Video wird geladen...
Video konnte nicht geladen werden
Presenting the QuickLogin attack against Omarchy. Think again, is leaving your FDE laptop unattended a good idea? Let's have a look! DHH Omarchy Linux
177,387 Aufrufe • vor 2 Tagen •via X (Twitter)
47 Kommentare

@dhh @OmarchyLinux well of course, I dont think its a secret the secondary lock is not a "real" lock. It's a deterrent at best. A UI gate.. Pretty sure all Operating systems work this way

Shout out to the Beaglebone Black hardware. ifykyk

@dhh @OmarchyLinux You are actually helping even though you think you are dunking. You are not hurting anyone. The beauty of open source. Thank you.

@dhh @OmarchyLinux It’s ok. I mean, developing an os with agents is going to be a mess at the beginning but as the team gains more experience they will be delivering a much better product. And in The long run, with all the knowledge they will get, no other Linux distro will be able to catch Omarchy

@dhh @OmarchyLinux its not a distro, its a collection of dotfiles. arch is doing all the hard work

Oh good, the Distro Purity Board is in session again. Someone cloned Arch, slapped an ISO on it, gave it a name, and now we need a theology degree to decide if it counts. There is no ISO committee that certifies the word. If it uses the Linux kernel, can be installed as a complete system, and is maintained as one named product, the accepted usage is to call it a distro, even a thin or highly opinionated one. Yes, even if the maintainer has taste. Yes, even if the defaults annoy you. Yes, even if you would have named it “Not A Real Distro Linux” in the comments. The kernel does not check your vibes at boot.

@andresgrda @dhh @OmarchyLinux Did you really... let an LLM write this all for you?

@andresgrda @dhh @OmarchyLinux Yes! Was it wrong?

@andresgrda @dhh @OmarchyLinux maybe let the LLM explain the meme to you

@dhh @OmarchyLinux @FBI I don't think DHH wants you to suck his dick weirdo

@dhh @OmarchyLinux It almost doesn't even matter that this was patched. It's pure clownery that it was allowed to happen in the first place.

@dhh @OmarchyLinux I don't understand what's the exploit here. The lock screen crashed or what? Unlocking by face ID with a photo? The fact that an FDE laptop has the decryption key in RAM while not shut down is the same thing in all OSes.

@dhh @OmarchyLinux Death grips perfect soundtrack to this

@dhh @OmarchyLinux so full disk encryption only protects a laptop that is off, and the lock screen is the weak part when it is on?

@dhh @OmarchyLinux That background lmao.

@dhh @OmarchyLinux Is this unique to Omarchy or is this an issue with hyprlock?

@dhh @OmarchyLinux dhh should pay good prizes from his fund for such vulnerabilities. There is no point sharing them with him or bug reports its to omarchy for free.

@dhh @OmarchyLinux Hmmm pretty fucking weak, seems they already patched the lua injection through USB. Submit a PR if this isn't that, or the badly configure default user in the docker group.

@dhh @OmarchyLinux ah yeah? what did you type on the shell BEFORE you locked tge screen???

@dhh @OmarchyLinux uname -r

@dhh @OmarchyLinux Thank you for your service. Keep doing more please!

@dhh @OmarchyLinux Question. How to we prevent this from happening to our machines?

there's no simple answer, but: a) Arch-hardened kernel b) usbguard + blocking hid c) no new kernel module loading for network, usb, printer, etc on a lockscreen d) do something with secureboot+ima+remote attestation

@dhh @OmarchyLinux You clearly don't posses taste and correct opinions the way DHH does and are a crazy/clown person, so it is expected that you will not be able to understand the superior experience provided by dhh, the saviour of linux desktop's AI generated dotfiles.

@dhh @OmarchyLinux Dude needs to unlock a pair of fingernail clippers. Like do some hacking on those finger tips my guy.

@dhh @OmarchyLinux all that omarchy dick riding without contributing fuck outta here

@dhh @OmarchyLinux With @bl4sty you have probably a nice CTF to organize without a lot of preparation except the beers.

@dhh @OmarchyLinux Istgat Death Grips why is there Death Grips on an Omarchy video

@dhh @OmarchyLinux why not

@dhh @OmarchyLinux True

Naturally *the* song for this:

@dhh @OmarchyLinux I love the fact that so many talented people are eager to work on making #omarchy better and more secure for free. Keep going!

@dhh @OmarchyLinux This is a perfect use case for a HID attack. Do you have any documentation on this method?

@dhh @OmarchyLinux It's a lil more complex than that, but I hope to write this up soon and release when it's patched upstream.

@dhh @OmarchyLinux k… keep me posted

@dhh @OmarchyLinux We can fix everything 🤘

@dhh @OmarchyLinux Share dhh and his team as soon as possible

@dhh @OmarchyLinux Yea physical security is a huge concern for me. I’m worried my gun might not help.

@dhh @OmarchyLinux can you share what you do please is the exploit open source?

@dhh @OmarchyLinux this vid goes hard

@dhh @OmarchyLinux Omarchy is just arch with dotfiles

@dhh @OmarchyLinux Disadvantages of making os with vibe coding and dot files

@dhh @OmarchyLinux Very cool, but what's up with red fascism wallpaper

@dhh @OmarchyLinux why did it take that long to login?

@dhh @OmarchyLinux security demos like this are useful because they turn an easy-to-miss lock screen assumption into a concrete test. i'd like to see the fix and its threat model side by side.

@dhh @OmarchyLinux @dhh awesome works, keep the momentum and the money

@dhh @OmarchyLinux @dhh will give some $$$
