Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
135 Indlæg 100 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • ddritter@neopaquita.esD ddritter@neopaquita.es

    @JadedBlueEyes From "vibe coding" to "vibe security".

    bumbervevo@easymode.imB This user is from outside of this forum
    bumbervevo@easymode.imB This user is from outside of this forum
    bumbervevo@easymode.im
    wrote sidst redigeret af
    #97

    @DDRitter@neopaquita.es @JadedBlueEyes@tech.lgbt puts a paper plate on top of your server
    Yeah that feels secure enough

    1 Reply Last reply
    0
    • herzog@mastodon.socialH herzog@mastodon.social

      @JadedBlueEyes This takes it from "lazy and disappointing" to "actively malicious". One quick apology blogpost would fix this, but they're doubling down, aren't they?

      womble@infosec.exchangeW This user is from outside of this forum
      womble@infosec.exchangeW This user is from outside of this forum
      womble@infosec.exchange
      wrote sidst redigeret af
      #98

      @herzog first rule of corporate comms: never, ever apologise.

      1 Reply Last reply
      0
      • bitofabother@swingset.socialB bitofabother@swingset.social

        @petunia @JadedBlueEyes so like, on an emotional level I understand why people hate ORMs, but on a "people are very bad at databases" level ..................

        womble@infosec.exchangeW This user is from outside of this forum
        womble@infosec.exchangeW This user is from outside of this forum
        womble@infosec.exchange
        wrote sidst redigeret af
        #99

        @bitofabother in fairness, people are also very bad at ORMs...

        1 Reply Last reply
        0
        • tauon@possum.cityT tauon@possum.city

          @JadedBlueEyes@tech.lgbt

          I’m not gonna be trusting anything Cloudflare after this.
          as if you should've been doing this in the first place

          apophis@kill-corporations.enterprisesA This user is from outside of this forum
          apophis@kill-corporations.enterprisesA This user is from outside of this forum
          apophis@kill-corporations.enterprises
          wrote sidst redigeret af
          #100
          @tauon @JadedBlueEyes true but this is the giant rock excavator hitting a whole new substrate of rock bottom
          1 Reply Last reply
          0
          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

            fsoc@infosec.exchangeF This user is from outside of this forum
            fsoc@infosec.exchangeF This user is from outside of this forum
            fsoc@infosec.exchange
            wrote sidst redigeret af
            #101

            @JadedBlueEyes

            Thank you for bringing your attention to this matter.

            This #slopshard

            1 Reply Last reply
            0
            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

              Oh look, they’re trying to cover up what they did too

              https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

              Archive link for posterity:

              https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

              bredroll@mas.toB This user is from outside of this forum
              bredroll@mas.toB This user is from outside of this forum
              bredroll@mas.to
              wrote sidst redigeret af
              #102

              @JadedBlueEyes did anyone fork thier repo?

              1 Reply Last reply
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                ariadne@social.treehouse.systemsA This user is from outside of this forum
                ariadne@social.treehouse.systemsA This user is from outside of this forum
                ariadne@social.treehouse.systems
                wrote sidst redigeret af
                #103

                @JadedBlueEyes does it scale? does it have the ability to delete CSAM when stupid edgelords device to upload it to your homeserver and then get you swatted?

                as always I want to believe there is a usable matrix homeserver... but it seems there is always a catch.

                1 Reply Last reply
                0
                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                  Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                  https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                  peturdainn@mastodon.socialP This user is from outside of this forum
                  peturdainn@mastodon.socialP This user is from outside of this forum
                  peturdainn@mastodon.social
                  wrote sidst redigeret af
                  #104

                  @JadedBlueEyes I stopped reading after:
                  "But there is a "tax" to running it. Traditionally, operating a Matrix homeserver has meant accepting a heavy operational burden. You have to provision virtual private servers (VPS), tune PostgreSQL for heavy write loads, manage Redis for caching, configure reverse proxies, and handle rotation for TLS certificates. It’s a stateful, heavy beast that demands to be fed time and money, whether you’re using it a lot or a little."

                  Mine runs on a small NAS 🤷‍♂️

                  1 Reply Last reply
                  0
                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                    saikoujya@mastodon.socialS This user is from outside of this forum
                    saikoujya@mastodon.socialS This user is from outside of this forum
                    saikoujya@mastodon.social
                    wrote sidst redigeret af
                    #105

                    @JadedBlueEyes internet is dead

                    1 Reply Last reply
                    0
                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                      I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

                      famfo@frogs.lgbtF This user is from outside of this forum
                      famfo@frogs.lgbtF This user is from outside of this forum
                      famfo@frogs.lgbt
                      wrote sidst redigeret af
                      #106

                      @JadedBlueEyes a bit later in the posts it's still

                      > The key insight from porting Tuwunel

                      instead of Synapse

                      1 Reply Last reply
                      0
                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                        legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
                        legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
                        legit_spaghetti@mastodo.neoliber.al
                        wrote sidst redigeret af
                        #107

                        @JadedBlueEyes So, in layman's terms, does this mean they claimed they did a thing but did not actually do the thing, and no one checked whether they did the thing before they published the blog claiming they did the thing?

