7 ms·
In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, th
by dluan 1y ago
In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.
- lyu07282 1y agoThis is just the tooling though, not "rubygems.org" which is still owned by a hostile entity (depending on where you sit on this), so not sure how this would restore any trust?
- rich_kilmer 1y agoAs a co-author of RubyGems and one of the original Board members of Ruby Central, they are not a hostile entity. They are the entity that we gave stewardship of RubyGems and we/they have hosted it for its entire existence.
- lyu07282 1y agoIt goes without saying that Ruby Central doesn't think Ruby Central has ever lost any trust to begin with.
- monooso 1y agoI don't have a dog in this fight, but the discussion is about the phrase "hostile entity", not about a loss of trust.
- lyu07282 1y agoThat really doesn't matter. I think what happened could be described as "hostility" towards the community, that's what my impression was, it was appearing like a hostile takeover of the github repositories/organization with no discussion, no community involvement, no transparency. Obviously not everybody will agree especially not people working at Ruby Central.
- deleted 1y ago[deleted]
- shevy-java 1y agoI disagree. The actions are orthogonal to your claim - they eliminated everyone else from there. How is that not hostile? Duckinator has been 100% right here. > we gave stewardship of RubyGems I didn't sign anything. I also remember the original creators of rubygems. How old is Ruby Central? 10 years? 15 years? There were several years before that.
- rich_kilmer 1y agoRuby Central started in 2001. I was one of the early Board members, along with Chad Fowler and David Alan Black. We put on every Ruby conference until Ruby became more popular to support multiple conferences. We started coding RubyGems (although the name originated in 2001 at the first RubyConf in Florida) in 2003 at the RubyConf in Austin TX. We sat around a table the first night with a CVS repo on a USB drive and passed it around and committed code until we had a functioning gem command. I demoed it in my talk the next day with the first "gem install". Gem versioning, gemspec, gem command, gem server were all built that first night. Obviously tons of changes since then!
- deleted 1y ago[deleted]
- dismalaf 1y agoHostile entity? The entity that has literally hosted them for their entire existence?
- kragen 1y agoApparently so. That shouldn't be a surprise; Amazon Web Services turned out to be hostile to WikiLeaks, CDDB's hosting turned out to be hostile to the community that built CDDB, coal mining company towns were hostile to miners' unions, and, in the final analysis, turkey farmers are hostile to the turkeys.
- florkbork 1y agoImagine if you opened up your laptop to discover Microsoft windows has locked you out of a your entire machine, because you were writing a novel in RTF and it could be opened in Microsoft Word. Microsoft's executives started posting they "took control of the your machine/the novel to maintain security". - Corporate entity doesn't have copyright over your creative output. Just because word can open and view ("run") your novel does not give them ownership. - Locking your access completely on your resources would be akin to a ransomware attack or account compromise Would you label those actions hostile? Or just accept it as right because "maintain security"? If you would label the above hypothetical actions as hostile (if not outrageous overreach, something akin to theft?); what is fundamentally different to what Ruby Central did by taking over the source code of a GitHub repository?
- dismalaf 1y agoThis is a bad analogy. André Arko was a contractor employed by Ruby Central. His employer terminated his contract. He continued to access their server which is literally a crime. The "maintainers" weren't volunteers. They were paid employees. Also none of the ones complaining were the original authors of gem nor bundler.
- florkbork 1y agoAlright, let's extend it. You work for Microsoft as an independent contractor, as a night watchman/groundskeeper. So do a number of others. You were hired because you and your crew of weirdos were writing the story of advanced gardening and building maintenace; which people including those at many famous and powerful companies used and found useful. A number of years ago someone said "huh, maybe these guys should get funding", and a few others agree; and Microsoft ends up in charge of distributing that funding. The above still happens. They have locked your computer with a ransomware message that says "we will give you back access if you get rid of one of you". To lock your computer, which is airgapped, it would require someone with admin privileges to your computer to walk in and manually do this. It turns out one of your has colleagues done this, added an account for the Director of Night Maintenance at Microsoft to your machine. You and almost all of the "paid employees", again, a number of whom are independent contractors, resign in protest; leaving only the person who tampered with your computer. https://bsky.app/profile/duckinator.bsky.social/post/3lz6exzgtcc2j https://bsky.app/profile/duckinator.bsky.social/post/3lz6exz... > The behavior Ruby Central exhibited was so egregious that I sincerely thought someone's account had been compromised at one point During this chaos; which all happened between September 9 and September 18; - at midday LA time/2:40pm New York time; Microsoft terminates the contract with one specific individual; who was the one they demanded the group gets rid of if they wanted access back - 8 hours later, that person locks the doors; changes nothing else, etc. Some basic analysis about the situation you need to do: - Did the actions on September 19th, even if you believe it was a crime of the most serious nature, justify the actions on Sept 9-18 where Microsoft took access, said whoopsie, then did it again? - Treating the Sept 19 actions as a crime; did the person who did it do so with a criminal intent? (Mens rea). Did they intend harm? Or were they indifferent to the harm caused? Should this be prosecuted, has that person provided justification or similar that could in any way be reasonable doubt? - If the actions on September 19 are a crime in your viewpoint; would paying/influencing someone to lock the accounts of all of the maintainers also be a crime? Why or why not? Note that you'll want to read https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030 First off, was anything involved a "protected computer"? No, probably not, not by the legal definition there; yes by what we as laypeople would assume. But, let's roll with the assumption it's "literally a crime" and not a civil matter; but apply that standard equally. > (4)knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer and the value of such use is not more than $5,000 in any 1-year period; * Is the draft novel/rubygems source code a thing of value? Yes. $5000 worth? Tricky to say with the open source licencing! But RC were distributing $ to maintain it; and that cost them more than $5000/year. Cost does not equal value; but I think we can argue yes, kinda here. > (7)with intent to extort from any person any money or other thing of value, transmits in interstate or foreign commerce any communication containing any— * Did anyone attempt to extort anyone else to remove a person? (Get rid of x if you want access back!) * Did that have value? (Gee, I hope the treasurer didn't post, it was about the funding deadlines/only to have that walked back!) Also a bit murky as the value isn't coming from the extortion directly, only indirectly. > (b)Whoever conspires to commit or attempts to commit an offense under subsection (a) of this section shall be punished as provided in subsection (c) of this section. * Did anyone conspire? (Two or more people agree to criminal act, followed by an overt act) Can you plausibly see how if you try to apply US law to argue one individual on one side is a criminal; that same law would likely make the other side just as criminal; if not more so? --- > none of the ones complaining were the original authors of gem nor bundler. Doesn't hold water. From the individual: https://andre.arko.net/2025/09/25/bundler-belongs-to-the-ruby-community/ https://andre.arko.net/2025/09/25/bundler-belongs-to-the-rub... "I joined the team at a pivotal moment, in February 2010, as the 0.9 prototype was starting to be re-written yet another time into the shape that would finally be released as 1.0. By the time Carl, Yehuda, and I released version 1.0 together in August 2010, we had fully established the structure and commands that Bundler 2.7.2 still uses today." IE: Claims to be a significant contributor, predating any "stewardship" by RubyCentral. I would argue this can be born out by contributions and the fact he proposed the darned merger with RC in the first place; and that merger assigns no intellectual property rights or similar.
- neya 1y agoAny summary of what exaclty unfolded please (if you don't mind)? Sorry haven't been following the Ruby news for sometime.
