Ruby core team takes ownership of RubyGems and Bundler
321–330 of 407 posts
Re: Ruby core team takes ownership of RubyGems and Bundler
#322Earlier quoted context omitted.
Imagine if you opened up your laptop to discover Microsoft windows has locked you out of a your entire machine, because you were writing a novel in RTF and it could be opened in Microsoft Word. Microsoft's executives started posting they "took control of the your machine/the novel to maintain security". - Corporate entity doesn't have copyright over your creative output. Just because word can open and view ("run") yo…
This is a bad analogy. André Arko was a contractor employed by Ruby Central. His employer terminated his contract. He continued to access their server which is literally a crime. The "maintainers" weren't volunteers. They were paid employees. Also none of the ones complaining were the original authors of gem nor bundler.
You work for Microsoft as an independent contractor, as a night watchman/groundskeeper. So do a number of others. You were hired because you and your crew of weirdos were writing the story of advanced gardening and building maintenace; which people including those at many famous and powerful companies used and found useful. A number of years ago someone said "huh, maybe these guys should get funding", and a few others agree; and Microsoft ends up in charge of distributing that funding.
The above still happens. They have locked your computer with a ransomware message that says "we will give you back access if you get rid of one of you". To lock your computer, which is airgapped, it would require someone with admin privileges to your computer to walk in and manually do this. It turns out one of your has colleagues done this, added an account for the Director of Night Maintenance at Microsoft to your machine.
You and almost all of the "paid employees", again, a number of whom are independent contractors, resign in protest; leaving only the person who tampered with your computer.
https://bsky.app/profile/duckinator.bsky.social/post/3lz6exz...
> The behavior Ruby Central exhibited was so egregious that I sincerely thought someone's account had been compromised at one point
During this chaos; which all happened between September 9 and September 18;
- at midday LA time/2:40pm New York time; Microsoft terminates the contract with one specific individual; who was the one they demanded the group gets rid of if they wanted access back - 8 hours later, that person locks the doors; changes nothing else, etc.
Some basic analysis about the situation you need to do:
- Did the actions on September 19th, even if you believe it was a crime of the most serious nature, justify the actions on Sept 9-18 where Microsoft took access, said whoopsie, then did it again?
- Treating the Sept 19 actions as a crime; did the person who did it do so with a criminal intent? (Mens rea). Did they intend harm? Or were they indifferent to the harm caused? Should this be prosecuted, has that person provided justification or similar that could in any way be reasonable doubt?
- If the actions on September 19 are a crime in your viewpoint; would paying/influencing someone to lock the accounts of all of the maintainers also be a crime? Why or why not?
Note that you'll want to read https://www.law.cornell.edu/uscode/text/18/1030
First off, was anything involved a "protected computer"? No, probably not, not by the legal definition there; yes by what we as laypeople would assume.
But, let's roll with the assumption it's "literally a crime" and not a civil matter; but apply that standard equally.
> (4)knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer and the value of such use is not more than $5,000 in any 1-year period;
* Is the draft novel/rubygems source code a thing of value? Yes. $5000 worth? Tricky to say with the open source licencing! But RC were distributing $ to maintain it; and that cost them more than $5000/year. Cost does not equal value; but I think we can argue yes, kinda here.
> (7)with intent to extort from any person any money or other thing of value, transmits in interstate or foreign commerce any communication containing any—
* Did anyone attempt to extort anyone else to remove a person? (Get rid of x if you want access back!) * Did that have value? (Gee, I hope the treasurer didn't post, it was about the funding deadlines/only to have that walked back!) Also a bit murky as the value isn't coming from the extortion directly, only indirectly.
> (b)Whoever conspires to commit or attempts to commit an offense under subsection (a) of this section shall be punished as provided in subsection (c) of this section.
* Did anyone conspire? (Two or more people agree to criminal act, followed by an overt act)
Can you plausibly see how if you try to apply US law to argue one individual on one side is a criminal; that same law would likely make the other side just as criminal; if not more so?
---
> none of the ones complaining were the original authors of gem nor bundler.
Doesn't hold water.
From the individual: https://andre.arko.net/2025/09/25/bundler-belongs-to-the-rub...
"I joined the team at a pivotal moment, in February 2010, as the 0.9 prototype was starting to be re-written yet another time into the shape that would finally be released as 1.0. By the time Carl, Yehuda, and I released version 1.0 together in August 2010, we had fully established the structure and commands that Bundler 2.7.2 still uses today."
