Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
103 Indlæg 71 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

    This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

    They just have TODO comments, and happily accept anything, even if it's blatantly forged

    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
    jadedblueeyes@tech.lgbt
    wrote sidst redigeret af
    #5

    Rather than implementing the critical state resolution algorithm that's the core of Matrix, they just directly insert the latest state into the database. That'll instantly lead to diverging views of the room and incompatibility with every other implementation - and it's also a massive security hole.

    jadedblueeyes@tech.lgbtJ jessew@mk.cpluspatch.comJ 2 Replies Last reply
    0
    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

      Rather than implementing the critical state resolution algorithm that's the core of Matrix, they just directly insert the latest state into the database. That'll instantly lead to diverging views of the room and incompatibility with every other implementation - and it's also a massive security hole.

      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
      jadedblueeyes@tech.lgbt
      wrote sidst redigeret af
      #6

      Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

      jadedblueeyes@tech.lgbtJ sodiboo@gaysex.cloudS darkcat09@gts.dc09.xyzD h5e@tech.lgbtH 4 Replies Last reply
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

        barometz@social.treehouse.systemsB This user is from outside of this forum
        barometz@social.treehouse.systemsB This user is from outside of this forum
        barometz@social.treehouse.systems
        wrote sidst redigeret af
        #7

        @JadedBlueEyes I suppose "never mind auth" is also post-quantum, in a philosophical sort of way

        jadedblueeyes@tech.lgbtJ 1 Reply Last reply
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
          jadedblueeyes@tech.lgbt
          wrote sidst redigeret af
          #8

          Honestly this is almost insulting to me, as someone who has spent a nontrivial amount of effort developing a Matrix homeserver, with how low effort it is. And what’s the point? Marketing? I’m not gonna be trusting anything Cloudflare after this.

          jadedblueeyes@tech.lgbtJ tauon@possum.cityT darkcat09@gts.dc09.xyzD 3 Replies Last reply
          0
          • barometz@social.treehouse.systemsB barometz@social.treehouse.systems

            @JadedBlueEyes I suppose "never mind auth" is also post-quantum, in a philosophical sort of way

            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbt
            wrote sidst redigeret af
            #9

            @barometz 😭 Post quantum openness

            1 Reply Last reply
            0
            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

              Honestly this is almost insulting to me, as someone who has spent a nontrivial amount of effort developing a Matrix homeserver, with how low effort it is. And what’s the point? Marketing? I’m not gonna be trusting anything Cloudflare after this.

              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbt
              wrote sidst redigeret af
              #10

              The pricing comparisons are stupid, by the way, too - a bunch of us in the matrix chatrooms got out how many HTTP requests per day we were serving and the per-request cost of Workers would be more expensive than dedicated VPSs - not even counting CPU time or storage costs!

              jadedblueeyes@tech.lgbtJ 1 Reply Last reply
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                poitzorg@social.as743.orgP This user is from outside of this forum
                poitzorg@social.as743.orgP This user is from outside of this forum
                poitzorg@social.as743.org
                wrote sidst redigeret af
                #11

                @JadedBlueEyes
                Pretty solid business strategy!
                Cloudflare bills rivaling current military budgets cause you got spammed by invalid room events... /s

                jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                0
                • poitzorg@social.as743.orgP poitzorg@social.as743.org

                  @JadedBlueEyes
                  Pretty solid business strategy!
                  Cloudflare bills rivaling current military budgets cause you got spammed by invalid room events... /s

                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                  jadedblueeyes@tech.lgbt
                  wrote sidst redigeret af
                  #12

                  @poitzorg Even only counting valid events, a normal matrix server is still consistently serving millions of requests a month!

                  jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                  0
                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                    @poitzorg Even only counting valid events, a normal matrix server is still consistently serving millions of requests a month!

                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                    jadedblueeyes@tech.lgbt
                    wrote sidst redigeret af
                    #13

                    @poitzorg per-request pricing is just not the right model for that

                    1 Reply Last reply
                    0
                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                      Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                      https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                      hohokam@mastodon.sdf.orgH This user is from outside of this forum
                      hohokam@mastodon.sdf.orgH This user is from outside of this forum
                      hohokam@mastodon.sdf.org
                      wrote sidst redigeret af
                      #14

                      @JadedBlueEyes what a stupid time to be alive.

                      1 Reply Last reply
                      0
                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                        The pricing comparisons are stupid, by the way, too - a bunch of us in the matrix chatrooms got out how many HTTP requests per day we were serving and the per-request cost of Workers would be more expensive than dedicated VPSs - not even counting CPU time or storage costs!

