HappyFellow.dev criticized Omarchy 4.0, a Linux distribution project promoted by David Heinemeier Hansson, arguing that users should not run it on machines where security matters. The post alleges that the release contained security flaws including bash injection through video titles and a notification mechanism that could allow arbitrary bash commands to run. It says these flaws stem from unsafe handling of untrusted input and from using AI-generated bash scripts to process such input without sufficient review. The author contends that starting from insecure shell scripts cannot produce a reasonably secure system through later fixes. The post acknowledges that all software projects have security vulnerabilities but argues that Omarchy’s reported issues were predictable and reflect development practices that do not prioritize security. It contrasts that view with Omarchy’s security-team announcements and recent point release, which reportedly listed numerous resolved issues. The author characterizes DHH’s promotion of Omarchy as strong marketing but says its security messaging is misleading, and predicts that some companies may prohibit its use. The stated concern is that users may underestimate the risks of installing Omarchy because the project does not, in the author’s view, clearly communicate its security limitations.
blog.happyfellow.dev
2 min
7h ago
HappyFellow.dev criticized Omarchy 4.0, a Linux distribution project promoted by David Heinemeier Hansson, arguing that users should not run it on machines where security matters. The post alleges that the release contained security flaws including bash injection through video titles and a notification mechanism that could allow arbitrary bash commands to run. It says these flaws stem from unsafe handling of untrusted input and from using AI-generated bash scripts to process such input without sufficient review. The author contends that starting from insecure shell scripts cannot produce a reasonably secure system through later fixes. The post acknowledges that all software projects have security vulnerabilities but argues that Omarchy’s reported issues were predictable and reflect development practices that do not prioritize security. It contrasts that view with Omarchy’s security-team announcements and recent point release, which reportedly listed numerous resolved issues. The author characterizes DHH’s promotion of Omarchy as strong marketing but says its security messaging is misleading, and predicts that some companies may prohibit its use. The stated concern is that users may underestimate the risks of installing Omarchy because the project does not, in the author’s view, clearly communicate its security limitations.
blog.happyfellow.dev
2 min
7h ago
HappyFellow.dev criticized Omarchy 4.0, a Linux distribution project promoted by David Heinemeier Hansson, arguing that users should not run it on machines where security matters. The post alleges that the release contained security flaws including bash injection through video titles and a notification mechanism that could allow arbitrary bash commands to run. It says these flaws stem from unsafe handling of untrusted input and from using AI-generated bash scripts to process such input without sufficient review. The author contends that starting from insecure shell scripts cannot produce a reasonably secure system through later fixes. The post acknowledges that all software projects have security vulnerabilities but argues that Omarchy’s reported issues were predictable and reflect development practices that do not prioritize security. It contrasts that view with Omarchy’s security-team announcements and recent point release, which reportedly listed numerous resolved issues. The author characterizes DHH’s promotion of Omarchy as strong marketing but says its security messaging is misleading, and predicts that some companies may prohibit its use. The stated concern is that users may underestimate the risks of installing Omarchy because the project does not, in the author’s view, clearly communicate its security limitations.
blog.happyfellow.dev
2 min
7h ago
No more articles to load