Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?
But, this “vulnerability” is the thing everybody knows about docker since forever. I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year. What is different here?
Start a docker container with the docker socket mounted in the container and now you can have yourself mount / as rw. Everybody knows this. How is everybody so shocked here. Many instructions online tell you to make yourself part of the docker group for convenience (like the digital ocean one).
What’s different is that it comes configured this way out of the box, silently, without warning. It’s functionally equivalent to opting in to giving all user accounts root privileges, which is not what anyone expects the default configuration to be.
You can choose to configure your installs this way if you choose to do so. It should not come this way quietly by default.
First they should try making a solution that works as well as Docker. Every time I use Podman or Podman Desktop I run into the most basic problems. Docker works out of the box everywhere.
I don't use Podman desktop but I haven't had any issues at all with basic Podman. It just seems like a better overall design. It would be great if Docker copied the rootless / daemonless approach if possible.
For me the problems are always when I pull some image (like GitLab) and try to get it to work with podman. Or the hoops you have to jump through with podman-compose (user lingering, systemd services, privileged ports (80,443) [yeah I know it's a feature]). Docker just works, Podman (I feel) still requires stuff that makes it less declarative (to get to a running infra).
Still, having a gitlab runner with a docker in docker setup that can access the host docker socket is not something you do lighty, so I am eyeballing buildah etc.
I guess what really grinds my gears is that I'd use podman a looooot more if it could nicely coexist with Docker. I'd use Docker for the big services and podman for all my own stuff. But that is just not possible (at least not afaik), so it is also difficult to switch step by step (yes VMs, bla bla, but it's all complicating).
It might be a mistake but not a serious one, like it's a common setting they had on for convenience of development without being too insecure, but forgot to leave it out of public release.
So there's nothing weird. It being on originally was intentional and not crazy. Only it going all they way wasn't.
Overly active analytics / tracing stuff is not uncommon during dev. Likely they just did it to be able to debug things better in the weirdest cases; doing a full session replay basically when you have the whole original state of the repo
> people who want to use Arch Linux but have it configured the way DHH does
Then they don't actually want to use Arch Linux.
The Arch Linux way is to read the excellent wiki documentation, learn about all the choices available, and then make all of those choices so the system is configured the user's way instead of some celebrity's way.
> It is targeted at the proficient GNU/Linux user, or anyone with a do-it-yourself attitude who is willing to read the documentation, and solve their own problems.
Assuming you mean "they don't actually want to use Arch" as a criticism (rather than a truism), I think that's fair for a distro described as "Arch linux but configured X way". I don't think it's a good criticism for something like SteamOS which is configurable but is aiming hard for "it just works".
Actually we do. I like pacman for example. And don't mind going thru archinstall for a test install once to learn. But my workstation, I'd not like to have to develop, even if I do like configuring minimal installs for other uses like kiosks.
I didn't realise there was a correct way to use Arch, or that there were people authorised to explain what it is. Is that an Arch-exclusive service, or is it available for other distros as well?
You say the whole point is ending up with a system configured the user's way instead of some celebrity's way, and then you go on to tell us what we are actually allowed to want. That's a bit rich.
Starting from someone else's config and then changing whatever annoys you is making the choice, it just skips the part where you spend a weekend reading about display managers to arrive at the same place. That is what dotfiles have been for since roughly forever.
By your standard, anyone who used archinstall from the official ISO isn't really using Arch either, and I suppose the truly enlightened path is Linux From Scratch, compiled this morning, on hardware you soldered yourself.
I like and use Arch daily. My "way" was just to get past the fdisk squirrel catcher. After that it was as easy as Ubuntu. I'm not bragging, I wish I'd read the manual but was too impatient for that. I suspect I'm not the only arch user that arrived at it using similar approaches. I might even be a target user for DHH's distro but the bloat (and to some extent the vibe coding) holds me back.
What exactly is special about rolling a custom arch in this instance? Like, why does this get so much attention? Do web developers really care about what DHH does that much?
Like, I get it if thats the case. Say, if Chris Lattner or Andrej Karpathy rolled some ML GPU programming distro I'd probably care about it and try and see if it made me more productive.
