Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
135 Indlæg 100 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

    fsoc@infosec.exchangeF This user is from outside of this forum
    fsoc@infosec.exchangeF This user is from outside of this forum
    fsoc@infosec.exchange
    wrote sidst redigeret af
    #101

    @JadedBlueEyes

    Thank you for bringing your attention to this matter.

    This #slopshard

    1 Reply Last reply
    0
    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

      Oh look, they’re trying to cover up what they did too

      https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

      Archive link for posterity:

      https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

      bredroll@mas.toB This user is from outside of this forum
      bredroll@mas.toB This user is from outside of this forum
      bredroll@mas.to
      wrote sidst redigeret af
      #102

      @JadedBlueEyes did anyone fork thier repo?

      1 Reply Last reply
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

        ariadne@social.treehouse.systemsA This user is from outside of this forum
        ariadne@social.treehouse.systemsA This user is from outside of this forum
        ariadne@social.treehouse.systems
        wrote sidst redigeret af
        #103

        @JadedBlueEyes does it scale? does it have the ability to delete CSAM when stupid edgelords device to upload it to your homeserver and then get you swatted?

        as always I want to believe there is a usable matrix homeserver... but it seems there is always a catch.

        1 Reply Last reply
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

          peturdainn@mastodon.socialP This user is from outside of this forum
          peturdainn@mastodon.socialP This user is from outside of this forum
          peturdainn@mastodon.social
          wrote sidst redigeret af
          #104

          @JadedBlueEyes I stopped reading after:
          "But there is a "tax" to running it. Traditionally, operating a Matrix homeserver has meant accepting a heavy operational burden. You have to provision virtual private servers (VPS), tune PostgreSQL for heavy write loads, manage Redis for caching, configure reverse proxies, and handle rotation for TLS certificates. It’s a stateful, heavy beast that demands to be fed time and money, whether you’re using it a lot or a little."

          Mine runs on a small NAS 🤷‍♂️

          1 Reply Last reply
          0
          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

            saikoujya@mastodon.socialS This user is from outside of this forum
            saikoujya@mastodon.socialS This user is from outside of this forum
            saikoujya@mastodon.social
            wrote sidst redigeret af
            #105

            @JadedBlueEyes internet is dead

            1 Reply Last reply
            0
            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

              I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

              famfo@frogs.lgbtF This user is from outside of this forum
              famfo@frogs.lgbtF This user is from outside of this forum
              famfo@frogs.lgbt
              wrote sidst redigeret af
              #106

              @JadedBlueEyes a bit later in the posts it's still

              > The key insight from porting Tuwunel

              instead of Synapse

              1 Reply Last reply
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
                legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
                legit_spaghetti@mastodo.neoliber.al
                wrote sidst redigeret af
                #107

                @JadedBlueEyes So, in layman's terms, does this mean they claimed they did a thing but did not actually do the thing, and no one checked whether they did the thing before they published the blog claiming they did the thing?

                jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                0
                • joepie91@fedi.slightly.techJ joepie91@fedi.slightly.tech

                  @JadedBlueEyes This is almost a minor criticism in comparison to all the other crap, but I am so sick of companies calling things 'serverless' when what they really mean is "servers, but only ours and they're really opaquely billed and impossible to replace with someone else's servers so you're stuck with us, and also they're managed in a totally custom way so none of your normal sysadmin skills are portable to it but you still have to learn how to manage it"

                  lunaphied@provably.onlineL This user is from outside of this forum
                  lunaphied@provably.onlineL This user is from outside of this forum
                  lunaphied@provably.online
                  wrote sidst redigeret af
                  #108

                  @JadedBlueEyes @joepie91 we've just gone back to managed databases again: overpriced, billed by metrics that aren't easy to price, and totally impossible to manage.

                  1 Reply Last reply
                  0
                  • simonjust@mstdn.dkS simonjust@mstdn.dk shared this topic
                  • legit_spaghetti@mastodo.neoliber.alL legit_spaghetti@mastodo.neoliber.al

                    @JadedBlueEyes So, in layman's terms, does this mean they claimed they did a thing but did not actually do the thing, and no one checked whether they did the thing before they published the blog claiming they did the thing?

                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbt
                    wrote sidst redigeret af
                    #109

                    @Legit_Spaghetti Yep. They claimed to do an extremely hard thing which is notorious for having security issues, and did not do it.

