Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
103 Indlæg 71 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

    @josh @dcousineau oh god I didn't even look at the client code

    dcousineau@hachyderm.ioD This user is from outside of this forum
    dcousineau@hachyderm.ioD This user is from outside of this forum
    dcousineau@hachyderm.io
    wrote sidst redigeret af
    #62

    @JadedBlueEyes @josh oh woooow, using ...innerHtml = `<...>`, inCREDIBLE the kids these days couldn't understand

    1 Reply Last reply
    0
    • wyldtom@chaos.socialW wyldtom@chaos.social

      @JadedBlueEyes The comments under this commit make it at least a bit funnier

      elilla@transmom.loveE This user is from outside of this forum
      elilla@transmom.loveE This user is from outside of this forum
      elilla@transmom.love
      wrote sidst redigeret af
      #63

      @wyldtom @JadedBlueEyes for me the funniest part is

      > a serverless architecture where operations disappear, costs scale to zero when idle, and every connection is protected by post-quantum cryptography by default.

      I don't know about the post-quantum cryptography, but I'll grant them that their homeserver is serveless and costs scale to zero (on account of it not existing)

      flesh@transfem.socialF 1 Reply Last reply
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

        dio9sys@haunted.computerD This user is from outside of this forum
        dio9sys@haunted.computerD This user is from outside of this forum
        dio9sys@haunted.computer
        wrote sidst redigeret af
        #64

        @JadedBlueEyes ah yes, AI. The technology of the future right?

        ...right??

        1 Reply Last reply
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

          ivan@possum.cityI This user is from outside of this forum
          ivan@possum.cityI This user is from outside of this forum
          ivan@possum.city
          wrote sidst redigeret af
          #65

          @JadedBlueEyes@tech.lgbt

          What in absolute fuck is a serverless server

          1 Reply Last reply
          0
          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

            moin@gruene.socialM This user is from outside of this forum
            moin@gruene.socialM This user is from outside of this forum
            moin@gruene.social
            wrote sidst redigeret af
            #66

            @JadedBlueEyes
            They seem to do there Global deployment this way...

            1 Reply Last reply
            0
            • elilla@transmom.loveE elilla@transmom.love

              @wyldtom @JadedBlueEyes for me the funniest part is

              > a serverless architecture where operations disappear, costs scale to zero when idle, and every connection is protected by post-quantum cryptography by default.

              I don't know about the post-quantum cryptography, but I'll grant them that their homeserver is serveless and costs scale to zero (on account of it not existing)

              flesh@transfem.socialF This user is from outside of this forum
              flesh@transfem.socialF This user is from outside of this forum
              flesh@transfem.social
              wrote sidst redigeret af
              #67

              @elilla@transmom.love @wyldtom@chaos.social @JadedBlueEyes@tech.lgbt Not even a quantum computer can get your data from the system without authorisation.

              elilla@transmom.loveE 1 Reply Last reply
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                grumpasaurus@infosec.exchangeG This user is from outside of this forum
                grumpasaurus@infosec.exchangeG This user is from outside of this forum
                grumpasaurus@infosec.exchange
                wrote sidst redigeret af
                #68

                @JadedBlueEyes aewwwww2 crap

                1 Reply Last reply
                0
                • flesh@transfem.socialF flesh@transfem.social

                  @elilla@transmom.love @wyldtom@chaos.social @JadedBlueEyes@tech.lgbt Not even a quantum computer can get your data from the system without authorisation.

                  elilla@transmom.loveE This user is from outside of this forum
                  elilla@transmom.loveE This user is from outside of this forum
                  elilla@transmom.love
                  wrote sidst redigeret af
                  #69

                  @flesh @wyldtom @JadedBlueEyes Cloudflare truly has mastered the definite Matrix security approach (not sending messages at all)

                  1 Reply Last reply
                  0
                  • algernon@come-from.mad-scientist.clubA algernon@come-from.mad-scientist.club

                    @JadedBlueEyes I recently learned that GitHub allows one to view the activity on a repo, and you can limit it to show force pushes only, which in turn allows you to view the diff between the two states too, even if they span multiple commits.

