If they really have ethical concerns regarding sharing data with third parties, maybe they should update their privacy policies accordingly? "We collect information related to web traffic such as IP addresses and geolocation data for security-relevant events and to analyze how and where RubyGems.org is used." ( https://rubygems.org/policies/privacy ) "We may share aggregate or de-identified information with third par…
Rubygems.org AWS Root Access Event – September 2025
121–130 of 179 posts
Re: Rubygems.org AWS Root Access Event – September 2025
#122Earlier quoted context omitted.
The other subtext is that they literally have no idea how to run rubygems securely... And what to do in case of a security incident...
The other other subtext is that this sure is an effective distraction from their governance problems, and muddies the waters. Given the utter lack of trust I have for anything the Ruby Central folks say at this point, given the amount of spin and misinformation they've spread already, my default assumption is that this is an excuse to malign someone who may well have had legitimate access, in the process of claiming…
> Regarding Arko’s blog post about his removal, McQuaid [Homebrew Maintainer] told me it’s good that Arko is crediting other people for their contribution and that he’s following open source principles of community and transparency, but that “his ‘transparency’ here has been selective to things that benefit him/his narrative, he seems unwilling or unable to admit that he failed as a leader in being unwilling or unable to introduce a formal governance process long before this all went down or appoint a meaningful successor and step down amicably.”
Re: Rubygems.org AWS Root Access Event – September 2025
#123Ethical and legal boundaries? RubyGems Privacy Notice already tells you that they share information with a number of large firms and notably ClickHouse... for "Customer Data Processing." All this proposal does is request from one of the maintainers/on-call providers? another entry in this Privacy Notice as a part of a payment deal. This is a mess, but it also unnecessary smears both sides. It calls out that RubyCentr…
[flagged]
Re: Rubygems.org AWS Root Access Event – September 2025
#124Earlier quoted context omitted.
Isn't the subtext of this post pretty clearly that the unauthorized actor was Andre Arko, who had until days prior all the same access to RubyGems.org already? The impression I have reading this is that they're going out of their way to make it clear they believe it was him, but aren't naming him because doing so would be accusing him of a criminal act.
Let's say that they are 100% correct, we parse the subtext as text, it was totally him. We still do not know the critical details of how (and when) he stored the root password he copied out of their password manager (encrypted in his own password manager? on his pwned laptop? in dropbox? we'll never know!) therefore the whole chain of custody is still broken.
Re: Rubygems.org AWS Root Access Event – September 2025
#125Earlier quoted context omitted.
> Not even sure why you are being downvoted, this is such a great idea actually. Expressing negative opinions about DHH is not well-received here. Oddly enough the Ruby community includes both the most thoughtful and gentle people and the biggest assholes I know... I refuse to believe the latter are not fringe.
Yes I absolutely hate DHH as well and in fact I was using omarchy but then migrated over to cachyos hyprland https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug... DHH is not a good guy but the hype around him made me feel so. He's weird and racist and fascist. Stop the hype around dhh and everyone please read the article everybody here's DHH reality Let’s ditch the superlatives and review David’s post objec…
Do you legitimately believe DHH would say those are his beliefs?
Re: Rubygems.org AWS Root Access Event – September 2025
#126So is this a smear of Arko (and by extension Ruby Gems' sloppy security) but dressed up like a Security disclosure? If I'm reading it right, it seems quite petty (and a bit cowardly). Arko was a maintainer was he not? How is that a breach? Presumably his credentials were not misbegotten, or is that the accusation?
Re: Rubygems.org AWS Root Access Event – September 2025
#127Earlier quoted context omitted.
Yes I absolutely hate DHH as well and in fact I was using omarchy but then migrated over to cachyos hyprland https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug... DHH is not a good guy but the hype around him made me feel so. He's weird and racist and fascist. Stop the hype around dhh and everyone please read the article everybody here's DHH reality Let’s ditch the superlatives and review David’s post objec…
You’re taking the interpretation of the author of that article as the words that DHH said. Do you legitimately believe DHH would say those are his beliefs?
DHH mentions 39% or something which was the population of native white and not native british as an example...
Please read the article link and they have given a proper sound reasoning...
>Do you legitimately believe DHH would say those are his beliefs?
Yes, I mean, DHH wrote it in his own blog post. There is still an argument to be made that DHH is far right but even he knows that it is bad and somehow tries to normalize it...
DHH might not say that these are his beliefs but his words in his blogs logically point to this conclusion. Why do you think that DHH said those words in his blogpost if he doesn't believe in such similar far right ideologies? Nobody forced him to write a blog post but himself...
Why do you think such things are not what DHH believes in? Do you have any evidence as the author of the article provides for their reasoning/interpretation?
Re: Rubygems.org AWS Root Access Event – September 2025
#128Earlier quoted context omitted.
IMO the only way to avoid doing a total rebuild is to have Andre Arko: 1. Admit that he was the unauthorized actor (which means he's probably admitting to a crime?) 2. Have him attest he didn't exfil or modify the integrity of service while committing a crime. If I was Ruby Central I would give clemency on #1 in exchange for #2 and I think #2 helps Andre Arko.
If Andre doing that was criminal, it seems quite possible that their original takeover of the github organization was also criminal? I have been waiting to hear if there would be any civil action on it since it's not at all clear they had any rights to do most of what they did.
I don't think for a second Arko will be charged, but there isn't a "nuh-uh, you did this gross thing in our open source community" defense for 18 USC 1030.
Re: Rubygems.org AWS Root Access Event – September 2025
#129This is a pretty hilarious and long-winded way to say "we have no idea how to lock someone out of a web service:" > 1. While Ruby Central correctly removed access to shared credentials through its enterprise password manager prior to the incident, our staff did not consider the possibility that this credential may have been copied or exfiltrated to other password managers outside of Ruby Central’s visibility or contr…
It didn't occur to them that he might have written the password down? That's wild.
Re: Rubygems.org AWS Root Access Event – September 2025
#130> “Following these budget adjustments, Mr. Arko’s consultancy, (…), submitted a proposal offering to provide secondary on-call services at no cost in exchange for access to production HTTP access logs, containing IP addresses and other personally identifiable information (PII). The offer would have given Mr. Arko’s consultancy access to that data, so that they could monetize it by analyzing access patterns and potent…