Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
103 Indlæg 71 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • joepie91@fedi.slightly.techJ joepie91@fedi.slightly.tech

    @JadedBlueEyes This is almost a minor criticism in comparison to all the other crap, but I am so sick of companies calling things 'serverless' when what they really mean is "servers, but only ours and they're really opaquely billed and impossible to replace with someone else's servers so you're stuck with us, and also they're managed in a totally custom way so none of your normal sysadmin skills are portable to it but you still have to learn how to manage it"

    flesh@transfem.socialF This user is from outside of this forum
    flesh@transfem.socialF This user is from outside of this forum
    flesh@transfem.social
    wrote sidst redigeret af
    #71

    @joepie91@fedi.slightly.tech @JadedBlueEyes@tech.lgbt It seems minor in comparison, because we're so far down along the tracks, but it's still a line we never should have allowed to be crossed.

    1 Reply Last reply
    0
    • kieran@hom.phK kieran@hom.ph

      @JadedBlueEyes that'll fix it!

      airshipper@cloudisland.nzA This user is from outside of this forum
      airshipper@cloudisland.nzA This user is from outside of this forum
      airshipper@cloudisland.nz
      wrote sidst redigeret af
      #72

      @kieran @JadedBlueEyes addressed todos, ready to ship!

      1 Reply Last reply
      0
      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

        Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

        https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

        markasspandi@shrimpnet.gej.petM This user is from outside of this forum
        markasspandi@shrimpnet.gej.petM This user is from outside of this forum
        markasspandi@shrimpnet.gej.pet
        wrote sidst redigeret af
        #73

        @JadedBlueEyes It started off okay, mostly because they said it was a proof of concept and an experiment, but then I saw that "it is arguably one of the most secure ways to deploy a homeserver today" and just
        lmfao

        jadedblueeyes@tech.lgbtJ 1 Reply Last reply
        0
        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

          Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

          https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.social
          wrote sidst redigeret af
          #74

          @JadedBlueEyes

          "build a serverless home server" is the most fucking brainrot, dipshit, nonsense thing ive read in a while

          1 Reply Last reply
          0
          • markasspandi@shrimpnet.gej.petM markasspandi@shrimpnet.gej.pet

            @JadedBlueEyes It started off okay, mostly because they said it was a proof of concept and an experiment, but then I saw that "it is arguably one of the most secure ways to deploy a homeserver today" and just
            lmfao

            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbtJ This user is from outside of this forum
            jadedblueeyes@tech.lgbt
            wrote sidst redigeret af
            #75

            @MarkAssPandi They updated the text

            1 Reply Last reply
            0
            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

              Oh look, they’re trying to cover up what they did too

              https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

              Archive link for posterity:

              https://web.archive.org/web/*/https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463

              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbtJ This user is from outside of this forum
              jadedblueeyes@tech.lgbt
              wrote sidst redigeret af
              #76

              For those coming in now, they updated the blog post to include a disclaimer. Original post:
              https://archive.is/AbxU5

              jadedblueeyes@tech.lgbtJ 1 Reply Last reply
              0
              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                swags@social.treehouse.systemsS This user is from outside of this forum
                swags@social.treehouse.systemsS This user is from outside of this forum
                swags@social.treehouse.systems
                wrote sidst redigeret af
                #77

                @JadedBlueEyes Serverless is exactly how matrix shouldve been built anyway. Cuz I dont wanna use this crap anymore.

                1 Reply Last reply
                0
                • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                  This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

                  They just have TODO comments, and happily accept anything, even if it's blatantly forged

                  goopadrew@infosec.exchangeG This user is from outside of this forum
                  goopadrew@infosec.exchangeG This user is from outside of this forum
                  goopadrew@infosec.exchange
                  wrote sidst redigeret af
                  #78

                  @JadedBlueEyes lol, "unknown error" should imply the existence of a known error

                  1 Reply Last reply
                  0
                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                    gudenau@hachyderm.ioG This user is from outside of this forum
                    gudenau@hachyderm.ioG This user is from outside of this forum
                    gudenau@hachyderm.io
                    wrote sidst redigeret af
                    #79

                    @JadedBlueEyes I know someone Tibet works there that has openly admitted to changing their workflow to `while (testsFailing()) doLlmSlop()` and it really shows.