                    It's fun to see what kind of things some companies try to hide. (edit: like the original history, which has some fun commits in there!)

                    phryk@mastodon.socialP This user is from outside of this forum
                    phryk@mastodon.socialP This user is from outside of this forum
                    phryk@mastodon.social
                    wrote sidst redigeret af
                    #70

                    @algernon @JadedBlueEyes "Remove PII" is always a banger of a commit to have public. 👌 😂

                    1 Reply Last reply
                    0
                    • joepie91@fedi.slightly.techJ joepie91@fedi.slightly.tech

                      @JadedBlueEyes This is almost a minor criticism in comparison to all the other crap, but I am so sick of companies calling things 'serverless' when what they really mean is "servers, but only ours and they're really opaquely billed and impossible to replace with someone else's servers so you're stuck with us, and also they're managed in a totally custom way so none of your normal sysadmin skills are portable to it but you still have to learn how to manage it"

                      flesh@transfem.socialF This user is from outside of this forum
                      flesh@transfem.socialF This user is from outside of this forum
                      flesh@transfem.social
                      wrote sidst redigeret af
                      #71

                      @joepie91@fedi.slightly.tech @JadedBlueEyes@tech.lgbt It seems minor in comparison, because we're so far down along the tracks, but it's still a line we never should have allowed to be crossed.

                      1 Reply Last reply
                      0
                      • kieran@hom.phK kieran@hom.ph

                        @JadedBlueEyes that'll fix it!

                        airshipper@cloudisland.nzA This user is from outside of this forum
                        airshipper@cloudisland.nzA This user is from outside of this forum
                        airshipper@cloudisland.nz
                        wrote sidst redigeret af
                        #72

                        @kieran @JadedBlueEyes addressed todos, ready to ship!

                        1 Reply Last reply
                        0
                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                          markasspandi@shrimpnet.gej.petM This user is from outside of this forum
                          markasspandi@shrimpnet.gej.petM This user is from outside of this forum
                          markasspandi@shrimpnet.gej.pet
                          wrote sidst redigeret af
                          #73

                          @JadedBlueEyes It started off okay, mostly because they said it was a proof of concept and an experiment, but then I saw that "it is arguably one of the most secure ways to deploy a homeserver today" and just
                          lmfao

                          jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote sidst redigeret af
                            #74

                            @JadedBlueEyes

                            "build a serverless home server" is the most fucking brainrot, dipshit, nonsense thing ive read in a while

                            1 Reply Last reply
                            0
                            • markasspandi@shrimpnet.gej.petM markasspandi@shrimpnet.gej.pet

                              @JadedBlueEyes It started off okay, mostly because they said it was a proof of concept and an experiment, but then I saw that "it is arguably one of the most secure ways to deploy a homeserver today" and just
                              lmfao

                              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                              jadedblueeyes@tech.lgbt
                              wrote sidst redigeret af
                              #75

                              @MarkAssPandi They updated the text

                              1 Reply Last reply
                              0
                              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                Oh look, they’re trying to cover up what they did too

                                https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                Archive link for posterity:

                                https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbt
                                wrote sidst redigeret af
                                #76

                                For those coming in now, they updated the blog post to include a disclaimer. Original post:
                                https://archive.is/AbxU5

                                jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                                0
                                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                  Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                  https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                  swags@social.treehouse.systemsS This user is from outside of this forum
                                  swags@social.treehouse.systemsS This user is from outside of this forum
                                  swags@social.treehouse.systems
                                  wrote sidst redigeret af
                                  #77

                                  @JadedBlueEyes Serverless is exactly how matrix shouldve been built anyway. Cuz I dont wanna use this crap anymore.

                                  1 Reply Last reply
                                  0
                                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                    This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

                                    They just have TODO comments, and happily accept anything, even if it's blatantly forged

                                    goopadrew@infosec.exchangeG This user is from outside of this forum
                                    goopadrew@infosec.exchangeG This user is from outside of this forum
                                    goopadrew@infosec.exchange
                                    wrote sidst redigeret af
                                    #78

                                    @JadedBlueEyes lol, "unknown error" should imply the existence of a known error

                                    1 Reply Last reply
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                      https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                      gudenau@hachyderm.ioG This user is from outside of this forum
                                      gudenau@hachyderm.ioG This user is from outside of this forum
                                      gudenau@hachyderm.io
                                      wrote sidst redigeret af
                                      #79

                                      @JadedBlueEyes I know someone Tibet works there that has openly admitted to changing their workflow to `while (testsFailing()) doLlmSlop()` and it really shows.

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        For those coming in now, they updated the blog post to include a disclaimer. Original post:
                                        https://archive.is/AbxU5

                                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                        jadedblueeyes@tech.lgbt
                                        wrote sidst redigeret af
                                        #80

                                        [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

                                        jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                                        0
                                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                          [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

                                          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                          jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                          jadedblueeyes@tech.lgbt
                                          wrote sidst redigeret af
                                          #81

                                          https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

                                          Quoting from one of my chat rooms:

                                          > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

                                          authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

                                          > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

                                          YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

                                          jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper