I'd recommend to people to wait for a response - RubyCentral spins up a gazillion accusations right now and has been in the last days (and, it is also incomplete, because why did they fire every dev here and placed Marty Haught in charge specifically? They never were able to logically explain this; plus, why didn't they release this write-up before? It feels very strange to wait here; they could have clarified things…
Rubygems.org AWS Root Access Event – September 2025
91–100 of 179 posts
Re: Rubygems.org AWS Root Access Event – September 2025
#92WTF. This is the same guy that is launched gems.coop, a competing index for Ruby gems recently.
On the other hand, RubyCentral actions were truly incompetent, I don’t know anymore who is worse
Re: Rubygems.org AWS Root Access Event – September 2025
#93They buried the lede... Arko wanted a copy of the HTTP Access logs from rubygems.org so his consultancy could monetize the data, after RC determined they didn't really have the budget for secondary on-call. Then after they removed him as a maintainer he logged in and changed the AWS root password.
In a certain sense this post justifies why RC wanted so badly to take ownership - I mean, here you have a maintainer who clearly has a desire to sell user data to make a buck - but the way it all played out with terrible communication and rookie mistakes on revoking access undermines faith in RC's ability to secure the service going forward.
Not to mention no explanation here of who legally "owned" the rubygems repo (not just the infra) and why they thought they had the right to claim it, which is something disputed by the "other" side.
Just a mess all around, nobody comes off looking very good here!
Re: Rubygems.org AWS Root Access Event – September 2025
#94Ethical and legal boundaries? RubyGems Privacy Notice already tells you that they share information with a number of large firms and notably ClickHouse... for "Customer Data Processing." All this proposal does is request from one of the maintainers/on-call providers? another entry in this Privacy Notice as a part of a payment deal. This is a mess, but it also unnecessary smears both sides. It calls out that RubyCentr…
[flagged]
Re: Rubygems.org AWS Root Access Event – September 2025
#95Any part of this narrative could be false, but I don't see a way to read it and take it as true where Arko's actions would be OK.
Re: Rubygems.org AWS Root Access Event – September 2025
#96I'd recommend to people to wait for a response - RubyCentral spins up a gazillion accusations right now and has been in the last days (and, it is also incomplete, because why did they fire every dev here and placed Marty Haught in charge specifically? They never were able to logically explain this; plus, why didn't they release this write-up before? It feels very strange to wait here; they could have clarified things…
> let those accused respond. Literally all we've heard so far is from the other side... > If they have factual evidence, they need to bring the matter to a court I'd be surprised if they aren't. This post feels very much like the amount of disclosure a lawyer would recommend to reassure stakeholders. > rules of engagement that doesn't put rich corporations atop the whole ecosystem Right now the only thing stopping us…
Re: Rubygems.org AWS Root Access Event – September 2025
#97Ethical and legal boundaries? RubyGems Privacy Notice already tells you that they share information with a number of large firms and notably ClickHouse... for "Customer Data Processing." All this proposal does is request from one of the maintainers/on-call providers? another entry in this Privacy Notice as a part of a payment deal. This is a mess, but it also unnecessary smears both sides. It calls out that RubyCentr…
[flagged]
Set that aside, which obviously stinks, but then why is said obviously incompetent organization sharing confidential corporate emails with the public, saying this guy proposing a corporate data access plan in exchange for consulting fees is crossing "ethical and legal boundaries?"
Are you serious? This reeks of someone or a number of people who have no idea what they're doing. Have these people never worked with a business before? Never spoken with a software firm? A marketing firm? Any consultancy whatsoever?
Who owns the registry? What is going on here? This is insane.
It makes the entire Ruby ecosystem look like it's run by children.
Re: Rubygems.org AWS Root Access Event – September 2025
#98AWS account root access on a language package registry for 11 days. Not EC2 root - AWS account root. Complete control over IAM, S3, CloudTrail, every-damn-thing. They're claiming "no evidence of compromise" based on CloudTrail logs that AWS root could have deleted or modified. They even admit they "Enabled AWS CloudTrail" after regaining control - meaning CloudTrail wasn't running during the compromise window. You ca…
The impression I have reading this is that they're going out of their way to make it clear they believe it was him, but aren't naming him because doing so would be accusing him of a criminal act.
Re: Rubygems.org AWS Root Access Event – September 2025
#99Earlier quoted context omitted.
The problem, as with every package manager, is transitive dependencies. It's all well and good to set up direct dependencies to only pull from git repositories, but bundler still needs a way to resolve those gems' dependencies. You could pre-resolve every dependency in your chain to a git repository, even to a fork under your own control, but that will end up being a maintenance nightmare.
Can't a middle compromise happen as it happens in something like golang? Can some vps/serverless provider not do this like fly.io as an recent example with kurt got got? or hetzner? I think that golang's model can actually be sort of cheaper/ more cost effective for servers as compared to how ruby might be doing it right now and so cheaper might mean that a new non profit can be created which can work on less money/o…
It also means no code signing and the natural capture of most of the ecosystem by Microsoft (due to devs preferring to host their code on github, a bundler that lacks package hosting will be entirely at the whim of MS)
Re: Rubygems.org AWS Root Access Event – September 2025
#100That email screenshot is pretty bad for Arko. It clearly shows intent to sell PII data to a third party during a time when Ruby Central had diminished funds and needed help affording basic services. What the fuck.
Why do they need money? What happened to their funding?