Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
103 Indlæg 71 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

    For those coming in now, they updated the blog post to include a disclaimer. Original post:
    https://archive.is/AbxU5

    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbt
    wrote sidst redigeret af
    #80

    [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

    jadedblueeyes@tech.lgbtJ 1 Reply Last reply
    0
    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

      [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbt
      wrote sidst redigeret af
      #81

      https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

      Quoting from one of my chat rooms:

      > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

      authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

      > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

      YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

      jadedblueeyes@tech.lgbtJ 1 Reply Last reply
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

        They just have TODO comments, and happily accept anything, even if it's blatantly forged

        ricko@tech.lgbtR This user is from outside of this forum
        ricko@tech.lgbtR This user is from outside of this forum
        ricko@tech.lgbt
        wrote sidst redigeret af
        #82

        @JadedBlueEyes Eeek. That || instead of ?? is just painful to see. Repeatedly.

        At my previous company we had one of our mid-level devs fall into this trap last year. Ended up failing in production in almost exactly this type of scenario, where the dev expected an array or undefined, but got true.

        I have to wonder if this is an artifact of the initial training for these systems being on Python, which doesn't have a strong equivalent for ??. And, you know, the fact that these things don't actually understand the code they generate, as much as anyone may claim otherwise.

        1 Reply Last reply
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

          chris_colvin@mastodon.socialC This user is from outside of this forum
          chris_colvin@mastodon.socialC This user is from outside of this forum
          chris_colvin@mastodon.social
          wrote sidst redigeret af
          #83

          @JadedBlueEyes don't worry

          "* This post was updated at 11:45 a.m. Pacific time to clarify that the use case described here is a proof of concept and a personal project. Some sections have been updated for clarity."

          1 Reply Last reply
          0
          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

            Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

            h5e@tech.lgbtH This user is from outside of this forum
            h5e@tech.lgbtH This user is from outside of this forum
            h5e@tech.lgbt
            wrote sidst redigeret af
            #84

            @JadedBlueEyes They updated their post, it now says Synapse instead of Tuwunel.

            jadedblueeyes@tech.lgbtJ 1 Reply Last reply
            0
            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

              https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

              Quoting from one of my chat rooms:

              > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

              authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

              > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

              YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbt
              wrote sidst redigeret af
              #85

              I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

              1 Reply Last reply
              0
              • h5e@tech.lgbtH h5e@tech.lgbt

                @JadedBlueEyes They updated their post, it now says Synapse instead of Tuwunel.

                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                jadedblueeyes@tech.lgbt
                wrote sidst redigeret af
                #86

                @h5e https://tech.lgbt/@JadedBlueEyes/115968861622285804

                h5e@tech.lgbtH 1 Reply Last reply
                0
                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                  Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                  https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                  amd@gts.amd.imA This user is from outside of this forum
                  amd@gts.amd.imA This user is from outside of this forum
                  amd@gts.amd.im
                  wrote sidst redigeret af
                  #87

                  @JadedBlueEyes thank you for your work on continuwuity. An actually good matrix implementation.

                  1 Reply Last reply
                  0
                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    wrote sidst redigeret af
                    #88

                    @JadedBlueEyes lol

                    1 Reply Last reply
                    0
                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                      @h5e https://tech.lgbt/@JadedBlueEyes/115968861622285804

                      h5e@tech.lgbtH This user is from outside of this forum
                      h5e@tech.lgbtH This user is from outside of this forum
                      h5e@tech.lgbt
                      wrote sidst redigeret af
                      #89

                      @JadedBlueEyes oh sorry I missed that!

                      h5e@tech.lgbtH 1 Reply Last reply
                      0
                      • h5e@tech.lgbtH h5e@tech.lgbt

                        @JadedBlueEyes oh sorry I missed that!

                        h5e@tech.lgbtH This user is from outside of this forum
                        h5e@tech.lgbtH This user is from outside of this forum
                        h5e@tech.lgbt
                        wrote sidst redigeret af
                        #90

                        @JadedBlueEyes ah we posted around the same time. I did check 😅

                        1 Reply Last reply
                        0
                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                          eflex@social.spejset.orgE This user is from outside of this forum
                          eflex@social.spejset.orgE This user is from outside of this forum
                          eflex@social.spejset.org
                          wrote sidst redigeret af
                          #91

                          @JadedBlueEyes I am so glad we are well invested, giving all of the moneys to Cloudflare.