IE: Claims to be a significant contributor, predating any "stewardship" by RubyCentral. I would argue this can be born out by contributions and the fact he proposed the darned merger with RC in the first place; and that merger assigns no intellectual property rights or similar.
Re: Ruby core team takes ownership of RubyGems and Bundler
#323Earlier quoted context omitted.
> So this whole thing stems from a dislike of DHH? Not really. Shopify threatened to pull funding for them which set the whole thing in motion
Which only had weight because Sidekiq pulled funding because Ruby Central wouldn't deplatform DHH.
Re: Ruby core team takes ownership of RubyGems and Bundler
#324Earlier quoted context omitted.
That's the narrative from the new Ruby Central, which feels like a wild distortion of the actual situation. You’re likely aware, though it’s worth mentioning, that the new owners ousted all existing maintainers without any explanation[1]. This follows a prior incident where access was revoked and later restored, with assurances that it was a mistake. This situation can only be viewed as a malicious attack, in which o…
Did he or did he not log in to the AWS root account after losing his own credentials and change the root password? I don't need paragraphs of explication following that. Seems simple!
It’s telling that you can write multiple paragraphs claiming the moon is made of cheese while expecting others to communicate only in brief, misleading soundbites.
Re: Ruby core team takes ownership of RubyGems and Bundler
#325Earlier quoted context omitted.
Did he or did he not log in to the AWS root account after losing his own credentials and change the root password? I don't need paragraphs of explication following that. Seems simple!
You take issue with me using 148 words in my comment? Just 8 hours before you wrote that, you spent more words than I did downplaying problems with AI powered mass surveillance cameras. Are rules something you live by or something that you arbitrarily impose on others? It’s telling that you can write multiple paragraphs claiming the moon is made of cheese while expecting others to communicate only in brief, misleadin…
Re: Ruby core team takes ownership of RubyGems and Bundler
#326As an outsider, I have two questions: - why is Shopify kind of hated in the comments? - what is it DHH said? Hoping for some context
Oh no, looks like you're one of today's (unlucky) 10000[0]. (For context I only heard about all this recently). For the DHH thing he wrote a recent blog post where he said he wants fewer non-white people in London and praises an english far-right fascist figure (Tommy Robinson)[1]. Not really sure about the Shopify stuff. I've heard people aren't too fond of Tobi (the C.E.O. I think), and he's buddies with DHH, but i…
No, it turns out DHH really wrote a blog post complaining not enough people in London are white (even though they’re British) and praising a famous British fascist.
The rest is very much still confusing, some kind of opportunistic power plays and typical open source chaos.
Re: Ruby core team takes ownership of RubyGems and Bundler
#327Earlier quoted context omitted.
You take issue with me using 148 words in my comment? Just 8 hours before you wrote that, you spent more words than I did downplaying problems with AI powered mass surveillance cameras. Are rules something you live by or something that you arbitrarily impose on others? It’s telling that you can write multiple paragraphs claiming the moon is made of cheese while expecting others to communicate only in brief, misleadin…
It's a yes or no question.
https://en.wikipedia.org/wiki/Loaded_question
Changing passwords was the responsible course of action to protect Ruby users in light of the attack. Maintainers should act in the interest of the Ruby community, not in favor of usurpers with a vendetta.
Re: Ruby core team takes ownership of RubyGems and Bundler
#328In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.
I prefer the Go solution where the package manager uses the git repos instead of a separate package index that might or might not correspond to the git repos.
Re: Ruby core team takes ownership of RubyGems and Bundler
#329Decentralized package hosting is the only way.
The key question here is how exactly the supply chain attacks will be prevented. If you consider release of new version of a library some sort of transaction, it's easy to see then the difference with cryptocurrencies: in crypto transaction can be automatically verified, but with software releases it is impossible. It is hard to imagine hundreds of hostings on the same very high trust level, so either risks become si…
Re: Ruby core team takes ownership of RubyGems and Bundler
#330Earlier quoted context omitted.
It's a yes or no question.
The term you're looking for is a loaded question . https://en.wikipedia.org/wiki/Loaded_question Changing passwords was the responsible course of action to protect Ruby users in light of the attack. Maintainers should act in the interest of the Ruby community, not in favor of usurpers with a vendetta.
Here's what I think: people are starting from a sympathetic principle (independent community-minded maintainers are better that corporations) and working their way back to what they've decided must have happened. The person we're talking about here tried to (quietly!) monetize the server logs for RubyGems. Don't even try to play the "that's what RubyCentral says" card --- they published the email.
The world doesn't always line up with the most sympathetic principles.