Omarchy 4.0 ships with a pile of security holes
Omarchy development practices lead to predictable security issues

A security researcher warns against using Omarchy, the Linux distribution promoted by DHH, citing a series of severe vulnerabilities in version 4.0, including bash injection via video titles and arbitrary code execution through notifications. The post argues that Omarchy's development practices prioritize speed over security, and criticizes DHH's marketing as disingenuous, suggesting that the project's security team announcements are little more than PR.
You can't get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited.
- Hugsbox
I'm somewhat out of the loop, and it's not really mentioned in the article, but what's with Omarchy getting this crazy amount of financial support from this list of fairly prominent individuals? Until a few weeks ago I'd never heard of it, then what I did hear is that it's being made by a very... uhh, eccentric(?) individual, and now it's suddenly got a crazy amount of funding. What am I missing?
- ricardobeat
The two linked issues are for the same bug report.
A friend has been urging me to install Omarchy for months. I’ve finally caved in after a horrible experience with highly-praised CachyOS.
All I can say is, I understand the hype. It works. The install is uncomplicated, no selecting from five legacy bootloaders, choosing versions or selecting a window manager. The tiled window manager works pretty much how I already use Mac. I like the terminal-focused system tools. Installing software is easy and lightning-fast.
- fidotron
This tumblr level of discourse is precisely what the Linux community needs to leave behind.
- dborovikov
“Full of security holes" - and two examples in the article have been swiftly addressed, ignoring that there is a whole dedicated security team https://omarchy.org/teams/
What kind of blogging is this?
- thehappyfellow
Yo, why is my blog post title editorialised? It should've said "Merchants of Insecurity". Rude!
- fnoef
There is this meme of a bell curve where the left side is some newbie trying to do something obvious, the right side is a "pro" trying to do the same obvious thing, and the middle is a someone trying to do cool/new/trendy stuff.
The left side us Ubuntu/Fedora. The right side is Arch. The middle is all these tech-fluencer-wanna-bes custom-made-ai-enhanced distros.
- okinternets
I have been seeing so many podcasts and YouTube videos about Omarchy in the past week or so. Must be a massive marketing push or just hype.
- markstos
Apparently the Omarchy plugin ecosystem is also a free for all like the Arch AUR, except the audience includes people who are new to Linux and less likely to understand the risks.
- vova_hn2
Okay, but how cool is that this feature (hotkey to pass a video, that is open in the browser, to yt-dlp) exists and works out of the box?
It's unfortunate, that it was developed in a weird, insecure way, but I think that the fact that it exists is very cool.
I've heard about Omarchy long time ago, but didn't switch, because at some point in my life I started to prefer something that is rock solid and well supported (currently on Fedora Atomic with KDE) to new/shiny/bleeding edge. But still. I think that an overall good UX out of the box is composed of little things like this.
- UK-Al05
Isn't most of the security holes still there if used arch and installed the packages yourself. A lot of people complained ssh had security issues in omarchy because it used the default settings. That would still be the same on arch?