I thought that’s pretty much the way all technology goes. Just seems silly to take promotion an operating system that’s essentially a lot of config files atop existing work seriously from someone that made a popular web development framework 20 years ago. That’d be like me caring about a distro Gavin king made because he made hibernate in the 2000s at jboss.
He leveraged his past success as a web developer to get into online culture war punditry. Now he's a prominent race-baiting reactionary.
There's a sort of cult of personality around him at this point. His acolytes follow him for his nativist views, and then adopt his technology unthinkingly.
I don't know why my comment was downvoted above. This isn't a serious distribution and you shouldn't expect it to be. It's a vanity project of a niche alt right tech bro, and this is the level of rigor you should expect.
Yeah that’s exactly it. Seems he’s manufacturing a lot of culture war bullshit just to bring attention to a less than interesting distro. If it wanted to be the “hyperland“ distro as so many distros are (built to bring one de/wm to users prepackaged) that’d be one thing. If he wanted to show people how to roll their own opinionated distro the way gentoo or lfs kinda did that’d be another too! But seems it’s neither of these, and purely vanity to me.
DHH was on the Lex Fridman podcast talking about this recent release of Omarchy in that most of it
is "vibe coded". It is mostly just a bash script to configure Linux, but his approach is interesting.
AI as a core part of the OS that can just change or add anything you want. Linux is great for this because it has access to the source code for everything.
He said he didnt review the code line by line, just looked at the shape of it. Whatever that means.
I recently used Arch Linux because I have a 4 GiB Mac Air that I want to use for something but it has too little RAM for UI.
The installer was user friendly and fast. I got exactly what I wanted.
I don't, and I migrated to Podman because Docker is poorly designed and full of footguns. For example, it it will silently overwrite iptables rules and punch holes in your firewall.
Indeed. Podman works great. And kube play unifies container orchestration by using k8s manifests for local orchestration instead of a separate DSL like docker compose.
A distro should be secure-by-default. Omarchy’s design here was insecure by default while the docs have the impression that Docker might be running rootless. Pairing insecure defaults with docs that claim better security is bad.
> I always make my user part of the docker group, so my NixOS also has this, and any Ubuntu I’ve used over the past year.
You may do that, but I don't. I always use sudo to manage the few docker containers I need, and I prefer podman where possible specifically because I can run it rootless.
If you want to give your user passwordless root for convenience, go ahead, but that should never be the default.
> I always use sudo to manage the few docker containers I need
I'm afraid that isn't really any better. If the attacker is in position to exploit membership in the docker group, he already has access to the user's .bashrc. He can simply write a function called sudo that wraps the real command and records your password[1]. Unless the user always invokes sudo with /usr/bin/sudo, docker group membership doesn't really make a difference.
Once malware runs as an administrator, getting access to root isn't really that complicated. The boundary between wheel and root is more or less security theater.
Edit: Oh well, I see now that others have made the same point (https://news.ycombinator.com/item?id=49500588). With the same wording even. I'm half-way tempted to delete my comment so as not to look like a plagiarist, but it seems many posters are unaware of the vulnerability, so I'd leave it here.
Does 'chattr +i .bashrc' reliably prevent this? Always seemed sensible to me. Then again, there are a few files getting sourced by the shell and I am not sure I could spontaneously name them all.
The attacker could use `chattr -i .bashrc` with the same privileges before editing your bashrc. A better way would probably be to use `sudo chown 0:0 .bashrc`.
Also you will want to do the same to .profile (because of LD_PRELOAD etc).
And also do the same to any directories in your $PATH (~/.local/bin etc)
> The attacker could use `chattr -i .bashrc` with the same privileges before editing your bashrc.
No. Setting flags requires root privileges, sudo was implied. At least on my system.
> Also you will want to do the same to .profile (because of LD_PRELOAD etc).
Yeah, that's what I meant with additional files sourced by the shell. I knew about .profile, but I am not sure that's all of it. I think different distros may be set up differently in this regard. Also I am pretty sure, you can define function overwrites/aliases and execute code in any file getting sourced, it's not just LD_PRELOAD attacks.
I don't think this is as widely known as you believe: I use dockerd via colima so it's not a limitation I've encountered - if I had, I likely would've switched to podman wholesale instead of compromising my system.
Either way though, I would hope it's self-evident to most that taking glaring security holes in a single app (docker) & transforming them into glaring security holes in an entire OS is generally not desirable.
Exposing the docker socket seems like such a rookie mistake to. There's a good reason we've known about docker socket proxies for a very long time.
Also beside that they use ancient package alongside Archlinux. One of those being Chromium. It also used to use Chaotic AUR but now they just automate packages (every 6 hours) in their own repository without any maintainer intervention so it's still open for supply chain issues.
Unfortunately, it's hard to classify something as a "rookie mistake" when the developers behind the most revolutionary enterprise tech in the world have accepted it as "by design" & just put a hard-to-find disclaimer about it on one single page of their dense docs.
It certainly does help quell imposters syndrome whenever it creeps up on my though.
Absolutely. Docker is a boiling mess of baked-in convenience workarounds (ie vulns). It's an orchestration layer (like k8s with containers), not a real security boundary like VMs. OTOH, single-purpose VMs are basically just as easy these days and those can still pull in containers as needed.
If you are asking concerning security, the answer is that it’s an insecure default that should have protected an unwitting user.
If you are asking concerning consistency with real world situations, then there is no difference and it feels like the fit is over a somewhat controversial figure (DHH) and how he created the distro’s recent release without reading any of the code himself. The counter is that no one installing a distro actually understands how their distro is configured, and trusts someone else’s judgement. Here that judgment was farmed out to AI, and while that is controversial, the uncomfortable truth is that this is how an awful lot of real people are told to configure their Docker installations.
IMO Docker running as a root daemon is a bad idea in the first place and I’d much rather use Podman’s rootless containers.
> But, this “vulnerability” is the thing everybody knows about docker since forever
OP’s point exactly - it seemed somehow in their vibecoding workflow, they forgot to even do a human architectural sniff test for the stuff everyone knows. It reflects very negatively on them.
This. Was also super confused when I saw the post. Like every docker guide literally screams at you when you use rootfull docker. Either add yourself to the docker group with `newgrp` for a termimal session or use rootless docker.
You add yourself to the docker group to be able to use the socket. By default, a uid 0 on a docker container is run as root, regardless of the uid of the owner of the container. That is precisely the issue being discussed.
You specifically called out security vulnerabilities, but the point missed by the commenter you are replying to is that people who ridicule something originating from DHH or AI are generally not based on nothing. "People just hate X no matter what" is almost always a low-quality complaint, for most values of X.
That remains to be seen. The whole concept is still in its infancy. An AI reviewer should have caught these issues when they were PRs.
But you see, it wasn't even a PR. It was just DHH making a straight up commit on the main branch (as far as I can see). With a message "Do all the additional Docker configuration needed". Was it even AI-assisted? At least the commit message wasn't, AIs write smarter commit messages than that.
I said on my earlier comment that DHH and AI get ridiculed automatically because people hate both. That doesn't mean that the ridicule isn't always justified.
Which tells me that they don't really take security seriously because everyone knows exposing the docker socket is dangerous. I would almost bet that AI would warn about that.
I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.
I just switched over to it from Ubuntu. So far the nice thing is that it gives you a fully decked out hyprland setup without any of the hassle and pretty good UX.
The problem I've always had with trying out a tiling window manager like hyprland is you're going to spend a very long time trying to get everything just right. With Omarchy I get a really nice hyprland setup right out of the box.
Github is awash with people's dotfiles including fully featured DEs built on top of things like Hyprland and Noctalia, and they don't require you to use a mess of a distro to use them.
> No need to use a whole distribution with 1000 other poor decisions made for you.
I used Vim for a decade (and Linux for much of that time) and the constant tweaking and changing things drives you mad after a while. The more you invent it yourself the more it changes. This is why I prefer MacOS+VSCode these days, which comes with good defaults and simpler VIM-style bindings.
Omarchy sounds like those popular vim configs such as https://astronvim.com/, which I also tried using and also ended up heavily customizing myself. It provided some nice defaults as a baseline but was ultimately comes with too much hyper-customization (which has a lot to do with vim/neovim trying to act like other more modern editors).
Yeah, I mean when I set up my last distro I just installed claude and told it what I wanted and in about 30 minutes it was up and running. No need to install random distros!
The nice thing about wayland is you can easily combine a compositor/window manager with a wayland desktop shell and get a lot of the stuff you used to have to fiddle with when using like i3 for free. For example, I use niri with the “dank material shell” desktop shell and get status bar, notifications, clock, suspend/resume, etc. all “out of the box.”
Well the whole point is to have a good foundation and then make it actually yours, and the only necessary key binds are probably SUPER+K for the key bind cheatsheet and SUPER+SPACE for the menu.
Also the community is large so there's usually someone that has already had your issue and resolved it. The amount of themes and plugins are growing everyday.
A bare arch+hyprland install really feels terrible to use and has a much larger barrier to entry than Omarchy.
Hey, do you have any concerns about malware, in case of using the plugins or themes from these websites ?
I was a bit skeptical, considering all the malwares that are being found in the package managers and plugins are pretty much the same thing but as extensions.
There's definitely appeal in key-driven window managers in general. Projects like i3 and Niri are popular. But you can get that with any Linux distro (albeit not many have it set up that way by default). You don't generally choose a distro just for whatever DE/WM it happens to start with.
What I don't get is that VS Code has solved this perfectly via the command palette - you just bring up the prompt and start typing and it will find you the command you actually need without having to memorize anything.
It is kind of nuts how little attention this more-than-controversial-enough aspect of it gets compared to anything else, to the point people don’t even know this about it.
I happen to hate Omarchy for the precise reason I don’t want that sort of interface, but apparently everyone else does, and if they do that’s up to them.
Can you say what you prefer? I'm always down for alternative UX flows and with hyprland being so user specific it's hard to see how people leverage it across the spectrum.
I got here because it was the first time I saw a tiling window manager on an Omarchy video. I was on windows my entire life, so when i saw it and how bad windows got, I decided to give it a try. A few months since I de-omarchyfied the system and went straight back to arch. And now still on it.
I should have gone with something like cachyos as games are important to me, but I think at the time hyperland wasn't an option (i don't remember). I know it is now.
There's a segment of people who are into customizing their desktop environment as a hobby and end in itself.
Personally I've never really been into it, and these days I have a broad and revolving set of machines I have to use, so this sort of thing is absolutely not worth the bother. I just install KDE Plasma and use the computer.
Then it's not for you, or you can't vision how 5 minutes of learning can save you hours of future time.
Having to know like 5 keybinds and no taskbar is absolutely the point and it's a beautiful concept of how to use your computer. And it works, if you are open to relearning just a bit.
Being hyprland keybinding skilled removes a lot of the desktop interaction surface, it's a worthwhile investment. People who've used tiling window managers for a while will tell you that it gets natural at a point, then a whole class of friction that normal WMs cause just goes away.
I for one hold out for them releasing an optimized XFCE variant - don't by any means dislike keyboard driven software but I like it as an extension of a regular functional UI experience not as a "argh the windows are stuck in xyz pattern until I re-remember xyz combo"-experience: the UI surface is not the speed limit in my optics, rather it is the apps I use or (increasingly due to local AI) the computational hardware limits of my machine.
I recently customized my own Bazzite install to use hyprland plus other customizations, there's really not much different than what omarchy did. It's pretty much that with some pre installed apps. Anyone that gave them funding is an idiot IMO.
On the flipside, once you use an OS that is totally open to agentic stuff, there's no going back really.
I can open Pi and ask it to fix some window tiling issue, help me install shortcuts, help me figure out how to install flatpak vs appimage, etc. the list is endless. I cannot see myself going back to a legacy OS unless I'm forced to by my job for compliance reasons.
Why is the list endless? I don’t even remember the last time I check or change any on my mac settings. And my unix things haven’t been touched in months. My debian server is basically frozen at this point.
That’s like one of two lines of i3status. Awesome if you need something like this one and built it. But don’t pretend that there aren‘t myriad solutions out there that have solved a lot of possible use cases.
You didn't switch away from windows to get superior software?
Also, the statement was valid because it will be true for most. It doesn't matter that you read it and it wasn't true for you, as long as it's true by the numbers, it's true, because it's one-to-many communication not one to one.
My reasons to switch to Linux from Windows were very little about "security" and plenty more about freedom. Sure, it was very nice avoiding running an antivirus, but that was just the cherry on top.
I wanted the freedom to change and "rice" my desktop however I wanted, and the Compiz cube looked awesome. I found Windows condescending and restricting in that regard. Yes, my first reason was the aesthetics, kick me out of the nerds club. (That was also the reason I switched to Mac for 10 years).
My second reason was that I suspected I could learn so much more about computers using Linux full time. And I did.
I was also younger and used to associate Windows with soul-sucking corporate jobs and Linux with new ideas and experimentation. It was us-vs-them. Open Source vs Micro$oft and all that vibe.
While I don't want to discuss the quality of any distro vs Windows, there is a big reason most of us use free software: because it is free.
Whether for you it is because of free as in freedom or free as in beer specifically, quality may not have much to do with it.
In EU at least you can almost get free as in beer Windows, you can buy a fully legal 2nd hand (resold) Windows license for about $10, the price of a fancy beer.
I'm sure "superior software" is true for most, but that's a much wider goalpost than the people specifically worried about security/vulnerabilities. One of the biggest factors pushing people to Linux lately is the increasing number of ads and annoyances being crammed in to Windows. Security has been moderate for a long time.
This seems to be quite contrarian considering we had this on the front page of HN the other day: "Debian votes to allow "responsible use of generative AI".
I guess this LLM coding wasn't "Responsible" enough. hahaha
Omarchy is all in on AI, if you look at the recent commits and the dev workflows they have set up you can easily tell no human is looking at all the stuff they are merging.
It's not the same thing as allowing some AI contributions under strict guidelines.
Even worse. They don't even have AI review them. I fed the commits that introduced the problem to a few frontier models and they saw several problems, including the aforementioned security problem. Even Mistral saw it. I did have to instruct all models to look for security problems, though, but still.
It's not that we shouldn't use vibecoded distros. It's that we shouldn't use badly vibecoded distros with shitty or non-existent processes.
On Lex Fridman recently DHH was enthusiastically bragging about how he was letting AI generate C++ that he intentionally wasn't even looking at, he was treating it as a pure black box and just submitting the output.
"Someone" didn't find that, AI found it. So it's not clear what your point is about vibe coding. Would humans have noticed this problem, especially given that it's not remotely exploitable? (you have to plug in a malicious USB device).
It’s that age old “start a docker container with the docker socket in the container and you are effectively root”. What are we talking about here? This is not new?
The fact comments like this get downvoted because what they say is inconvenient is one of the major signs AI has fundamentally broken HN.
It was already hard to have technical conversations in public, now there is a contingent determined to make it utterly impossible, and they are succeeding.
HN has been fundamentally broken for a long time, there's nothing new or special about AI. It just joins a loooong list of topics where people abuse downvotes and flagging to punish people they disagree with.
Ironically, the right fix is to replace human moderation with AI. Every so often I think about creating an HN or old-Reddit style discussion website that gets rid of user driven moderation entirely in favour of "polite but free speech" rules, assessed by LLMs on the fly, along with ways for users to label comments with various adjectives for both their own filtering and training a RecNet. A bit like a mashup of Reddit, HN, Slashdot and new ideas.
Doing that from Europe is tricky due to the lack of the first amendment, but could be worth a try anyway. It could probably be sold to an American if local laws become too difficult.
Yes. An additional reason is that both X and Reddit are no longer viewable without logging in. This might attract readers, though perhaps not posters, who need to log in anyway. But your free speech rule might make the forum one-sided over time because users whose views are excluded elsewhere would concentrate there.
https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8...
Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?