                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                        jadedblueeyes@tech.lgbt
                        wrote sidst redigeret af
                        #15

                        For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                        jadedblueeyes@tech.lgbtJ ariadne@social.treehouse.systemsA 2 Replies Last reply
                        0
                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchange
                          wrote sidst redigeret af
                          #16

                          @JadedBlueEyes lol. lmao even.

                          1 Reply Last reply
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            For those of you that don't know, I develop https://continuwuity.org - a Rust based Matrix homeserver that actually works, and that you can run on a Raspberry Pi, rather than someone else's centralized cloud infrastructure

                            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                            jadedblueeyes@tech.lgbt
                            wrote sidst redigeret af
                            #17

                            I'm also giving a talk about some of the actual work that goes into building this software in a few days at FOSDEM, if you want to learn more:

                            https://tech.lgbt/@JadedBlueEyes/115956965835059690

                            jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                            0
                            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                              Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                              https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                              agowa338@chaos.socialA This user is from outside of this forum
                              agowa338@chaos.socialA This user is from outside of this forum
                              agowa338@chaos.social
                              wrote sidst redigeret af
                              #18

                              @JadedBlueEyes

                              Lol, just searching for "TODO" in their github repo doesn't disappoint

                              jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                              0
                              • agowa338@chaos.socialA agowa338@chaos.social

                                @JadedBlueEyes

                                Lol, just searching for "TODO" in their github repo doesn't disappoint

                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbt
                                wrote sidst redigeret af
                                #19

                                @agowa338 They’re trying to clean up their tracks https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                agowa338@chaos.socialA 1 Reply Last reply
                                0
                                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                  I'm also giving a talk about some of the actual work that goes into building this software in a few days at FOSDEM, if you want to learn more:

                                  https://tech.lgbt/@JadedBlueEyes/115956965835059690

                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbt
                                  wrote sidst redigeret af
                                  #20

                                  Oh look, they’re trying to cover up what they did too

                                  https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                  Archive link for posterity:

                                  https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                  kieran@hom.phK wyldtom@chaos.socialW outsidecontext@fosstodon.orgO herzog@mastodon.socialH algernon@come-from.mad-scientist.clubA 8 Replies Last reply
                                  0
                                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                    @agowa338 They’re trying to clean up their tracks https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                    agowa338@chaos.socialA This user is from outside of this forum
                                    agowa338@chaos.socialA This user is from outside of this forum
                                    agowa338@chaos.social
                                    wrote sidst redigeret af
                                    #21

                                    @JadedBlueEyes

                                    Wonder if that's because of my LinkedIn post from 15 minutes ago where I said that they're wasting everyones times and mentioned Cloudflare...

                                    https://www.linkedin.com/posts/klausfrank_ai-share-7421952201788608512-oFiv

                                    agowa338@chaos.socialA 1 Reply Last reply
                                    0
                                    • agowa338@chaos.socialA agowa338@chaos.social

                                      @JadedBlueEyes

                                      Wonder if that's because of my LinkedIn post from 15 minutes ago where I said that they're wasting everyones times and mentioned Cloudflare...

                                      https://www.linkedin.com/posts/klausfrank_ai-share-7421952201788608512-oFiv

                                      agowa338@chaos.socialA This user is from outside of this forum
                                      agowa338@chaos.socialA This user is from outside of this forum
                                      agowa338@chaos.social
                                      wrote sidst redigeret af
                                      #22

                                      @JadedBlueEyes

                                      I mean it only got 6 impressions with one of them being by a paying member.

                                      But as I basically have no followers there and I mentioned them it's not that unlikely...

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                        me@mastodon.cysioland.plM This user is from outside of this forum
                                        me@mastodon.cysioland.plM This user is from outside of this forum
                                        me@mastodon.cysioland.pl
                                        wrote sidst redigeret af
                                        #23

                                        @JadedBlueEyes

                                        > You aren't just installing software; you are becoming a system administrator

                                        🤢

                                        1 Reply Last reply
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                          kopper@not-brain.d.on-t.workK This user is from outside of this forum
                                          kopper@not-brain.d.on-t.workK This user is from outside of this forum
                                          kopper@not-brain.d.on-t.work
                                          wrote sidst redigeret af
                                          #24
                                          @JadedBlueEyes it's wildebeest (cloudflare fedi software that leaked dms to the public) all over again
                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper