Live data from Hacker News

Ruby core team takes ownership of RubyGems and Bundler

ruby-lang.org

331–340 of 407 posts

Re: Ruby core team takes ownership of RubyGems and Bundler

#331
post #18

Earlier quoted context omitted.

[flagged]

I don't like talking about a heterogeneous group of people in a generally negative way. I try to stick to the people I perceive as sharing the same values that are important to me. And there are many such people in the Ruby community.

[deleted]

Re: Ruby core team takes ownership of RubyGems and Bundler

#332
post #18

Earlier quoted context omitted.

[flagged]

I don't like talking about a heterogeneous group of people in a generally negative way. I try to stick to the people I perceive as sharing the same values that are important to me. And there are many such people in the Ruby community.

> I don't like talking about a heterogeneous group of people

> many such people in the Ruby community.

In which case, this presumes that the values you share with the Ruby community are positive - otherwise you would be talking about this heterogeneous group in a generally negative way.

This would appear to beg the very question under contention - that the values of the Ruby community are not in fact positive, but toxic; unless you wish to argue that a community can simultaneously profess positive values and still exhibit toxic behaviour.

One position offers historical (and current) examples; the other offers an impressive feat of linguistic gymnastics.

Re: Ruby core team takes ownership of RubyGems and Bundler

#333
post #144

Earlier quoted context omitted.

Your addition also misses an important part where the only reason he was able to do that was because the servers were forcibly taken from the previous owners for the ostensible purpose of security, but the new regime forgot to change the passwords as part of that. At this point, it's probable that any attempt to just list the pertinent events isn't going to end up being as neutral as one might hope because even the c…

Wait, you think the former maintainer breaking into Ruby Central's AWS account and changing its root password makes the former maintainers look better ?

[deleted]

Re: Ruby core team takes ownership of RubyGems and Bundler

#334
post #11

In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.

I can't believe that long gone maintainers still had root access, or any access at all to the core platform. Its has been wild to see ruby community members getting upset with modern and established security norms, for a platform that runs a lot of the web. Its not 2006 anymore, and we aren't just running random curl commands off the net to get rails installed. Scary to think how naive the backlash has been. Having a…

Trying and doing aren’t the same thing. I’ll take competent community members over incompetent leadership any day of the week. And I am right to think so, seeing how they entirely bungled even kicking out the people they wanted kicked out. They literally had their first security incident at second zero of their attempt to “bring security up to this decade”.

Re: Ruby core team takes ownership of RubyGems and Bundler

#335

Earlier quoted context omitted.

I don't think that's fair, I mostly thought that until I read his recent blog post[0] where he wished for fewer non-white people in London and praises a far-right fascist figure in England (Tommy Robinson, he was a member of the BNP[1] for while before he started the EDL which was more extreme). When you're advocating for ethno-nationalism and praising fascists, I don't think you can get mad at people thinking maybe…

I read it and I don't see it. He praised one policy from Tommy Robinson. This doesn't mean he support every single action performed by Tommy Robinson for eternity. He advocates for stricter immigration laws and is against mass immigration. He then praises the stricter immigration laws in Denmark. Then, Denmark would be considered facist and ethno-nationalistic by your logic? > I don't think you can get mad at people…

I disagree, wanting stricter immigration is not fascist, and isn't the problem I have with the article.

He argues that non-White people aren't British[0], that's the bit where it gets a bit fascist for me.

There's a debate to be had about immigration, that I think is valid. I think there's nothing wrong with advocating to reduce immigration. I think saying non-White people (who were born here, just so we can get away from the immigration side of things) aren't British is a dick move and kinda fascist.

[0] https://news.ycombinator.com/item?id=45358344

Re: Ruby core team takes ownership of RubyGems and Bundler

#336

These projects were not Ruby Central’s in the first place. They were stolen for Ruby Central by a Ruby Core insider, HSBT. This is horrible news. They were stolen from André Arko, Colby Swandale, David Rodríguez, Ellen, Josef Šimánek, Martin Emde and Samuel Giddins.

