TL;DR: make sure you're not using strong_password 0.0.7 This is a great story and debug. Yay for developers checking changes in upgraded gems! https://withatwist.dev/strong-password-rubygem-hijacked.html