Rubygems.org AWS Root Access Event – September 2025
rubycentral.org
Rubygems.org AWS Root Access Event – September 2025
1–10 of 179 posts
Re: Rubygems.org AWS Root Access Event – September 2025
#2Re: Rubygems.org AWS Root Access Event – September 2025
#3What the fuck.
Re: Rubygems.org AWS Root Access Event – September 2025
#4Arko wanted a copy of the HTTP Access logs from rubygems.org so his consultancy could monetize the data, after RC determined they didn't really have the budget for secondary on-call.
Then after they removed him as a maintainer he logged in and changed the AWS root password.
Re: Rubygems.org AWS Root Access Event – September 2025
#5The Rubygems take over drama continues!
Re: Rubygems.org AWS Root Access Event – September 2025
#6There's no actual control improvements here, just "we'll follow our procedures better next time" which imo is effectively doing nothing.
Also this is really lacking in detail about how it was determined that no PII was accessed. What audit logs were checked? Where was this data stored?
Overall this is a super disappointing postmortem...
Re: Rubygems.org AWS Root Access Event – September 2025
#7I am wondering. Did they at least have MFA enabled on the root login or not ?
Re: Rubygems.org AWS Root Access Event – September 2025
#8"The root account credentials, essentially the highest level of administrative control, are stored in a shared enterprise password manager in a shared vault to which only three individuals had access: two current Ruby Central staff members and one former maintainer, André Arko" I am wondering. Did they at least have MFA enabled on the root login or not ?
> Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the departure of personnel with access to the shared vault.
Re: Rubygems.org AWS Root Access Event – September 2025
#9They buried the lede... Arko wanted a copy of the HTTP Access logs from rubygems.org so his consultancy could monetize the data, after RC determined they didn't really have the budget for secondary on-call. Then after they removed him as a maintainer he logged in and changed the AWS root password.