According to a blog post titled “Merchants of Insecurity” published at https://blog.happyfellow.dev/merchants-of-insecurity/, the author advises against using Omarchy 4.0 for anyone concerned about machine security. The post states that Omarchy 4.0 shipped with a collection of security issues described as regrettable. Specific examples cited are a video title bash injection vulnerability and the ability for all notifications to execute arbitrary bash commands on the user’s machine. The author acknowledges that all software contains security problems but argues that Omarchy’s issues are particularly predictable and stem from known unsafe practices, such as using AI‑generated bash scripts to process untrusted input without adequate review. The post argues that starting with a codebase likened to a “pile of bash slop” and hoping others will catch and fix flaws before exploitation is not a viable path to a reasonably secure system. It further claims that Omarchy’s development approach shows the project does not treat security as important, despite public statements and security‑team announcements that suggest otherwise. The author notes that DHH, who promotes Omarchy as a polished desktop Linux distribution, highlights resolved security issues in recent point releases, but suggests that such a list appears impressive only because the baseline is likened to “Swiss cheese.” The blog post characterizes the marketing around Omarchy as having become disingenuous, asserting that an honest stance would acknowledge greater focus on dotfile iteration than on fundamental system security. It describes DHH’s response to critics as relying on fake positivity and a “let’s fucking do it” attitude, while maintaining that the reality is a project that does not take security seriously, to the point that the author would not be surprised if many companies chose to ban its use. The author says they are not trying to stop anyone from using Omarchy but objects to the disconnect between public perception of risk and the actual risk involved. The post concludes by expressing concern that the Omarchy team does not appear interested in accurately explaining security matters to users, and that the author dislikes seeing people potentially harmed by such misunderstandings.

