(no title)
jnewland | 4 months ago
> 1. While Ruby Central correctly removed access to shared credentials through its enterprise password manager prior to the incident, our staff did not consider the possibility that this credential may have been copied or exfiltrated to other password managers outside of Ruby Central’s visibility or control.
> 2. Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the departure of personnel with access to the shared vault.
TehCorwiz|4 months ago
colonwqbang|4 months ago
jeffwask|4 months ago
TehCorwiz|4 months ago
baobun|4 months ago
Something they also failed to consider, reading between the lines.