I don't think the RubyGems people were incompetent. The software serves its core purpose quite well (as a library delivery mechanism) and is quite reliable. But clearly they weren't thinking about security in decision, and what would happen if the repos were compromised.
Let's be honest here - no software is 100% secure. As developers and consumers, the idea that we all review all of the tools in our toolchain for security soundness is absurd. It's like saying that everyone using C made poor decisions because of security flaws in popular libraries (even security ones, like openssl) and therefore all of the C community has no engineering competence.
The fact is, China already has their eyes on GitHub and it's not beyond the planning capability to place backdoors in popular software to suit their future ends.
No matter who the attacker may be, you have to be prepared for the situation where your computers and data are compromised, period.