cat manual/48-security.md
Omarchy takes security extremely seriously. This is meant to be an operating system that you can use to do Real Work in the Real World. Where losing a laptop can’t lead to a security emergency. So here’s what we do:
omarchy-update. You’re always running the latest, most secure versions of everything that way.You have two passwords on an encrypted install: the one that unlocks the drive at boot, and the one you log in and sudo with. Both can be changed under Update > Password in the Omarchy menu — Drive Encryption for the first, User for the second. Changing the drive password asks for the current one first, so have it handy.
If you’re handing your machine over to someone else, you don’t have to reinstall it. Run Setup > Reset Computer in the Omarchy menu, type reset to confirm, and reboot. That wipes every user account and everything in /home, throws away all the packages and system changes you made since installation, and clears the machine’s identity — network connections, host keys, and all. What comes back up is the setup wizard from the first boot, ready for its new owner to enter their own name, password, and encryption password.
It works by restoring the baseline snapshot the installer takes, so it’s only available on machines installed from the Omarchy ISO. And on a drive without encryption, a reset is deletion rather than a secure erase, so if the data was sensitive, do a fresh install instead.
Sometimes you want sudo to stop asking, most often when an AI agent is doing a long stretch of system work for you. Setup > Security > Passwordless Sudo turns that off for 15 minutes and then puts it back automatically. Run it again before the timer runs out to end it early, and pass your own number of minutes with omarchy-sudo-passwordless 30 if 15 isn’t enough.
Be clear-eyed about this one: while it’s on, anything running as your user can do anything as root without being asked. That’s the whole point, and it’s also the whole risk.
The public key for all ISO signatures and Omarchy repo package is 40DFB630FF42BCFFB047046CF0134EE680CAC571 (verify at openpgp.org). The omarchy/omarchy-keyring package contains this as well and will be used to rollout any potential updates seamlessly.
You can find the signature for any ISO release by adding .sig to the URL. Like https://iso.omarchy.org/omarchy-x.x.x.iso.sig.