                        jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                        0
                        • joepie91@fedi.slightly.techJ joepie91@fedi.slightly.tech

                          @JadedBlueEyes This is almost a minor criticism in comparison to all the other crap, but I am so sick of companies calling things 'serverless' when what they really mean is "servers, but only ours and they're really opaquely billed and impossible to replace with someone else's servers so you're stuck with us, and also they're managed in a totally custom way so none of your normal sysadmin skills are portable to it but you still have to learn how to manage it"

                          lunaphied@provably.onlineL This user is from outside of this forum
                          lunaphied@provably.onlineL This user is from outside of this forum
                          lunaphied@provably.online
                          wrote sidst redigeret af
                          #108

                          @JadedBlueEyes @joepie91 we've just gone back to managed databases again: overpriced, billed by metrics that aren't easy to price, and totally impossible to manage.

                          1 Reply Last reply
                          0
                          • simonjust@mstdn.dkS simonjust@mstdn.dk shared this topic
                          • legit_spaghetti@mastodo.neoliber.alL legit_spaghetti@mastodo.neoliber.al

                            @JadedBlueEyes So, in layman's terms, does this mean they claimed they did a thing but did not actually do the thing, and no one checked whether they did the thing before they published the blog claiming they did the thing?

                            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                            jadedblueeyes@tech.lgbt
                            wrote sidst redigeret af
                            #109

                            @Legit_Spaghetti Yep. They claimed to do an extremely hard thing which is notorious for having security issues, and did not do it.

                            1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              @JadedBlueEyes lol

                              siguza@infosec.spaceS This user is from outside of this forum
                              siguza@infosec.spaceS This user is from outside of this forum
                              siguza@infosec.space
                              wrote sidst redigeret af
                              #110

                              @GossiTheDog @JadedBlueEyes fucking OUCH

                              lerxst@az.socialL 1 Reply Last reply
                              0
                              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

                                walnut@shrimp.thesoftestpaws.netW This user is from outside of this forum
                                walnut@shrimp.thesoftestpaws.netW This user is from outside of this forum
                                walnut@shrimp.thesoftestpaws.net
                                wrote sidst redigeret af
                                #111
                                @JadedBlueEyes
                                They probably asked claude or chatgpt or whatever the name of the latest slop machine that's just gpt with a different initial prompt is to fix the blogpost, too.
                                1 Reply Last reply
                                0
                                • ivan@possum.cityI ivan@possum.city

                                  @JadedBlueEyes@tech.lgbt

                                  What in absolute fuck is a serverless server

                                  C This user is from outside of this forum
                                  C This user is from outside of this forum
                                  cjmalone@en.osm.town
                                  wrote sidst redigeret af
                                  #112

                                  @ivan @JadedBlueEyes someone elses server

                                  1 Reply Last reply
                                  0
                                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                    jc0f0116@infosec.exchangeJ This user is from outside of this forum
                                    jc0f0116@infosec.exchangeJ This user is from outside of this forum
                                    jc0f0116@infosec.exchange
                                    wrote sidst redigeret af
                                    #113

                                    @JadedBlueEyes Granted I don't know shit about serverless or quantum blablabla but that blog read like lorem ipsum text??? I guess if the project is underspecified and sufficiently novel Opus will just shit the bed. I think I want to write a bunch of .md files less than I want to write code which is already very little...

                                    1 Reply Last reply
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                      https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                      spyke@mastodon.onlineS This user is from outside of this forum
                                      spyke@mastodon.onlineS This user is from outside of this forum
                                      spyke@mastodon.online
                                      wrote sidst redigeret af
                                      #114

                                      @JadedBlueEyes This is literally how some of the pull requests look today at work. People vibe code; don't even look at the output; git push if the app works; ask for review/approvals; get annoyed, when you question why there are two identical files; pass your comments to the bot; push again without checking when it finishes; manager advises you to tame down your perfectionism; also asks why do you do less tickets than others.

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                        beejeebus@drupal.communityB This user is from outside of this forum
                                        beejeebus@drupal.communityB This user is from outside of this forum
                                        beejeebus@drupal.community
                                        wrote sidst redigeret af
                                        #115

                                        @JadedBlueEyes seems like the sort of thing @davidgerard would like to read

                                        davidgerard@circumstances.runD 1 Reply Last reply
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                          deliciousmile@mstdn.socialD This user is from outside of this forum
                                          deliciousmile@mstdn.socialD This user is from outside of this forum
                                          deliciousmile@mstdn.social
                                          wrote sidst redigeret af
                                          #116

                                          @JadedBlueEyes sasuga Buttflare

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper