Omarchy development practices lead to predictable security issues

Omarchy development practices lead to predictable security issues

Omarchy 的开发实践导致了可预见的安全问题

Merchants of Insecurity 25 Aug, 2026 不安全感的贩卖者 2026年8月25日

First, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit. You can’t polish a turd. Omarchy 4.0 shipped with a collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine. 首先,发布一个公共服务公告(PSA):如果你稍微在意一下你机器的安全性,就千万不要使用 Omarchy。烂泥扶不上墙。Omarchy 4.0 发布时携带了一系列安全问题,我只能用“令人遗憾”来形容(因为我答应过我妈要少说脏话)。其中甚至包括像视频标题 Bash 注入,或者所有通知都能在你的机器上运行任意 Bash 命令这种“重磅”漏洞。

All projects have security issues but not all projects have such predictable security issues. We know how to deal with untrusted inputs. We know we should not use AI-generated bash scripts for processing untrusted input, particularly with seemingly no review. And you can’t get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited. 所有的项目都会有安全问题,但并非所有项目都有如此可预见的安全问题。我们知道如何处理不可信的输入。我们知道不应该使用 AI 生成的 Bash 脚本来处理不可信输入,尤其是在看起来完全没有经过审查的情况下。你不可能通过一堆糟糕的 Bash 脚本起步,并寄希望于别人能在漏洞被利用之前发现并修复它们,从而构建出一个相对安全的系统。

Simply put, Omarchy doesn’t treat security as important. They do role-play taking security seriously but their development practices and the ease with which they speedrun decades of security issues and invent new ones tell us much more about the security of Omarchy than Security Team announcements. 简而言之,Omarchy 并不重视安全性。他们确实在扮演“认真对待安全”的角色,但他们的开发实践,以及他们能够如此轻松地“速通”过去几十年的安全问题并创造出新漏洞的事实,比安全团队的公告更能说明 Omarchy 的安全性。

Lies or marketing? DHH loves to say he’s making the year of Linux on desktop happen. How Omarchy is the distro people should use. Showing how polished the experience is. Essentially, he’s good at marketing Omarchy. On the security front, he highlights the security team’s efforts in the recent point release. A long list of resolved security issues sure looks impressive if you start with Swiss cheese of an operating system. 是谎言还是营销?DHH 喜欢说他正在实现“Linux 桌面元年”。他宣称 Omarchy 是人们应该使用的发行版,展示其体验是多么精致。本质上,他很擅长营销 Omarchy。在安全方面,他强调了安全团队在最近的小版本更新中所做的努力。如果你从一个像瑞士奶酪(满是漏洞)一样的操作系统开始,那么一份长长的已修复安全问题列表看起来确实令人印象深刻。

I think the marketing has turned into lying, being disingenuous. An honest attitude would be to say that they care about iterating on their dotfiles much more than about basic security of the system. DHH silences his critics with fake positivity, with a “let’s fucking do it” attitude. But the reality is that Omarchy is a project which doesn’t treat security seriously and I wouldn’t be surprised if many companies ban its use. 我认为这种营销已经变成了谎言,变得虚伪。诚实的态度应该是承认他们更关心迭代他们的配置文件(dotfiles),而不是系统的基本安全。DHH 用虚假的积极性和“让我们干吧”的态度让批评者闭嘴。但现实是,Omarchy 是一个不认真对待安全性的项目,如果许多公司禁止使用它,我一点也不会感到惊讶。

Just let people enjoy things, jeez. I’m not stopping anyone. I don’t like when the public perception of how much risk someone is taking is disconnected from the actual risk of using a project like Omarchy. The team doesn’t look interested in accurately explaining it to their users. I don’t like people being deceived into hurting themselves, hence this post. Peace ✌️ “就让人们享受吧,天哪。”我并没有阻止任何人。我不喜欢公众对风险的认知与使用像 Omarchy 这样的项目所带来的实际风险脱节。该团队似乎对向用户准确解释这些风险并不感兴趣。我不喜欢人们因为被欺骗而受到伤害,所以才写了这篇文章。和平 ✌️