Live data from Hacker News

Rubygems.org AWS Root Access Event – September 2025

rubycentral.org

1–10 of 179 posts

Re: Rubygems.org AWS Root Access Event – September 2025

#4
They buried the lede...

Arko wanted a copy of the HTTP Access logs from rubygems.org so his consultancy could monetize the data, after RC determined they didn't really have the budget for secondary on-call.

Then after they removed him as a maintainer he logged in and changed the AWS root password.

Re: Rubygems.org AWS Root Access Event – September 2025

#6
In 2025 there's no reason for anyone to be logging into an AWS account via the root credentials and this should have been addressed in the preventative measures.

There's no actual control improvements here, just "we'll follow our procedures better next time" which imo is effectively doing nothing.

Also this is really lacking in detail about how it was determined that no PII was accessed. What audit logs were checked? Where was this data stored?

Overall this is a super disappointing postmortem...

Re: Rubygems.org AWS Root Access Event – September 2025

#7
"The root account credentials, essentially the highest level of administrative control, are stored in a shared enterprise password manager in a shared vault to which only three individuals had access: two current Ruby Central staff members and one former maintainer, André Arko"

I am wondering. Did they at least have MFA enabled on the root login or not ?

Re: Rubygems.org AWS Root Access Event – September 2025

#8
post #7

"The root account credentials, essentially the highest level of administrative control, are stored in a shared enterprise password manager in a shared vault to which only three individuals had access: two current Ruby Central staff members and one former maintainer, André Arko" I am wondering. Did they at least have MFA enabled on the root login or not ?

Yes because they state under the section "Root Cause Analysis"

> Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the departure of personnel with access to the shared vault.

Re: Rubygems.org AWS Root Access Event – September 2025

#9
post #4

They buried the lede... Arko wanted a copy of the HTTP Access logs from rubygems.org so his consultancy could monetize the data, after RC determined they didn't really have the budget for secondary on-call. Then after they removed him as a maintainer he logged in and changed the AWS root password.

[deleted]
Post reply on HN