Hacker News new | past | comments | ask | show | jobs | submit | bdmac97's comments login

Hi all. I'm the (actual) owner of that gem.

As already hypothesized in the comments I'm pretty sure this was a simple account hijack. The kickball user likely cracked an old password of mine from before I was using 1password that was leaked from who knows which of the various breaches that have occurred over the years.

I released that gem years ago and barely remembered even having a rubygems account since I'm not doing much OSS work these days. I simply forgot to rotate out that old password there as a result which is definitely my bad.

Since being notified and regaining ownership of the gem I've:

1. Removed the kickball gem owner. I don't know why rubygems did not do this automatically but they did not.

2. Reset to a new strong password specific to rubygems.org (haha) with 1password and secured my account with MFA.

3. Released a new version 0.0.8 of the gem so that anyone that unfortunately installed the bogus/yanked 0.0.7 version will hopefully update to the new/real version of the gem.


one more reason why to use a password manager and have a unique password.

Thanks for sharing the info!


Sorry I meant to lump that in under the soft skills section. It was not meant to be an exhaustive list, there would be far more than 5 items :-)


There could have certainly been some of that but it didn't feel like it in the context (which I realize I didn't provide). I read the question as sincere but admit there's a chance it wasn't.

At any rate, I tried to answer him honestly with what I'd have told myself and it didn't have any bearing on the outcome one way or another.


Apologies in advance for the length (8 minutes). I've tried to whittle it down but it's a year of anguish for me. :-)


IMO, and as you mentioned, your best bet in those early days is to rely on your network and have that insanely compelling vision with which to sell them on. I think you need a certain level of trust with people for them to be willing to bet a significant chunk of their time and such an inordinate amount of energy on your vision. Conversely no matter how much the person may love you, if your vision for the company is a giant pile of "meh" then you won't (and shouldn't) have much luck convincing them either.

The two go hand in hand for your first few hires.


Absolutely agree with these points!


I got burned by this on Heroku recently as well but to a much lesser extent $$$-wise. My app typically runs on 1 dyno because it's basically not supported anymore. At some point I must have been messing around in the interface and accidently bumped my dynos. Oops.

I personally think they should have a "WTF your load is like zero, you normally have X dynos, but you're using Y dynos for no real reason... dumbass" alert email... I certainly would have appreciated it!


I'm getting the same thing. Tried redownloading/reinstalling and no love. Had to 'killall Cloud' to even get the thing out of my menubar...


And yet every other device they make (basically) has one...


No GPS???


According to the specs page (http://www.apple.com/ipad/specs/) there is A-GPS, but only on the 3G model.


They are probably holding back features for next generations of iPad... launched in a year or so after the first one (it could have a camera also)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: