A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
There seems to be a notable amount of FOSS coders of the old guard (90s til 00s) that are like that.
I long frequented a place called linuxquestions.org. You wouldn’t believe how right-wing to libertarian most of the people there were. Still are I guess.
Some gained status (Ruby on Rails was a big thing 1 or 2 decades back) and started spouting things because they knew people were listening.
Some people in such communities recognize that there’s something off here, and they have this excuse ready: all coders/nerds are basically on the spectrum (they don’t phrase it like this though) and don’t know how to phrase things politely, they just blurt it out.
As if that makes things better when you think like that guy.