Omarchy is full of security holes Omarchy 4.0, the Linux distribution from Basecamp, contains multiple security vulnerabilities, including a video title bash injection and a flaw allowing all notifications to execute arbitrary bash commands, according to a security researcher's blog post. The post criticizes Omarchy's development practices and marketing, claiming the project does not treat security seriously and that DHH's promotion of the security team's efforts is disingenuous. The researcher warns users not to use Omarchy if they care about machine security. Merchants of Insecurity First, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit . You can't polish a turd Omarchy 4.0 shipped with a collection of security issues which I can only describe as regrettable because I promised my mum I would swear less . There are bangers like video title bash injection https://github.com/basecamp/omarchy/pull/7847 or all notifications being able to run arbitrary bash on your machine https://github.com/basecamp/omarchy/pull/7926 . All projects have security issues but not all projects have such predictable security issues. We know how to deal with untrusted inputs. We know we should not use AI-generated bash scripts for processing untrusted input, particularly with seemingly no review. And you can't get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited. Simply put, Omarchy doesn't treat security as important. They do role-play taking security seriously but their development practices and the ease with which they speedrun decades of security issues and invent new ones tell us much more about the security of Omarchy than Security Team announcements. Lies or marketing? DHH loves to say he's making the year of Linux on desktop happen. How Omarchy is the distro people should use. Showing how polished the experience is. Essentially, he's good at marketing Omarchy. On the security front, he highlights the security team's efforts in the recent point release https://x.com/dhh/status/2092214214005833830?s=46 . A long list of resolved security issues sure looks impressive if you start with Swiss cheese of an operating system. I think the marketing has turned into lying, being disingenuous. An honest attitude would be to say that they care about iterating on their dotfiles much more than about basic security of the system. DHH silences his critics with fake positivity, with a "let's fucking do it" attitude. But the reality is that Omarchy is a project which doesn't treat security seriously and I wouldn't be surprised if many companies ban its use. Just let people enjoy things, jeez I'm not stopping anyone. I don't like when the public perception of how much risk someone is taking is disconnected from the actual risk of using a project like Omarchy. The team doesn't look interested in accurately explaining it to their users. I don't like people being deceived into hurting themselves, hence this post. Peace ✌️