Omarchy 充满了安全漏洞。
Omarchy development practices lead to predictable security issues

原始链接: https://blog.happyfellow.dev/merchants-of-insecurity/

博文《不安全感的贩卖者》(Merchants of Insecurity)对使用“Omarchy”操作系统发出了严厉警告,指出其存在严重且可避免的安全漏洞。作者强调了诸如通过通知执行任意 Bash 代码等致命缺陷,并认为这些问题源于疏忽的开发实践——即使用了未经审查、由人工智能生成的脚本。 作者批评该项目的领导层(特别是 DHH)将华丽的营销置于真正的安全之上。尽管领导层将该操作系统宣传为一种精致的、“Linux 桌面之年”的体验,并大肆吹嘘其修复 Bug 的能力,但作者认为这种说法虚伪透顶。他们指出,大量的安全补丁恰恰是基础架构根本不安全的症状,而非某种成就。 归根结底,这篇文章旨在纠正公众对 Omarchy 的看法,认为该项目并未认真对待安全性。作者主张用户在风险方面受到了误导,并警告称,由于缺乏基本的安全保障,该操作系统可能很快会在企业环境中被禁用。

近期,基于 Arch Linux 的发行版“Omarchy”因得到 DHH 等知名人物的支持而兴起,并在 Hacker News 上引发了激烈的讨论。 批评者认为,Omarchy 与其说是一个成熟的操作系统,不如说是一堆“氛围感”导向的脚本和配置文件合集。人们最主要的担忧在于其开发方法:怀疑者指出,该项目存在明显的安全漏洞(例如通知处理中的命令注入缺陷),这证明了该项目优先考虑的是快速部署和营销,而非安全的工程实践。 除了技术层面的批评,围绕该项目创始人 DHH 的政治立场,讨论也呈现出极度两极分化的态势。许多用户认为,该项目是他推行其争议性政治理念(特别是关于移民问题)的载体。虽然支持者将其视为传统 Linux 发行版的一种“开箱即用”、用户友好的替代方案,并称赞其集成了人工智能的工作流和精致的用户体验,但反对者则认为,这些热度是由“科技兄弟”(tech-bro)圈子人为制造出来的。 归根结底,这场争论反映了 Linux 社区内部更深层次的冲突:一方是优先考虑技术稳定性和意识形态中立的人群,另一方则是倾向于支持那些由个人主导、以创新为核心,且不惧争议与风险、挑战现状的项目的人群。
相关文章

原文
Merchants of Insecurity – One Happy Fellow - blog

First, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit.

You can't polish a turd

Omarchy 4.0 shipped with a collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine.

All projects have security issues but not all projects have such predictable security issues. We know how to deal with untrusted inputs. We know we should not use AI-generated bash scripts for processing untrusted input, particularly with seemingly no review.

And you can't get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited.

Simply put, Omarchy doesn't treat security as important. They do role-play taking security seriously but their development practices and the ease with which they speedrun decades of security issues and invent new ones tell us much more about the security of Omarchy than Security Team announcements.

Lies or marketing?

DHH loves to say he's making the year of Linux on desktop happen. How Omarchy is the distro people should use. Showing how polished the experience is. Essentially, he's good at marketing Omarchy.

On the security front, he highlights the security team's efforts in the recent point release. A long list of resolved security issues sure looks impressive if you start with Swiss cheese of an operating system.

I think the marketing has turned into lying, being disingenuous. An honest attitude would be to say that they care about iterating on their dotfiles much more than about basic security of the system.

DHH silences his critics with fake positivity, with a "let's fucking do it" attitude. But the reality is that Omarchy is a project which doesn't treat security seriously and I wouldn't be surprised if many companies ban its use.

Just let people enjoy things, jeez

I'm not stopping anyone. I don't like when the public perception of how much risk someone is taking is disconnected from the actual risk of using a project like Omarchy.

The team doesn't look interested in accurately explaining it to their users. I don't like people being deceived into hurting themselves, hence this post.

Peace ✌️

联系我们 contact @ memedata.com