- shadowgovt 1y agoThe broad-strokes story is: * DHH said some things on his blog that some people believe to be deeply racist / fascist (not going to unpack whether they were or not because answering that question is irrelevant to the fact pattern; consult other threads for that debate). * A Ruby conference run by Ruby Central was asked to deplatform him. Since he's the creator of Rails, they declined. * In response to their decision, a major sponsor (Sidekiq) pulled out of supporting the conference and Ruby Central in general, to the tune of $250k a year. * This created a "blood in the water" situation where Shopify hit Ruby Central with an ultimatum: they would back-fill the lost sponsorship for oversight control of Ruby Central (and the gem repository they maintain, rubygems.org). And if Ruby Central didn't take the deal, Shopify was going to pull their funding also, leaving them in dire straits (this, BTW, is a fairly common corporate tactic when multiple partners share support of a service that doesn't independently generate revenue. Look for it in your own business, startup company, and nonprofit dealings!). * Shopify now de-facto controls rubygems.org and people immediately started backing towards the exits because corporate takeover tends to be a harbinger of enshittification. As if to prove the point, Shopify's folks immediately ham-fisted the access controls, yanking several gem creators from the admin roles of the gems they created. They claim this was a mistake; several in the community do not want to give them a benefit of the doubt they are not believed to have earned. * Community members are standing up gem.coop as an alternative gem repository.
- neya 1y agoThanks, that was a superb summary! Appreciate it.
- ameliaquining 1y agoThis is missing an important part of the story that makes the Ruby Central side look relatively better, which is that one of the existing maintainers offered to help fill the funding gap in exchange for being allowed to monetize the server logs. https://rubycentral.org/news/rubygems-org-aws-root-access-event-september-2025/#why-did-ruby-central-treat-this-event-as-a-security-incident https://rubycentral.org/news/rubygems-org-aws-root-access-ev...
- shevy-java 1y agoAgreed. I think we have to wait and see how much momentum gem.coop can build. Right now they have promised "things for the future"; they will most likely also deliver eventually. But right now they are not there. If and when they open beta, though, I'll begin to republish my old gems (not all, some I merged into other gems but most of the core stuff will be back) there. They have some things they should improve on though - documentation (also a problem that ruby doc was separate by the way), namespacing (this is in part also a problem that ruby had no primary way of namespacing; this is also a feature, but it should have a way to separate concerns when possible or wanted). Anyway, I think we'll soon see what happens - I say people should evaluate again in about half a year or so, say like ... end of May 2026. I think this would be a more realistic time frame. I do, however had, also suspect that DHH may become the biggest asset to gem.coop - every further snide remark he does on his blog, will gain new people who are upset, and some of those will eventually help contribute and benefit gem.coop. So for the end user this may be a win-win situation since they can install things how they like it, thus having more flexibility. Many can and will stay with rubygems.org, others may prefer gem.coop, many others will probably use and combine both (this may be a bit more difficult; guess gem.coop needs to think of a way to specify different gem sources on a per-gem basis too. Lots of work to be had for certain).
- busterarm 1y agoEven if you're not an old-timer and don't remember what Ruby Together was like, the AWS root password changing shenanigans, presumably done by Arko, is enough of a red flag that nothing he's associated with has any credibility. No serious business with real (business) customers will accept that kind of risk and gem.coop will never be a thing outside of hobbyists.
- dluan 1y agoRead his account of it (https://andre.arko.net/2025/10/09/the-rubygems-security-incident/ https://andre.arko.net/2025/10/09/the-rubygems-security-inci...) and you might change your mind (again).
- 1y ago
- charcircuit 1y ago>multiple sources is safer It tripples the attack surface making it more vulernable to having security vulnerabilities.
- downrightmike 1y agoI can't believe that long gone maintainers still had root access, or any access at all to the core platform. Its has been wild to see ruby community members getting upset with modern and established security norms, for a platform that runs a lot of the web. Its not 2006 anymore, and we aren't just running random curl commands off the net to get rails installed. Scary to think how naive the backlash has been. Having an unmaintained security posture that is inherently insecure, just blows my mind. That supply chain was wide open to attacks, may still be, but at least someone tried to bring security up to this decade.
- sussmannbaka 1y agoTrying and doing aren’t the same thing. I’ll take competent community members over incompetent leadership any day of the week. And I am right to think so, seeing how they entirely bungled even kicking out the people they wanted kicked out. They literally had their first security incident at second zero of their attempt to “bring security up to this decade”.
- pabs3 1y ago> having multiple sources like gem.coop is probably a safer and more robust solution I prefer the Go solution where the package manager uses the git repos instead of a separate package index that might or might not correspond to the git repos.