logoalt Hacker News

RandomGerm4ntoday at 7:08 PM0 repliesview on HN

Even though I wouldn't really use something like that myself, I actually think it's a good thing when people share their dotfiles with others. Whether you call it a “distribution” or not is basically irrelevant, and I don't understand all the fuss about it.

However I would still generally advise against using Omarchy because the maintainer does not seem to place any importance on security. For example the default firewall configuration leaves the SSH port open and the number of failed login and sudo attempts before a timeout has been unnecessarily increased. Furthermore Omarchy installs some of the offered programs via a .sh script that is downloaded via curl rather than using a package manager like the one Arch already has. In addition Hannsen still refuses to sign his commits, which means it's only a matter of time before a supply chain attack occurs.