They did not WRITE RubyGems, they inherited it and evolved it. Chad, David, Jim (RIP), Paul and I wrote RubyGems. I hosted RubyGems from my home in Virginia for several years before we could cover the cost of colocation and stood up RubyForge. Its nice to look at the near history and think that this is all of history but it is not. Ruby Central has always been the stewards of RubyGems and then later, Bundler.

I’m not talking about who wrote the code. Hundreds of people wrote the code, that’s not particularly relevant. I’m talking about who had maintainership of the code and how those maintainers had agreed to govern the project.

What was your maintainership status when this all kicked off? Were you one of the owners removed by HSBT?

Re: Ruby core team takes ownership of RubyGems and Bundler

#337

Earlier quoted context omitted.

The term you're looking for is a loaded question . https://en.wikipedia.org/wiki/Loaded_question Changing passwords was the responsible course of action to protect Ruby users in light of the attack. Maintainers should act in the interest of the Ruby community, not in favor of usurpers with a vendetta.

I love that you had to link to the Wikipedia question for "loaded question" for this. So you're saying, the answer is "yes": he logged into the root account, after he lost access to his own account, and changed the root password. OK then! Here's what I think: people are starting from a sympathetic principle (independent community-minded maintainers are better that corporations) and working their way back to what they…

Everyone seems to gloss over it lol

Re: Ruby core team takes ownership of RubyGems and Bundler

#338

Earlier quoted context omitted.

that's the one thing I've heard them not address yet is the changing of the passwords.

Arko kind of did address it in his most recent blog post. He claims he was doing what was in Ruby Central's best interest. Unfortunately for him he basically admitted to a crime because it came after he was terminated. He tried appealing to community and whatnot but anyone who's ever worked for a corporation knows that once you're terminated, it doesn't matter if HR forgot to take away your credentials or not, you si…

How would it protect anyone?

Re: Ruby core team takes ownership of RubyGems and Bundler

#339
post #332
post #18

Earlier quoted context omitted.

I don't like talking about a heterogeneous group of people in a generally negative way. I try to stick to the people I perceive as sharing the same values that are important to me. And there are many such people in the Ruby community.

> I don't like talking about a heterogeneous group of people > many such people in the Ruby community. In which case, this presumes that the values you share with the Ruby community are positive - otherwise you would be talking about this heterogeneous group in a generally negative way. This would appear to beg the very question under contention - that the values of the Ruby community are not in fact positive, but to…

[deleted]

Re: Ruby core team takes ownership of RubyGems and Bundler

#340

Earlier quoted context omitted.

I read it and I don't see it. He praised one policy from Tommy Robinson. This doesn't mean he support every single action performed by Tommy Robinson for eternity. He advocates for stricter immigration laws and is against mass immigration. He then praises the stricter immigration laws in Denmark. Then, Denmark would be considered facist and ethno-nationalistic by your logic? > I don't think you can get mad at people…

I disagree, wanting stricter immigration is not fascist, and isn't the problem I have with the article. He argues that non-White people aren't British[0], that's the bit where it gets a bit fascist for me. There's a debate to be had about immigration, that I think is valid. I think there's nothing wrong with advocating to reduce immigration. I think saying non-White people (who were born here, just so we can get away…

I also find it really frustrating:

> I'm actually mad that the word fascist is losing its meaning.

When someone espouses ethno-nationalist viewpoints (a core part of fascism), and praises a fascist, I don't think it's unreasonable to say "hey that guy sounds a bit fascist", and I think pushing back against that is what is making fascism lose its meaning.

Now, saying "I don't think it's fascist because X" is perfectly valid, but that's not what I'm seeing here. It feels like a knee-jerk reaction, which I don't think is fair in this case.

Post reply on HN