1Password’s donation is probably directed toward the Omarchy project itself (although the donation goes to the recently established Omacom Foundation first, if I understand correctly), while Berntsson donated to an immediate cause, i.e. a political party.
1Password could have not considered Heinemeier-Hansson’s political stance (his linked blog posts really are problematic, narrow-minded and also bend the truth), but the foundations goal is not a cleansing as it might be for Sweden’s Örebro party.
That being said, this still associates 1Password with Heinemeier-Hansson’s view for me personally now, even if it happened unknowingly.
Of course pretty sad about the route that 1Password choose to follow and there are no excuses for me that they don’t know where they donate the $300,000.
Another recommended paying service is using our money for “controversial” donations.
Maybe the site needs to add a small controversy note in services like Mullvad VPN, 1Password etc, so new people who are looking to buy or subscribe to these services are better informed?
People really seem to love the anti-immigration kool-aide. I don’t really hold this against 1Password—it is quite different from what happened with Mullvad.
I don’t believe a companies/owners/employees political stance or donations have anything to do with “Privacy” and I don’t believe PG should get involved in a companies politics. It just wouldn’t be a good thing for PG to do
Whether or not some are offended by the political implications of the donation, I think we can all come together across ideological lines and be offended that somebody looked at Omarchy and said, “Yes, this is where $300,000 should go.”
Something I have noticed, and find rather sus, is the money being given to Omarchy - which is about $13 million. For what? A riced-up Arch Linux? Just because the guy behind it has his own Wikipedia page? Someone better tell /r/unixporn they could all become really wealthy.
Like most Arch Linux derivatives, they have poor practices, such as encouraging users to rely on Chaotic-AUR, which is a massive supply chain risk, or maintaining separate repositories with hugely outdated packages and a spaghetti of shitty shell scripts. I think one example brought up in chat was the massively outdated Chromium they were shipping (which is known for exploits being used in the wild when they become public).
And if you’re not convinced, it even came with its own exposed Docker socket. Before anyone says “but they fixed that,” it should never have been a thing that needed fixing in the first place. Docker socket proxies have existed for a long time.
A much better way of doing it would have been simply an ostree image with a the few changes he required on top of that (like what Secureblue does) which is a much better distribution for developers with a lot less risk due their build architecture and auditing.
If 1Password developers seriously use Omarchy it would be enough reason for me not to use 1Password due to supply chain risks.
I believe everything is political, in the sense that any of our choices is influenced, to some extent at least, by our culture, group mentality and inherited assumptions.
Political stances of software developers or vendors is of critical importance because it says a lot on what might be expected from them in the future, in particular about their products’ governance.
Endorsing fascist views (even involuntarily) necessarily leads, one day or another, to promote (or even help) mass surveillance.
I think no trust can be granted to someone vending software and having fascist views. Even if, at first, they want to promote anonymity and confidentiality in line with libertarian views, to ensure they and their fellows can escape what they regard as unfair censorship, the seeds of intolerance and control is at their core and will grow to invasive surveillance deeds to ensure control against what they will inevitably call “the enemy from within”.
I am also very, very confused about the hype around what I have perceived to be like … a customized Arch Linux. Which… is every “I use Arch btw” person’s desktop. It’s like the entire purpose of Arch.
Yeah except you can’t say “btw i use Arch” if you’re using some frankenstein arch distro with old packages. When you consider Omarchy’s fork of chromium was literally for theming it’s kind of hilarious and gives you no confidence in the project. Again, before anyone says “but they don’t do that anymore”, they should have never done it in the first place.
From what I understand, it’s also largely vibecoded, which I assume is part of the reason there’s seemingly an unending flow of security issues. It includes a bunch of AI-centric stuff, effectively encouraging users to vibecode their configurations and so on as well.
Even ignoring DHH’s personal opinions, that 1Password thinks Omarchy is worthy of support despite being a collection of shitty vibecoded shell scripts and outdated packages with the security properties of Swiss cheese is enough for me to dismiss them and their products outright.
TBH I think pretty much everyone in their donor list is untrustworthy. It’s also amusing that 1Password is now the only corporate sponsor other than 37signals, which DHH co-owns.
I recommend reading this post: Your Racist Linux Distro Is Very Nice . Not so much for what it says, but for its references to DHH’s own articles (although there is plenty of other material).
Wolves, sheep, and gypsies — He equates Roma people with a population of wolves that has become a threat. He does what all racists do: generalises from the behaviour of a few to an entire people. Their deportation, in his view, would be akin to culling animals to protect society.
As I remember London — Native Britons are white Britons, and their gradual decline amounts, as conspiracy theories would have it, to a ‘demographic replacement’. An invasion! Some citizens are treated as second-class citizens.
The Rape of Britain — Pakistani Muslims versus the ‘white British nation’. Generalisation, ethnonationalism and a lack of evidence. Quite a cocktail.
I don’t think 1P is trying to fund ethnic cleansing, but I do believe that every company should review who it donates to. In that respect, Proton, for example, has a sound policy and a good track record. Nor do I think we should become overly self-righteous about this. Using 1P is not tantamount to supporting DHH, although I would personally switch to another password manager to avoid indirectly funding him.
Kernel development, mise, Hyprland, Quickshell, some designer stuff
Do they?
I think this is true for every upcoming distro.
Ostree doesn’t address the packaging, they’d still have to rely on people providing packages. Last time i’ve tried Secureblue, Fedora shipped a super outdated version of Hyprland and i had to resort to Copr repository even for the most basic stuff, and my Mullvad VPN was leaking due to NetworkManager. Secureblue has no notion of a “VPN that doesn’t leak” and just assumes people are fine with relying on NM. I personally couldn’t rely on secureblue if i were to travel to China, for example:
If your VPN is broken, consider importing the configuration, instead of using the Mullvad GUI or wg-quick
Our glorified shellscripts + python + justfiles, their shitty shell scripts… I don’t see any improvement whatsoever, there’s nothing declarative about secureblue.
which is a much better distribution for developers
Yeah, let me just… maintain the entire OS because i wanted to swap network manager… So much velocity… The entire OS screams “you’re holding it wrong”.
If you want to add your own customizations on top of secureblue that go beyond installing packages, unless you are contributing, you are advised strongly against forking. Instead, create a repo for your own image by using the BlueBuild template, then change your base-image to a secureblue image. This allows you to apply your customizations to secureblue in a concise and maintainable way, without the need to constantly sync with upstream. For secureblue development purposes, forking then building with GitHub Actions is the recommended approach.
I’m not so sure about that, because frankly some of the security issues would have actually been avoided by AI, though it does depend on the model used and if you’re using it to make any risk assessment.
Pretty much and they pass this all off under the word “opinionated”, but the reality is the criticism of that distribution is valid, and based on fact.
I have to wonder whether there’s some sort of tax avoidance shenanigans or of that kind - of course that is speculation. $13M USD along with it being from all notable people seems strange. I somehow doubt they’re all users of Omarchy and I also doubt their companies have any commercial interest in it.
These are all developed by third parties, why wouldn’t you just donate to them directly. I’m sure it includes Wayland too and Python and maybe some GNU software too.
They used to as of version 2.1 but, now they have their own repository with out of date packages like a out of date chromium fork just because of theming although they’ve now ditched that too.
AUR should not just be treated as a package manager without very serious warnings. The reason Arch does not include it by default is because it can break your system as all pkgbuilds are not vetted in any way and are user content. I would bet most users of it are not auditing their pkgbuilds every single update to detect supply chain risks.
It is a particularly bad issue when developers use this distribution, and potentially are exposing their customers or users to those risks.
No, a distribution shouldn’t be forking packages needlessly like Chromium over theming choices and then failing to keep those up to date with upstream. That puts user security at risk and should never have been a decision made in the first place. The fact they don’t do it now is not the issue, the fact they ever did presents a judgement one though.
In an ostree distribution you’re primarily using Fedora’s packages as a base. They do that with Archlinux in a sense. You would provide your own packages for hyprland or whatever as a part of that image and build it on public infrastructure. It would mean less work for the distributor as they only have to focus on the specific things they need.
Image-based OS distributions can integrate SLSA build provenance directly into their build pipelines, with secureblue also planning to implement automated SBOM generation. This security architecture relies on cryptographically signed attestations so downstream mirrors and end users can easily verify that the operating system was in fact built on trusted public infrastructure.
They are a whole lot more readable, documented and audited by humans. Security is a decision that is considered during production rather than as an afterthought.
Does ujust install-vpn and installing the Mullvad client not work? My self I just used the IVPN client and it worked okay.
Having said that, I would not rely on VPN killswitches on any platform to really work as these have often shown to leak in unexpected ways. If I was traveling I’d probably get a portable router like one of the ones from GL.iNet.
It would seem that’s some third party fan project, not really an official project though so who knows how long it will be maintained for.
I haven’t kept up with Nix too much though I am hoping progress is still being made on SELinux on NixOS.