At this point, it's probable that any attempt to just list the pertinent events isn't going to end up being as neutral as one might hope because even the choice of what context to include or exclude is itself editorial. This is the same lesson people might learn in a high school history class, just applied to something much more recent.
Perfect neutrality is unachievable but that doesn't mean that every possible way of presenting the facts is equally valid, or even that it's impossible to distinguish presentations that are or aren't missing important context (see, e.g., the surprising success of Twitter's Community Notes).
You’re likely aware, though it’s worth mentioning, that the new owners ousted all existing maintainers without any explanation[1]. This follows a prior incident where access was revoked and later restored, with assurances that it was a mistake. This situation can only be viewed as a malicious attack, in which only the new owners had a full understanding of what transpired. Changing the password was a reasonable and appropriate response that any competent person in a similar position would've considered.
I’m shocked that we seem to be experiencing a Freenode 2.0 situation, but with some supporting the usurpers instead of the longstanding maintainers. It’s only been four years since the Freenode debacle, yet certain types of people seem to have grown bolder since then. A "win" for freedom of expression, huh?
It’s telling that you can write multiple paragraphs claiming the moon is made of cheese while expecting others to communicate only in brief, misleading soundbites.
https://en.wikipedia.org/wiki/Loaded_question
Changing passwords was the responsible course of action to protect Ruby users in light of the attack. Maintainers should act in the interest of the Ruby community, not in favor of usurpers with a vendetta.
Here's what I think: people are starting from a sympathetic principle (independent community-minded maintainers are better that corporations) and working their way back to what they've decided must have happened. The person we're talking about here tried to (quietly!) monetize the server logs for RubyGems. Don't even try to play the "that's what RubyCentral says" card --- they published the email.
The world doesn't always line up with the most sympathetic principles.
Personally I also think the monetization proposal was silly, but that was in August and Ruby Central rejected it.
He logged into the root account because he thought he was on call and that someone was taking over Ruby Central, so he reacted in real time. With the obvious chaos and incompetence in Ruby Central and the ill defined takeover that does not seem far fetched.
What exactly would he have gained by openly changing the root account for malicious reasons? He knows he would have been found out. It is not even a hack.
Shopify stole RubyGems from the maintainers, do you deny it? They tried to do so in secret, keeping the maintainers and the larger Ruby community in the dark. Their claim that the access revocations were a mistake was a blatant lie. Moreover, they spun even more conspicuous falsehoods in response to the public backlash.
When you twist protective measures against ongoing theft or shitty proposals that went nowhere into a nefarious conspiracy to justify the theft of critical Ruby infrastructure, it’s time to take a hard look in the mirror.
And hey, since you imply that loaded questions aren't fallacious, tell me: have you stopped beating your wife? It's a "simple question," just answer yes or no.
These aren't insinuations; they're direct factual claims. They're well-founded and they're either true or they're not. No, you can't just jazz-hands your way through this.
When you twist protective measures against ongoing theft or shitty proposals that went nowhere into a nefarious conspiracy to justify the theft of critical Ruby infrastructure, it’s time to take a hard look in the mirror.
What are you trying to achieve here, bringing up debunked insinuations over and over and over again? And haha no, going over every cherry-picked fact and half-truth you explicitly stated doesn’t prove you aren’t making insinuations.
> insinuate: to impart or suggest in an artful or indirect way
https://www.merriam-webster.com/dictionary/insinuated
Note the word "indirect."
Now, are you using that to justify the hostile takeover of critical infrastructure to the entire Ruby community? I'm baffled. RC did a *hostile takeover*. How many times do I have to repeat this?
And why are you ignoring that RC did a hostile takeover of the repos? Again, RC stole the repos. What do you think of that?
I don't know what happened with "the repos", is why I haven't offered an opinion about it. I have a professional interest in stories about people gaining unauthorized access to accounts. I assure you, the law doesn't weigh one party's transgression against the other the way you suggest it should.
And you know what? I think you're right! What Andre did could constitute a crime. Any serious organization would lawyer up and go after him... right? RIGHT?
What sort of monetisation?
Asking because there's a huge potential range of options there, from pretty innocuous stuff through to downright evil. :(
To me that seems like a good idea, not like a betrayal of trust as some people have been making out.
The HN commentariat is really shocking me here, because everyone in the professional space that I talk to about this thinks this is obvious and takes the same position.
I won't follow the thought from there, but maybe you see where I'm going...
Unfortunately for him he basically admitted to a crime because it came after he was terminated. He tried appealing to community and whatnot but anyone who's ever worked for a corporation knows that once you're terminated, it doesn't matter if HR forgot to take away your credentials or not, you simply don't attempt to access anything ever again. Having keys to something doesn't make you the owner.
At the same time, why didn't RC call him to ask? Was it easier to write about a security INCIDENT throwing shade at Arko?
With that said, let's keep focused on the real issue: RC did a hostile takeover of the projects. That's not been properly disputed so far. Matz is, therefore, accepting to steward stolen projects.
> Matz is, therefore, accepting to steward stolen projects.
You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right?
One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.
https://andre.arko.net/2025/10/09/the-rubygems-security-inci...
"Please confirm that you cannot access the Ruby Central AWS root account credentials, either through the console or by access keys."
Alternatively, we could see the whole issue for what it is: a power struggle between political factions of an open source project that is unprofessionally handled by at least one side.
Arko already stated that he didn't know he had been fired. Geez.
> You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right?
The project was stolen from a set of maintainers, not just Arko. Let's stick to the facts: someone with admin rights over the repos revoked the access of other admins without their consent. What do you call this?
> One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.
How in the world is that relevant? I have a lot of respect for Rich, but he wasn't a maintainer.
LMAO
No. He's one of the few people on the planet that could lay claim to it's copyright. He also gave the insight that Rubygems has literally ALWAYS been a part of RubyCentral.
But if you do care about the repo, once again, RC has always controlled Rubygems. From the day it was written. The maintainers were even paid by RC. That makes it RC's, not the maintainers'.
> When they finally did reply, they seem to have developed some sort of theory that I was interested in “access to PII”, which is entirely false. I have no interest in any PII, commercially or otherwise. As my private email published by Ruby Central demonstrates, my entire proposal was based solely on company-level information, with no information about individuals included in any way. Here’s their response, over three days later.
https://andre.arko.net/2025/10/09/the-rubygems-security-inci...
I'm only going by the corporate narrative structure of the director's post, who clearly wants to throw someone under the bus and cover up organizational incompetence. "Open" source has become so despicable.
"As this situation occurred, I was the primary on-call. My contractual, paid responsibility to Ruby Central was to defend the RubyGems.org service against potential threats."