                          1 Reply Last reply
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

                            They just have TODO comments, and happily accept anything, even if it's blatantly forged

                            joshbal4@m.fa.glJ This user is from outside of this forum
                            joshbal4@m.fa.glJ This user is from outside of this forum
                            joshbal4@m.fa.gl
                            wrote sidst redigeret af
                            #92

                            @JadedBlueEyes it’s post-quantum security: if you observe it it’s not there

                            1 Reply Last reply
                            0
                            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                              Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                              https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                              lappenjammerdiezweite@social.vivaldi.netL This user is from outside of this forum
                              lappenjammerdiezweite@social.vivaldi.netL This user is from outside of this forum
                              lappenjammerdiezweite@social.vivaldi.net
                              wrote sidst redigeret af
                              #93

                              @JadedBlueEyes Is this "blue screen of death" cloudflare?

                              1 Reply Last reply
                              0
                              • ddritter@neopaquita.esD ddritter@neopaquita.es

                                @JadedBlueEyes From "vibe coding" to "vibe security".

                                bumbervevo@easymode.imB This user is from outside of this forum
                                bumbervevo@easymode.imB This user is from outside of this forum
                                bumbervevo@easymode.im
                                wrote sidst redigeret af
                                #94

                                @DDRitter@neopaquita.es @JadedBlueEyes@tech.lgbt puts a paper plate on top of your server
                                Yeah that feels secure enough

                                1 Reply Last reply
                                0
                                • bitofabother@swingset.socialB bitofabother@swingset.social

                                  @petunia @JadedBlueEyes so like, on an emotional level I understand why people hate ORMs, but on a "people are very bad at databases" level ..................

                                  womble@infosec.exchangeW This user is from outside of this forum
                                  womble@infosec.exchangeW This user is from outside of this forum
                                  womble@infosec.exchange
                                  wrote sidst redigeret af
                                  #95

                                  @bitofabother in fairness, people are also very bad at ORMs...

                                  1 Reply Last reply
                                  0
                                  • tauon@possum.cityT tauon@possum.city

                                    @JadedBlueEyes@tech.lgbt

                                    I’m not gonna be trusting anything Cloudflare after this.
                                    as if you should've been doing this in the first place

                                    apophis@kill-corporations.enterprisesA This user is from outside of this forum
                                    apophis@kill-corporations.enterprisesA This user is from outside of this forum
                                    apophis@kill-corporations.enterprises
                                    wrote sidst redigeret af
                                    #96
                                    @tauon @JadedBlueEyes true but this is the giant rock excavator hitting a whole new substrate of rock bottom
                                    1 Reply Last reply
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                      https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                      fsoc@infosec.exchangeF This user is from outside of this forum
                                      fsoc@infosec.exchangeF This user is from outside of this forum
                                      fsoc@infosec.exchange
                                      wrote sidst redigeret af
                                      #97

                                      @JadedBlueEyes

                                      Thank you for bringing your attention to this matter.

                                      This #slopshard

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        Oh look, they’re trying to cover up what they did too

                                        https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                        Archive link for posterity:

                                        https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                        bredroll@mas.toB This user is from outside of this forum
                                        bredroll@mas.toB This user is from outside of this forum
                                        bredroll@mas.to
                                        wrote sidst redigeret af
                                        #98

                                        @JadedBlueEyes did anyone fork thier repo?

                                        1 Reply Last reply
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                                          ariadne@social.treehouse.systemsA This user is from outside of this forum
                                          ariadne@social.treehouse.systemsA This user is from outside of this forum
                                          ariadne@social.treehouse.systems
                                          wrote sidst redigeret af
                                          #99

                                          @JadedBlueEyes does it scale? does it have the ability to delete CSAM when stupid edgelords device to upload it to your homeserver and then get you swatted?

                                          as always I want to believe there is a usable matrix homeserver... but it seems there is always a catch.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper