1Password faced immediate backlash from customers this week over a $300,000 pledge in support of a Linux distro created by David Heinemeier Hansson, who has regularly published overtly racist blog posts that include comments calling for deportation of ethnic minorities in Europe. The popular password manager is now a “distinguished corporate patron” of Omacom, the nonprofit foundation that oversees a popular Linux distribution known as Omarchy.
Archive: https://archive.is/osNh3
Keep in mind that internal fights among community discourage users from shifting and benefit Microsoft. I would not be surprised if the smear campaign is a big tech initative.
That’s right. But are you suggesting we just sweep it under the rug and ignore the support of racist people? Because that is what big tech does and not a lot of people like it
DHH is bell end, maybe a good developer, but a bad human being. And there are other distros out there.
Aw man, I use them because they’re Canadian but fuck them, I guess. I wonder how hard it is to switch to another password manager. I’m especially concerned with how passkeys work.
Very easy. You should be able to export your passwords as .csv and import it into a new manager.
This should help: https://di.day/en/digital-switch-recipes/passwords
Yay, thanks!
I’m so glad I switched to Bitwarden. Even without the whole extreme-right angle, the distro, that I’ve never heard of before today, seems like total slop.
Its not even a distro. Its arch with dotfiles. Literally.
No repos, no custom packages, etc. Just arch with sloppy dotfiles.
You can hate DHH, but that’s a straight up lie. They have repos, custom packages. They have an ISO installer, mirrors, even a custom kernel. If that’s not a distro then what is?
They have repos now, but nothing in them is too advanced, and they absolutely do not deserve the money. GNU/Linux Mint offers THREE great desktop experiences, which are not kitsch slop (even if you don’t like them, they’re very high-quality) and have a much smaller budget.
Yeah but Bitwarden is forkable
There is also Vaultwarden which is basically a drop in for Bitwarden
now we need a fork/replacment for their shitty clients that have unreliable offline functionality and were on an EOL Electron for like 3 months, and for rbw which hasn’t been updated in ages and has compatibility issues with bitwarden.com now
There’s KeyGuard, but the license is simply “All rights reserved.” Source available, non foss?
Yeah no thanks
I hope someone makes a replacement rather than a fork, i reallly hate Electron, we need to hope for a fork of the browser extension too
(Before anyone says anything: yes i thought of making it myself but i don’t really have expirience in security stuff and fluff so i’d rather wait for someone expirienced to do it)
I must be confusing vaultwarden with another bitwarden compatible thing and thought this is the one I have to host a server myself.
Probably better that I do that tbh
that’s right, vaultwarden is the server. It’s not a bad idea to host it yourself, but this is kinda a critical service, and the clients are not too good in keeping the data accessible if the server goes down. so, choose wisely. there are also unofficial public bitwarden servers you can use. if that sounds better, choose one that hosts multiple services and has a community around it, those have a better chance of being kept alive.
My thought process is that I set up the server on my home computer as the main base, and have that occasionally sync to my other devices such as phone and laptop, and sync back to it if I do any changes in those. The remote devices should have local database because my main computer will not always be online.
How feasible is that and how easy is that to set up?
Or should I just set up keepass instead since IIRC that’s one of the ways it can be set up.
The remote devices should have local database because my main computer will not always be online.
yeah, about that. none of the official bitwarden clients allow editing if the server is not accessible. they didn’t want to have to deal with conflict resolution
Or should I just set up keepass instead since IIRC that’s one of the ways it can be set up.
sounds like a better idea. but synchronization wise, conflict resolution has to happen somewhere. like when you edit an entry on two devices, and later they try to sync both changes at once. Fortunately tye keepass format has a more comprehensive entry edit history than bitwarden, so clients can figure it out.
keepassxc on linux supports something called keeshare, check how is compatibility for that with your mobile keepass app. original keepass on windows supports some kind of automatic merging on saving and loading, maybe keepassxc does that too? if you end up using synthing, conflicts could occur at that layer, which is not hard but not so straightforward to handle, but keeshare is supposed to help with that I think.
Nonetheless, it seems the company has sacrificed a moral position for a “mission-driven” position. In the same message to staff, Faugno says “the scale and growth of [Omarchy’s] use among our customers is significant - Omarchy has grown to be the second most used Linux distribution among 1Password users."
I didn’t know Omarchy existed until, like, yesterday, so this is surprising. Do 1Password users just tend not to use Linux, so second place isn’t many users?
Probably because Omarchy is preinstalling 1password.
Isn’t that a commercial product for which great open source alternatives exist? What kind of distro does that?
And don’t they also preinstall Basecamp, DHH’s own company’s product?
Maybe it’s all just a vehicle for product placement.
What kind of distro does that?
One that does not care at all about having maintaining a sane and open ecosystem. Where there’s money to make, they will prey down quickly. Now that people are somewhat convinced that Linux based systems can work and actually attract the general public, a whole new market is ripe for reaping.
