Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
58 Beiträge 22 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

    Let me just pick a few examples from the code, because this is so bad

    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbt
    schrieb zuletzt editiert von
    #3

    This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

    They just have TODO comments, and happily accept anything, even if it's blatantly forged

    jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
    0
    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

      This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

      They just have TODO comments, and happily accept anything, even if it's blatantly forged

      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbt
      schrieb zuletzt editiert von
      #4

      Rather than implementing the critical state resolution algorithm that's the core of Matrix, they just directly insert the latest state into the database. That'll instantly lead to diverging views of the room and incompatibility with every other implementation - and it's also a massive security hole.

      jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        Rather than implementing the critical state resolution algorithm that's the core of Matrix, they just directly insert the latest state into the database. That'll instantly lead to diverging views of the room and incompatibility with every other implementation - and it's also a massive security hole.

        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
        jadedblueeyes@tech.lgbt
        schrieb zuletzt editiert von
        #5

        Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

        jadedblueeyes@tech.lgbtJ sodiboo@gaysex.cloudS darkcat09@gts.dc09.xyzD 3 Antworten Letzte Antwort
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

          barometz@social.treehouse.systemsB This user is from outside of this forum
          barometz@social.treehouse.systemsB This user is from outside of this forum
          barometz@social.treehouse.systems
          schrieb zuletzt editiert von
          #6

          @JadedBlueEyes I suppose "never mind auth" is also post-quantum, in a philosophical sort of way

          jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
          0
          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

            Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbt
            schrieb zuletzt editiert von
            #7

            Honestly this is almost insulting to me, as someone who has spent a nontrivial amount of effort developing a Matrix homeserver, with how low effort it is. And what’s the point? Marketing? I’m not gonna be trusting anything Cloudflare after this.

            jadedblueeyes@tech.lgbtJ tauon@possum.cityT darkcat09@gts.dc09.xyzD 3 Antworten Letzte Antwort
            0
            • barometz@social.treehouse.systemsB barometz@social.treehouse.systems

              @JadedBlueEyes I suppose "never mind auth" is also post-quantum, in a philosophical sort of way

              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbt
              schrieb zuletzt editiert von
              #8

              @barometz 😭 Post quantum openness

              1 Antwort Letzte Antwort
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                Honestly this is almost insulting to me, as someone who has spent a nontrivial amount of effort developing a Matrix homeserver, with how low effort it is. And what’s the point? Marketing? I’m not gonna be trusting anything Cloudflare after this.

                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                jadedblueeyes@tech.lgbt
                schrieb zuletzt editiert von
                #9

                The pricing comparisons are stupid, by the way, too - a bunch of us in the matrix chatrooms got out how many HTTP requests per day we were serving and the per-request cost of Workers would be more expensive than dedicated VPSs - not even counting CPU time or storage costs!

                jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                0
                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                  Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                  https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                  poitzorg@social.as743.orgP This user is from outside of this forum
                  poitzorg@social.as743.orgP This user is from outside of this forum
                  poitzorg@social.as743.org
                  schrieb zuletzt editiert von
                  #10

                  @JadedBlueEyes
                  Pretty solid business strategy!
                  Cloudflare bills rivaling current military budgets cause you got spammed by invalid room events... /s

                  jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                  0
                  • poitzorg@social.as743.orgP poitzorg@social.as743.org

                    @JadedBlueEyes
                    Pretty solid business strategy!
                    Cloudflare bills rivaling current military budgets cause you got spammed by invalid room events... /s

                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbt
                    schrieb zuletzt editiert von
                    #11

                    @poitzorg Even only counting valid events, a normal matrix server is still consistently serving millions of requests a month!

                    jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                    0
                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                      @poitzorg Even only counting valid events, a normal matrix server is still consistently serving millions of requests a month!

                      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                      jadedblueeyes@tech.lgbt
                      schrieb zuletzt editiert von
                      #12

                      @poitzorg per-request pricing is just not the right model for that

                      1 Antwort Letzte Antwort
                      0
                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                        hohokam@mastodon.sdf.orgH This user is from outside of this forum
                        hohokam@mastodon.sdf.orgH This user is from outside of this forum
                        hohokam@mastodon.sdf.org
                        schrieb zuletzt editiert von
                        #13

                        @JadedBlueEyes what a stupid time to be alive.

                        1 Antwort Letzte Antwort
                        0
                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                          The pricing comparisons are stupid, by the way, too - a bunch of us in the matrix chatrooms got out how many HTTP requests per day we were serving and the per-request cost of Workers would be more expensive than dedicated VPSs - not even counting CPU time or storage costs!

                          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                          jadedblueeyes@tech.lgbt
                          schrieb zuletzt editiert von
                          #14

                          For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                          jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchange
                            schrieb zuletzt editiert von
                            #15

                            @JadedBlueEyes lol. lmao even.

                            1 Antwort Letzte Antwort
                            0
                            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                              For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                              jadedblueeyes@tech.lgbt
                              schrieb zuletzt editiert von
                              #16

                              I'm also giving a talk about some of the actual work that goes into building this software in a few days at FOSDEM, if you want to learn more:

                              https://tech.lgbt/@JadedBlueEyes/115956965835059690

                              jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                              0
                              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                agowa338@chaos.socialA This user is from outside of this forum
                                agowa338@chaos.socialA This user is from outside of this forum
                                agowa338@chaos.social
                                schrieb zuletzt editiert von
                                #17

                                @JadedBlueEyes

                                Lol, just searching for "TODO" in their github repo doesn't disappoint

                                jadedblueeyes@tech.lgbtJ 1 Antwort Letzte Antwort
                                0
                                • agowa338@chaos.socialA agowa338@chaos.social

                                  @JadedBlueEyes

                                  Lol, just searching for "TODO" in their github repo doesn't disappoint

                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbt
                                  schrieb zuletzt editiert von
                                  #18

                                  @agowa338 They’re trying to clean up their tracks https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                  agowa338@chaos.socialA 1 Antwort Letzte Antwort
                                  0
                                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                    I'm also giving a talk about some of the actual work that goes into building this software in a few days at FOSDEM, if you want to learn more:

                                    https://tech.lgbt/@JadedBlueEyes/115956965835059690

                                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                    jadedblueeyes@tech.lgbt
                                    schrieb zuletzt editiert von
                                    #19

                                    Oh look, they’re trying to cover up what they did too

                                    https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                    Archive link for posterity:

                                    https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                    wyldtom@chaos.socialW outsidecontext@fosstodon.orgO herzog@mastodon.socialH algernon@come-from.mad-scientist.clubA nighten@hi.nighten.frN 5 Antworten Letzte Antwort
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      @agowa338 They’re trying to clean up their tracks https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                      agowa338@chaos.socialA This user is from outside of this forum
                                      agowa338@chaos.socialA This user is from outside of this forum
                                      agowa338@chaos.social
                                      schrieb zuletzt editiert von
                                      #20

                                      @JadedBlueEyes

                                      Wonder if that's because of my LinkedIn post from 15 minutes ago where I said that they're wasting everyones times and mentioned Cloudflare...

                                      https://www.linkedin.com/posts/klausfrank_ai-share-7421952201788608512-oFiv

                                      agowa338@chaos.socialA 1 Antwort Letzte Antwort
                                      0
                                      • agowa338@chaos.socialA agowa338@chaos.social

                                        @JadedBlueEyes

                                        Wonder if that's because of my LinkedIn post from 15 minutes ago where I said that they're wasting everyones times and mentioned Cloudflare...

                                        https://www.linkedin.com/posts/klausfrank_ai-share-7421952201788608512-oFiv

                                        agowa338@chaos.socialA This user is from outside of this forum
                                        agowa338@chaos.socialA This user is from outside of this forum
                                        agowa338@chaos.social
                                        schrieb zuletzt editiert von
                                        #21

                                        @JadedBlueEyes

                                        I mean it only got 6 impressions with one of them being by a paying member.

                                        But as I basically have no followers there and I mentioned them it's not that unlikely...

                                        1 Antwort Letzte Antwort
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                          me@mastodon.cysioland.plM This user is from outside of this forum
                                          me@mastodon.cysioland.plM This user is from outside of this forum
                                          me@mastodon.cysioland.pl
                                          schrieb zuletzt editiert von
                                          #22

                                          @JadedBlueEyes

                                          > You aren't just installing software; you are becoming a system administrator

                                          🤢

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum