A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
When I explained X11 on FreeBSD to Windows users 25 years ago, I said, “you start from the pretty side and work towards the ugly. I start on the ugly side and make it pretty.”
Omarchy is turning a perfectly decent OS and putting a pig outfit on it and giving it lipstick, then calling it pretty.
hows BSD for everyday use compare to linux?