I haven’t checked but I would guess that 1password comes pre-installed in Oligarchy and they’re counting every user that loads the client as a “user.”
I love the Oligarchy typo
I feel like this has to be made up, downstream repack distros almost never show up on the top 10 usage stats. You will always see Ubuntu way ahead of Kubuntu.
Not to mention 1Password is a pretty popular enterprise app and I have yet to see some insane sysadmin actually roll with arch as their distro of choice. Most are probably on RHEL or some other enterprise derivative.
It’s probably not made up because 1Password is pre-installed and bound to a hotkey in Omarchy. Linux users making informed decisions about what to use for password management probably don’t pick 1Password most of the time due to its terrible security record.
lol what. 1Password literally has one of the best security records out there. They’re the ones actually inventing new more secure ways of doing things. The fact that those are all of the issues over the years and they’re one of the most popular pw managers on the planet is pretty indicative of how strong their security actually is. And they’ve never had a password breach, unlike lastpass.
They are nonfree.
That piece of information seems like key context. 1Password didn’t just give money simply because they like the product. More or less, it’s product placement in return for funding.
I’m on the fence if that’s better or worse.
I said somewhere else that giving money to a distro won’t even have an ROI, but I didn’t know about this. If the distro is promoting their product that’s a whole other thing.
Ah didn’t realize it came preinstalled lol.
spoiler
Prepackaged “superior” arch distro and the best they could come up with was 1Password? seriously lol?
1Password is the best they could come up with when “best” is measured in dollars contributed.
Terrible security record?
Of the items listed in your link, only the second one seems problematic, in that I wish they had discovered the (non-password but still privacy related) issues first. Even that section acknowledges all of the issues are fixed. The only section that makes it sound like there is still a problem is the last one, which states that version X still contains the vulnerabilities, but in reality that’s just how versions work. Patching a vulnerability creates a new version.
Is there ANY record of passwords being leaked from 1password because of their own lack of security??
Why does Omarchy even need this money when it’s run by a billionaire?
This song have just been sent to Arch or some Linux foundations.
Because there are multiple Linux options, once the commercial versions flood in, the most marketed will grab the biggest share of the uninformed populace. So obviously the billionaires want to wrestle control over it.
Thankfully it looks so unserious that it will not capture anyone except ‘windows/mac power users’.
So the majority of people.
The backlash to 1Password’s funding should have been predictable
Managers don’t know shit
The worst part is, giving money to a Linux distro isn’t likely to have any real return on investment, so why is it even worth a risk of backlash?
It preinstalls their app.
Indeed. Maybe nazi?
1Password does not endorse hateful, dehumanizing, or exclusionary views, including those shared publicly by DHH.
Except… ya just did. Big 'ol cashy money endorsement.
Or did you forget about that already? Because we didn’t.
Art / artist.
Why does this shit distro deserve all this funding and support? There’s many better options doing a lot more for the ecosystem yet this gets the attention. It’s don’t understand.
That’s the thing about real world. People don’t ask for permission to do things.
If you think you can do better, who’s stopping you?
I think we all know why. Whether having money causes racism, or it just so happens that racists are the ones with the money and they’re good at keeping it “In The Family” so to speak is kind of tangential and academic. It’s the hateful bigots that have the cash to fund big things, so if you want funding, it pays to be trashy.
This is what I think it is.
Very seldom is something funded that “deserves” it. The answer is that its’ creator (DHH) is very wealthy and connected.
It uses AI to fix issues and errors. And billionaires need people to use AI as much as possible.
to fix issues and errors
and create more issues and errors, like executing USB device names as root.
I think it’s time to start a company that produces excellent mice named rm -rf / --no-preserve-root then
it’s the circle of slop

Look! There’s a lion! Oh my god!
Nice reference bro!
But seriously what is the actual reason for the donation
Billionaires like racists?
Bundling of their stuff into the base installation, I suppose. With simple math, if 1password gets like 33k subscription payments, that’s about $100 000 already.
Omarchy got perhaps a 100K installations just last month.
They’re buying customers and visibility with a sum that’s probably pocket change for them.
Per @GreenBeard@lemmy.ca’s comment
I think we all know why. Whether having money causes racism, or it just so happens that racists are the ones with the money and they’re good at keeping it “In The Family” so to speak is kind of tangential and academic. It’s the hateful bigots that have the cash to fund big things, so if you want funding, it pays to be trashy.
They aren’t just racist, They also hate the poors and basically anyone that isn’t them.
I agree, but I suggest you direct your replies directly to the source comment. I’m just the messenger here.
did they do a Proton?
I think proton dodged a bullet as the comment of the CEO was only not okay, but not like super bad. But if you funnel 300k to a openly racist idiot, that’s super bad. Same with Mullvad. As soon as money flows, you are immediately batshit crazy.
Seems closer to a Mullvad
“popular Linux distribution known as Omarchy.”
I’ve literally never heard of it.
Popular for Linux, not popular for Marvel movies.
It’s virtually unknown in the Linux world too. It’s literally something they made up overnight and are trying to astroturf.
I’d say “what a time to be alive” to see the day someone considers it worth astroturfing a Linux distro, except there’s probably some nefarious shit behind it.
Still not convinced it’s very popular.
Oh well if you’ve never personally heard of it, it must not be popular, right?
I’m not OP but yeah, basically. People who are passionate about a specific topic will know what’s up in that area.
I can name half a dozen of the most popular Arch-based distros off the top of my head because… they’re actually well-known. Meaning they’ve been around for years, I’ve used several personally and can argue their pros and cons, and they feature prominently in objective lineups like the Steam Hardware Survey. Omarchy is none of these things.
I only know of it because I was on Distro Watch this week looking for top mention distros I never heard of. The mentions position is likely because of this donation. lol
It’s yet another distro being shilled by god knows who on YouTube and other social media.
The fact that it’s being pushed so hard without anything of note about it is already suspicious to me.
I’ve seen a handful of videos about it recently that have been pushed into my algorithm. There’s definitely a campaign to get it out to influencers. Never heard of it prior to this week.
It’s just a fork of Arch, with tiling, that’s been slop coded with AI. Something anyone could recreate without AI in a couple hours if they’re familiar with Arch.
It’s not even a fork or an actual distribution or anything. It’s just Arch Linux with a bunch of dotfiles made using AI and some pre-installed packages.
But could you recreate it with $30mil and AI‽
/s
Touche.
Don’t forget that’s “macOS inspired”.
Meanwhile actually good distros are drowning at the bottom of the ocean.
yeah this is like a bunch of other internet things where I kinda hate it even seeing it. for me its not a thing of interest.
I’ve heard the name but have not spent the time to find out what it is. I thought it was some immutable distro. I think the same about bazzite and catchy (sp?) which are other distros I see mentioned from time to time and believe are immutable and flatpak-y and that’s all I know. I realise I’m just one data point but I never see a lot about these sorts of distros in my general browsing.
Popular?
Sure Jan…
I don’t use password managers and I’ve never been exposed.
If your password is 16 characters with a letter, number, symbol, and is more than 1 word it will take millions of years to brute force. Just use multiple passwords and change the important ones every few months in case of data breach and you’re golden.
Forgot your password? If you have access to an email with multiple 2-factor you can recover any account in about a minute.
Then you forgot the whole point of password managers which is having a place to store all your credentials, what you said are not reasons to not use a password manager but rather some good practices that you can use alongside a password manager lol
Having all of your credentials stored sounds like a detriment and a pointless amount of trust for a shady group like 1Password who conspire with literal fascists.
This is why I’ve not used one. The whole point of passwords is privacy, yet people put them all in one place controlled by someone else where you have no way to verify how secure they actually are. And you need a password to get into it, so now there’s one password that could be breached to gain access to everything.
Local password managers exist too, look at KeePassXC
You could probably use a local password file like Keepass.
But why? The user said it was stupid to keep them all in one place controlled by somebody else, and if keepass never updates then that is its own can of worms. You would literally be better off with sticky notes than that because then at least attackers have to be present locally.
It is encrypted.
I literally never talked about 1password, they aren’t the only password managers nor you need a password manager on the cloud (look at KeePassXC), I currently use Bitwarden because i need to be able to sync the password on multiple devices but in the light of what they are doing, I probably need to start hosting a Vaultwarden instance…
Wasn’t Omarchy literally just a couple of dotfiles for Arch and a easy Installer?
It also has a few native apps now.
“Beautiful, fun and agentic linux” I bet they vibe coded all of them lol, this is a HUGE red flag

Which are slop.
It is currently more than that, and it even has its own repos/mirrors, but the fact that basically every rich person is throwing money at this project should be a huge warning sign to everyone to avoid this.
But at the end of the day, it’s nothing revolutionary. It’s customized Linux with a tiling window manager, all funded by billionaires and developed by a turbo racist.
Except for the very last part (I hope…), it’s the case of most “funky crazy distro” out there.
So YT’s algorithm is pushing right wing racist distros?
Huh. Wonder who is paying to make that algorithm work that way.
And hoo boy, you should see the bearded influencer chuds pushing this slopfest.
Like NetworkChuck.
Always has been. 🌍🧑🚀🔫👨🚀
Lex Fridman, The Primeagen and friends are also to blame
1Password says “Our contribution is made to the Omacom Foundation, not to an individual” but there are many instances of their VP of product praising DHH https://x.com/jmeller/status/1971530423030387081 https://x.com/jmeller/status/2094132068342964671
Why isn’t this in the article? That’s literally a journalist’s job to provide that kind of context.



























