top | item 45535310

(no title)

ebcase | 4 months ago

> I'd recommend to people to wait for a response

https://andre.arko.net/2025/10/09/the-rubygems-security-inci...

discuss

order

frenchtoast8|4 months ago

This makes Ruby Central look even worse. TFA is only concerned with the root user, and the timeline ends at September 30, but Arko was able to confirm as late as October 5 that he had access to _other_ accounts with production access. Ruby Central doesn't seem interested in the article to mention that even after being notified about unauthorized access they still hadn't rotated all relevant credentials almost a week later.

ilikepi|4 months ago

Welp, now that there is confirmation that lawyers are involved, the chances there will be any of sort of open and transparent reconciliation process have plummeted.