正在加载视频...

视频加载失败

Presenting the QuickLogin attack against Omarchy. Think again, is leaving your FDE laptop unattended a good idea? Let's have a look! DHH Omarchy Linux

177,387 次观看 • 2 天前 •via X (Twitter)

47 条评论

🦀 Triston Armstrong 的头像
🦀 Triston Armstrong2 天前

@dhh @OmarchyLinux well of course, I dont think its a secret the secondary lock is not a "real" lock. It's a deterrent at best. A UI gate.. Pretty sure all Operating systems work this way

Jurre van Bergen 的头像
Jurre van Bergen2 天前

Shout out to the Beaglebone Black hardware. ifykyk

Nyasha Dennis 的头像
Nyasha Dennis2 天前

@dhh @OmarchyLinux You are actually helping even though you think you are dunking. You are not hurting anyone. The beauty of open source. Thank you.

Andres Gracia 的头像
Andres Gracia2 天前

@dhh @OmarchyLinux It’s ok. I mean, developing an os with agents is going to be a mess at the beginning but as the team gains more experience they will be delivering a much better product. And in The long run, with all the knowledge they will get, no other Linux distro will be able to catch Omarchy

Jurre van Bergen 的头像
Jurre van Bergen2 天前

@dhh @OmarchyLinux its not a distro, its a collection of dotfiles. arch is doing all the hard work

Iain Rae Lennox 的头像
Iain Rae Lennox1 天前

Oh good, the Distro Purity Board is in session again. Someone cloned Arch, slapped an ISO on it, gave it a name, and now we need a theology degree to decide if it counts. There is no ISO committee that certifies the word. If it uses the Linux kernel, can be installed as a complete system, and is maintained as one named product, the accepted usage is to call it a distro, even a thin or highly opinionated one. Yes, even if the maintainer has taste. Yes, even if the defaults annoy you. Yes, even if you would have named it “Not A Real Distro Linux” in the comments. The kernel does not check your vibes at boot.

Jurre van Bergen 的头像
Jurre van Bergen1 天前

@andresgrda @dhh @OmarchyLinux Did you really... let an LLM write this all for you?

Iain Rae Lennox 的头像
Iain Rae Lennox1 天前

@andresgrda @dhh @OmarchyLinux Yes! Was it wrong?

Jurre van Bergen 的头像
Jurre van Bergen1 天前

@andresgrda @dhh @OmarchyLinux maybe let the LLM explain the meme to you

Jurre van Bergen 的头像
Jurre van Bergen2 天前

@dhh @OmarchyLinux @FBI I don't think DHH wants you to suck his dick weirdo

Nick 的头像
Nick2 天前

@dhh @OmarchyLinux It almost doesn't even matter that this was patched. It's pure clownery that it was allowed to happen in the first place.

DrOptix 的头像
DrOptix2 天前

@dhh @OmarchyLinux I don't understand what's the exploit here. The lock screen crashed or what? Unlocking by face ID with a photo? The fact that an FDE laptop has the decryption key in RAM while not shut down is the same thing in all OSes.

dan0mad 的头像
dan0mad2 天前

@dhh @OmarchyLinux Death grips perfect soundtrack to this

Jazz № 04 的头像
Jazz № 042 天前

@dhh @OmarchyLinux so full disk encryption only protects a laptop that is off, and the lock screen is the weak part when it is on?

Spud 的头像
Spud2 天前

@dhh @OmarchyLinux That background lmao.

Matt Jones 的头像
Matt Jones2 天前

@dhh @OmarchyLinux Is this unique to Omarchy or is this an issue with hyprlock?

Rusttty 的头像
Rusttty2 天前

@dhh @OmarchyLinux dhh should pay good prizes from his fund for such vulnerabilities. There is no point sharing them with him or bug reports its to omarchy for free.

hexa 的头像
hexa2 天前

@dhh @OmarchyLinux Hmmm pretty fucking weak, seems they already patched the lua injection through USB. Submit a PR if this isn't that, or the badly configure default user in the docker group.

Chafik Moalem 的头像
Chafik Moalem2 天前

@dhh @OmarchyLinux ah yeah? what did you type on the shell BEFORE you locked tge screen???

Jurre van Bergen 的头像
Jurre van Bergen2 天前

@dhh @OmarchyLinux uname -r

sean 的头像
sean2 天前

@dhh @OmarchyLinux Thank you for your service. Keep doing more please!

████████████ 的头像
████████████2 天前

@dhh @OmarchyLinux Question. How to we prevent this from happening to our machines?

Jurre van Bergen 的头像
Jurre van Bergen2 天前

there's no simple answer, but: a) Arch-hardened kernel b) usbguard + blocking hid c) no new kernel module loading for network, usb, printer, etc on a lockscreen d) do something with secureboot+ima+remote attestation

heap allocator 的头像
heap allocator2 天前

@dhh @OmarchyLinux You clearly don't posses taste and correct opinions the way DHH does and are a crazy/clown person, so it is expected that you will not be able to understand the superior experience provided by dhh, the saviour of linux desktop's AI generated dotfiles.

Tim Sonner 的头像
Tim Sonner2 天前

@dhh @OmarchyLinux Dude needs to unlock a pair of fingernail clippers. Like do some hacking on those finger tips my guy.

거부 ++® 的头像
거부 ++®2 天前

@dhh @OmarchyLinux all that omarchy dick riding without contributing fuck outta here

Sébastien Dudek 📡 的头像
Sébastien Dudek 📡1 天前

@dhh @OmarchyLinux With @bl4sty you have probably a nice CTF to organize without a lot of preparation except the beers.

sylvia 的头像
sylvia2 天前

@dhh @OmarchyLinux Istgat Death Grips why is there Death Grips on an Omarchy video

Jurre van Bergen 的头像
Jurre van Bergen2 天前

@dhh @OmarchyLinux why not

sylvia 的头像
sylvia2 天前

@dhh @OmarchyLinux True

Jurre van Bergen 的头像
Jurre van Bergen2 天前

Naturally *the* song for this:

Tomasz Mazur 的头像
Tomasz Mazur2 天前

@dhh @OmarchyLinux I love the fact that so many talented people are eager to work on making #omarchy better and more secure for free. Keep going!

abraxas 的头像
abraxas2 天前

@dhh @OmarchyLinux This is a perfect use case for a HID attack. Do you have any documentation on this method?

Jurre van Bergen 的头像
Jurre van Bergen2 天前

@dhh @OmarchyLinux It's a lil more complex than that, but I hope to write this up soon and release when it's patched upstream.

abraxas 的头像
abraxas2 天前

@dhh @OmarchyLinux k… keep me posted

Suraj Jadhav 的头像
Suraj Jadhav1 天前

@dhh @OmarchyLinux We can fix everything 🤘

FabianLegacy 的头像
FabianLegacy2 天前

@dhh @OmarchyLinux Share dhh and his team as soon as possible

Dursh Merkfurlin 的头像
Dursh Merkfurlin1 天前

@dhh @OmarchyLinux Yea physical security is a huge concern for me. I’m worried my gun might not help.

cat 的头像
cat1 天前

@dhh @OmarchyLinux can you share what you do please is the exploit open source?

Harry McKenzie 的头像
Harry McKenzie2 天前

@dhh @OmarchyLinux this vid goes hard

Domn 的头像
Domn2 天前

@dhh @OmarchyLinux Omarchy is just arch with dotfiles

Hyder Codes 的头像
Hyder Codes1 天前

@dhh @OmarchyLinux Disadvantages of making os with vibe coding and dot files

kenniiii88 的头像
kenniiii882 天前

@dhh @OmarchyLinux Very cool, but what's up with red fascism wallpaper

maxtraxv2 的头像
maxtraxv21 天前

@dhh @OmarchyLinux why did it take that long to login?

Mena Botrous 的头像
Mena Botrous2 天前

@dhh @OmarchyLinux security demos like this are useful because they turn an easy-to-miss lock screen assumption into a concrete test. i'd like to see the fix and its threat model side by side.

mizu 的头像
mizu2 天前

@dhh @OmarchyLinux @dhh awesome works, keep the momentum and the money

a2a 的头像
a2a2 天前

@dhh @OmarchyLinux @dhh will give some $$$

相关视频