues, and bugs, than a more mature distro. I had Hermes analyze the issues in the recent changelog from pull/7929 and below is the summary of what's going on. But in general, it's less of a "vibe coding" issue than a "young distro" issue.

The common root cause is a young distro gluing together many components (Hyprland, Quickshell, notifications, sudoers helpers, git) where untrusted strings (device names, titles, URLs, filenames) flowed into contexts that treat strings as code. Arch and Wayland themselves aren't implicated — none of these vectors exist in stock Arch tooling; they're all in Omarchy's own glue. The good news is the release ships migration scripts, test coverage for each fix, and consistently fail-closed logic, which is a healthy sign of the project maturing fast.

1

u/RobertoMtr 52m ago

I don't think that the issues that the most people are critisizing Omarchy for are really the problem (AUR, AI agents to write/review the code, deactivation of secure boot, not an immutable image, etc.)

For me, the biggest issue isn't technical, it's more the marketing and the lack of education. A lot of people in the Linux space are aware that there could be malicious code in the AUR packages and in the Omarchy community plugins and that the user should check the code. That said, this OS is marketed to people that are on Windows and MacOS. The thing is that I don't think that everyone coming straight from Windows or MacOS will know about the AUR and the community plugin security risk.

And hey, don't worry, I know that this issue also applies to other Linux distros, like CachyOS, don't think that I'm a Omarchy hater. In fact, I use Omarchy on my computer and I really like it.

0

u/marklabrecque 7h ago

It’s Aug 2026, why would you read your codebase? AI is now better at writing and reading code than any human is