| ▲ | exitb 4 hours ago | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | pibaker 4 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
It is one thing to do things the risky way on your own system and another thing to ship an unsafe and unconventional default to your users. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | steve1977 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
Using Docker instead of podman is the first mistake and that is a distro decision (or a "chef" decision, in Omarchy parlance...) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | dawnerd 40 minutes ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
Docker itself is such a massive security problem. Like it’ll punch through your firewall. Found out the hard way after a misconfigured redis was exposed to the web. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | gruez 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | lrvick 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
Docker can be run rootless. It is so easy. No excuse for desktop distros to not do this by default. And that is why all major Linux distros are just as bad as Omarchy (Not recommending MacOS or Windows either as those are wildly worse) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | Aurornis 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
> but I’m not sure this should be framed as Omarchy-specific, Adding the user to the docker group by default, out of the box, is Omarchy-specific. EDIT: More accurately, was Omarchy specific, until they realized that it's not a good idea and changed it. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | StrLght 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
Exactly! I was also surprised by this — that's a sensible default for many people. However, I agree that it should be opt-in. Docs should be more explicit about that too, they should warn users about risks of going with that option. That excerpt mentioned in the article was rather misleading. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | pixl97 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
This also seems like one of the more common things LLMs use to priv escalate themselves when not given root access, seems like a rather common misconfiguration. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bakugo 2 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
It's absolutely not Omarchy-specific, Ubuntu has the exact same vulnerability out of the box, just with lxd instead. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||