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      @JadedBlueEyes lol

                      siguza@infosec.spaceS This user is from outside of this forum
                      siguza@infosec.spaceS This user is from outside of this forum
                      siguza@infosec.space
                      wrote sidst redigeret af
                      #110

                      @GossiTheDog @JadedBlueEyes fucking OUCH

                      lerxst@az.socialL 1 Reply Last reply
                      0
                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                        I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

                        walnut@shrimp.thesoftestpaws.netW This user is from outside of this forum
                        walnut@shrimp.thesoftestpaws.netW This user is from outside of this forum
                        walnut@shrimp.thesoftestpaws.net
                        wrote sidst redigeret af
                        #111
                        @JadedBlueEyes
                        They probably asked claude or chatgpt or whatever the name of the latest slop machine that's just gpt with a different initial prompt is to fix the blogpost, too.
                        1 Reply Last reply
                        0
                        • ivan@possum.cityI ivan@possum.city

                          @JadedBlueEyes@tech.lgbt

                          What in absolute fuck is a serverless server

                          C This user is from outside of this forum
                          C This user is from outside of this forum
                          cjmalone@en.osm.town
                          wrote sidst redigeret af
                          #112

                          @ivan @JadedBlueEyes someone elses server

                          1 Reply Last reply
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                            jc0f0116@infosec.exchangeJ This user is from outside of this forum
                            jc0f0116@infosec.exchangeJ This user is from outside of this forum
                            jc0f0116@infosec.exchange
                            wrote sidst redigeret af
                            #113

                            @JadedBlueEyes Granted I don't know shit about serverless or quantum blablabla but that blog read like lorem ipsum text??? I guess if the project is underspecified and sufficiently novel Opus will just shit the bed. I think I want to write a bunch of .md files less than I want to write code which is already very little...

                            1 Reply Last reply
                            0
                            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                              Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                              https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                              spyke@mastodon.onlineS This user is from outside of this forum
                              spyke@mastodon.onlineS This user is from outside of this forum
                              spyke@mastodon.online
                              wrote sidst redigeret af
                              #114

                              @JadedBlueEyes This is literally how some of the pull requests look today at work. People vibe code; don't even look at the output; git push if the app works; ask for review/approvals; get annoyed, when you question why there are two identical files; pass your comments to the bot; push again without checking when it finishes; manager advises you to tame down your perfectionism; also asks why do you do less tickets than others.

                              1 Reply Last reply
                              0
                              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                beejeebus@drupal.communityB This user is from outside of this forum
                                beejeebus@drupal.communityB This user is from outside of this forum
                                beejeebus@drupal.community
                                wrote sidst redigeret af
                                #115

                                @JadedBlueEyes seems like the sort of thing @davidgerard would like to read

                                davidgerard@circumstances.runD 1 Reply Last reply
                                0
                                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                  Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                  https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                  deliciousmile@mstdn.socialD This user is from outside of this forum
                                  deliciousmile@mstdn.socialD This user is from outside of this forum
                                  deliciousmile@mstdn.social
                                  wrote sidst redigeret af
                                  #116

                                  @JadedBlueEyes sasuga Buttflare

                                  1 Reply Last reply
                                  0
                                  • beejeebus@drupal.communityB beejeebus@drupal.community

                                    @JadedBlueEyes seems like the sort of thing @davidgerard would like to read

                                    davidgerard@circumstances.runD This user is from outside of this forum
                                    davidgerard@circumstances.runD This user is from outside of this forum
                                    davidgerard@circumstances.run
                                    wrote sidst redigeret af
                                    #117

                                    @beejeebus @JadedBlueEyes for horrified and appalled levels of "like"

                                    so i guess that's a yes

                                    1 Reply Last reply
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

                                      Quoting from one of my chat rooms:

                                      > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

                                      authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

                                      > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

                                      YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

                                      itswoland@mastodon.mlI This user is from outside of this forum
                                      itswoland@mastodon.mlI This user is from outside of this forum
                                      itswoland@mastodon.ml
                                      wrote sidst redigeret af
                                      #118

                                      @JadedBlueEyes

                                      Are they upload the code to public repo AS IS?

                                      If so, we are in a deep shit.
                                      If not, maybe they publish the open-source boilerplate, when the auth was proprietary

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                        cambria@hachyderm.ioC This user is from outside of this forum
                                        cambria@hachyderm.ioC This user is from outside of this forum
                                        cambria@hachyderm.io
                                        wrote sidst redigeret af
                                        #119

                                        @JadedBlueEyes
                                        It's just like that time I implemented Matrix in ActivityPub!

                                        https://hachyderm.io/@cambria/115970344802897969

                                        1 Reply Last reply
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                          smlx@fosstodon.orgS This user is from outside of this forum
                                          smlx@fosstodon.orgS This user is from outside of this forum
                                          smlx@fosstodon.org
                                          wrote sidst redigeret af
                                          #120

                                          @JadedBlueEyes Slop like this is so disrespectful to the time of everyone who reads the blog post. Jerks who are too lazy to do their job properly and expect others to fix their careless mistakes existed before LLMs but I swear this technology is like rocket fuel for these people.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper