Earlier quoted context omitted.
Why do they need money? What happened to their funding?
One of the major sources of funding was cut because they sided with the devil...
Rubygems.org AWS Root Access Event – September 2025
101–110 of 179 posts
Re: Rubygems.org AWS Root Access Event – September 2025
#102AWS account root access on a language package registry for 11 days. Not EC2 root - AWS account root. Complete control over IAM, S3, CloudTrail, every-damn-thing. They're claiming "no evidence of compromise" based on CloudTrail logs that AWS root could have deleted or modified. They even admit they "Enabled AWS CloudTrail" after regaining control - meaning CloudTrail wasn't running during the compromise window. You ca…
Isn't the subtext of this post pretty clearly that the unauthorized actor was Andre Arko, who had until days prior all the same access to RubyGems.org already? The impression I have reading this is that they're going out of their way to make it clear they believe it was him, but aren't naming him because doing so would be accusing him of a criminal act.
Re: Rubygems.org AWS Root Access Event – September 2025
#103Earlier quoted context omitted.
[flagged]
I think the point being that whatever was going on with access controls here was blatant gross negligence, because what is this guy doing with access who doesn't literally own the organization or the intellectual property? Set that aside, which obviously stinks, but then why is said obviously incompetent organization sharing confidential corporate emails with the public, saying this guy proposing a corporate data acc…
Re: Rubygems.org AWS Root Access Event – September 2025
#104Earlier quoted context omitted.
An entity that promised security had a security incident due of their incompetence to properly secure their production environment root access?
If somebody is going to abuse their accidentally-retained access after being removed from my organization, than the incompetence was in having that person in my organization in the first place. It turns out they were perfectly justified in removing him! First of all, it's criminal, and second of all, it absolutely lights a torch to any credibility they have. I expect people don't want to become unhireable. I've had a…
it would be quite easy to argue that ruby central had never had a right to remove these people at all
> I've had access/credentials to organizations that I've left and never abused them even once.
yes, likewise
and if I was Andre I wouldn't have even have ATTEMPTED to do this, as it looks terrible regardless of the eventual legal determination
Re: Rubygems.org AWS Root Access Event – September 2025
#105Earlier quoted context omitted.
Can't a middle compromise happen as it happens in something like golang? Can some vps/serverless provider not do this like fly.io as an recent example with kurt got got? or hetzner? I think that golang's model can actually be sort of cheaper/ more cost effective for servers as compared to how ruby might be doing it right now and so cheaper might mean that a new non profit can be created which can work on less money/o…
> I think that golang's model can actually be sort of cheaper/ more cost effective for servers as compared to how ruby might be doing it right now and so cheaper might mean that a new non profit can be created which can work on less money/outside funding/drama overall It also means no code signing and the natural capture of most of the ecosystem by Microsoft (due to devs preferring to host their code on github, a bun…
But this is so so much better than having arko or somebody having your PII.
Like I hate github but I am pretty sure that people there aren't actively looking for my PII when I download go projects or that a single person couldn't really access it I suppose
I am not really familiar but if I remember the heads project related to coreboot isn't there a way to sign your github repository with your ssh key or something related (I can be wrong, I usually am)
Like I know it could be a pain in the ass but if you are so worried about github, what if we could optionally have everything be gpg'd via ssh keys & the project could only work if someone shares a ssh key
And something like rubygems could just have a name github mapping gpg mapping and it might require some additional software right now but I am just giving ideas maybe for new languages as well I am not sure
What are your thoughts? And what do you think the ideal way could be. I have heard from many people (like primagen) that golang is the best package model and I also resonate with that statement but yeah github is a bit of menace/threat to open source
All the more reason to use something like codeberg!
Re: Rubygems.org AWS Root Access Event – September 2025
#106Earlier quoted context omitted.
Yes! Not even sure why you are being downvoted, this is such a great idea actually. F-droid has been so professional and they are just so professional There was this developer (axet) who recently accused f-droid of somehow convincing the users "maliciously" that the funds are going to the the creator and f-droid when in reality it was going to f-droid and he name called them and what not.. Do you know what f-droid te…
> Not even sure why you are being downvoted, this is such a great idea actually. Expressing negative opinions about DHH is not well-received here. Oddly enough the Ruby community includes both the most thoughtful and gentle people and the biggest assholes I know... I refuse to believe the latter are not fringe.
and in fact I was using omarchy but then migrated over to cachyos hyprland
https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug...
DHH is not a good guy but the hype around him made me feel so. He's weird and racist and fascist.
Stop the hype around dhh and everyone please read the article everybody here's DHH reality
Let’s ditch the superlatives and review David’s post objectively:
He thinks that even if you were born in the UK, you only count as British if you’re white.
He wouldn’t consider living in London specifically because it has too many people of color.
He uses racist tropes to accuse Asian men of being dangerous predators who attack white women.
He pushes debunked conspiracy theories about immigrants replacing white people.
He finds a march where speakers called for banning all non-Christian religions and ethnically cleansing immigrants “heartwarming”.
Finally — and maybe most alarmingly — he argues that all of the above is normal and not extreme.
You can use whatever word you want to describe all that. But if you, like me, didn’t realize that this is who DHH is, we can probably agree that he’s way worse than we thought.The above lines were from the article
This guy shouldn't remotely be talked about in a good light imo, yes I appreciate open source but I can't seperate the art from the artist.
I genuinely don't know why they defend this guy.
HN literally flaged this post in literal minutes when it had come out but I was lucky to have read it and I will continue to spread this word because HN's moderators seem to flag anything like this and its kinda sick and enabling behaviour really
They will allow the post that cf is sponsoring omarchy promotion thing or omarchy links in general but not a dhh-is-way-worse-than-i-thought/and I was surprised by how quickly they deleted the post that after I had read that post, it got flagged and I couldn't even write a comment.
A little bit Shocking if I can be honest.
I was on omarchy but now I am on cachyos hyprland and I learnt some custom live iso stuff too, I might make an article about it... I edited this because maybe I got a little angry towards DHH but I genuinely don't like the guy. I genuinely admired him as a person untill I found about it and I have strong opinions on him.
I think its the paradox of tolerance, should we as a society be tolerant to the intolerant people?
Re: Rubygems.org AWS Root Access Event – September 2025
#107Earlier quoted context omitted.
Isn't the subtext of this post pretty clearly that the unauthorized actor was Andre Arko, who had until days prior all the same access to RubyGems.org already? The impression I have reading this is that they're going out of their way to make it clear they believe it was him, but aren't naming him because doing so would be accusing him of a criminal act.
The other subtext is that they literally have no idea how to run rubygems securely... And what to do in case of a security incident...
Re: Rubygems.org AWS Root Access Event – September 2025
#108Re: Rubygems.org AWS Root Access Event – September 2025
#109Earlier quoted context omitted.
To me that sounds like security by obscurity not actual security. If you have the ability to go through the reset flow than then why is that much different than the username and password being available to a limited sets of users. That would not have prevented this from happening if the determination was made that all 3 of these users need the ability to possibly get into root. As far as having an IAM user, I fail to…
Not using root means not bypassing policies. There is no way to not bypass all policies. So yes, never using root makes that issue go away completely. As for all the other stuff: what it does is it creates distinct identities with distinct credentials and distinct policies. It means that there is no multi-party rotation requires, you can nuke the identity and credentials of a specific person and be done with it. So a…
It depends on what the goal of all of this was, which is unclear. If the goal was simply to get the data that they originally wanted it does not solve that problem and it would have just happened a different way.
According to the article there was 11 days between the first actions taken and them finding out it happened.
If instead of a root account you have a long running IAM user that you can then assume into the role you normally use through SSO. If you also do not monitor that account with proper alerts and proper offboarding procedures than they could have logged into that account and retrieved the data they wanted.
Which again is the reason I am saying they just saying not using root is not a magic bullet that would have avoided problems. Maybe the situation would have been different but they still could have done a lot in 11 days.
Re: Rubygems.org AWS Root Access Event – September 2025
#110Earlier quoted context omitted.
CloudTrail logs for the last 90 days are enabled by default, cannot be turned off, and are immutable, even by root. If you view this “event” as starting when Arko was supposed to have their access terminated, that’s within the 90 day window and you can indeed trust the logs from that period.
CloudTrail's 90-day immutable Event History only logs management events (IAM changes, instance launches, bucket creation). It does NOT log: * S3 object reads/writes (GetObject, PutObject) - these are "data events" requiring explicit configuration[0] * SSH/RDP to EC2 instances - CloudTrail only captures AWS API calls, not OS-level activity[1] With root access for 11 days, someone could modify gem files in S3, backdoor…
For S3 objects, you don’t necessarily need data events to identify if tampering happened. S3 objects are immutable as well, so if any changed you would see that reflected in the creation date and new hashes that S3 attaches as tags, which you can correlate with application logs to see if they match up or not. It’s not as simple as data logging, sure.
But you’re also missing the key component here that they did not say they only just enabled CloudTrail logs, they’re saying they just now enabled CloudTrail log alerting. We don’t have any idea if data events were enabled or not, or if things like flow logs were enabled or not, or what other investigation tools they have running at the application layer. However, even if none of existed, there’s still a lot more audit-ability of events that happen in an AWS account than you’re implying, even the root account.