                    1 Reply Last reply
                    0
                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                      For those coming in now, they updated the blog post to include a disclaimer. Original post:
                      https://archive.is/AbxU5

                      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                      jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                      jadedblueeyes@tech.lgbt
                      wrote sidst redigeret af
                      #80

                      [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

                      jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                      0
                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                        [U-turn in the readme, too](https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49), and an employee trying to do damage control on lobsters too

                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                        jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                        jadedblueeyes@tech.lgbt
                        wrote sidst redigeret af
                        #81

                        https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

                        Quoting from one of my chat rooms:

                        > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

                        authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

                        > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

                        YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

                        jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                        0
                        • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                          This is a core part of the protocol, that's not exactly simple (https://spec.matrix.org/v1.17/server-server-api/#authorization-rules)

                          They just have TODO comments, and happily accept anything, even if it's blatantly forged

                          ricko@tech.lgbtR This user is from outside of this forum
                          ricko@tech.lgbtR This user is from outside of this forum
                          ricko@tech.lgbt
                          wrote sidst redigeret af
                          #82

                          @JadedBlueEyes Eeek. That || instead of ?? is just painful to see. Repeatedly.

                          At my previous company we had one of our mid-level devs fall into this trap last year. Ended up failing in production in almost exactly this type of scenario, where the dev expected an array or undefined, but got true.

                          I have to wonder if this is an artifact of the initial training for these systems being on Python, which doesn't have a strong equivalent for ??. And, you know, the fact that these things don't actually understand the code they generate, as much as anyone may claim otherwise.

                          1 Reply Last reply
                          0
                          • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                            Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                            https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                            chris_colvin@mastodon.socialC This user is from outside of this forum
                            chris_colvin@mastodon.socialC This user is from outside of this forum
                            chris_colvin@mastodon.social
                            wrote sidst redigeret af
                            #83

                            @JadedBlueEyes don't worry

                            "* This post was updated at 11:45 a.m. Pacific time to clarify that the use case described here is a proof of concept and a personal project. Some sections have been updated for clarity."

                            1 Reply Last reply
                            0
                            • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                              Oh and to top things off, they make trivially false claims in their post. Tuwunel and its predecessors do not and have never used Postgres or Redis.

                              h5e@tech.lgbtH This user is from outside of this forum
                              h5e@tech.lgbtH This user is from outside of this forum
                              h5e@tech.lgbt
                              wrote sidst redigeret af
                              #84

                              @JadedBlueEyes They updated their post, it now says Synapse instead of Tuwunel.

                              jadedblueeyes@tech.lgbtJ 1 Reply Last reply
                              0
                              • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                https://lobste.rs/s/csxfc6/cloudflare_claimed_they_implemented#c_gychiy

                                Quoting from one of my chat rooms:

                                > Distributed protocols get extra complex once cryptography and security get in the mix and without a domain expert

                                authentication isn't "extra complex", you literally removed signature checking. and hashes. And fucking authentication.

                                > ensure this handles the myriad of edge cases that regularly plague Matrix implementations

                                YOU REMOVED. AUTHENTICATION. THIS ISN'T SOME WEIRD EDGE CASE WITH STATE RESETS. YOU REMOVED AUTHENTICATION AND VALIDATION.

                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                jadedblueeyes@tech.lgbt
                                wrote sidst redigeret af
                                #85

                                I swear every iteration of the blogpost is somehow worse. No, your starting point wasn’t Synapse either. Your starting point was the claude opus chatbox

                                1 Reply Last reply
                                0
                                • h5e@tech.lgbtH h5e@tech.lgbt

                                  @JadedBlueEyes They updated their post, it now says Synapse instead of Tuwunel.

                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbtJ This user is from outside of this forum
                                  jadedblueeyes@tech.lgbt
                                  wrote sidst redigeret af
                                  #86

                                  @h5e https://tech.lgbt/@JadedBlueEyes/115968861622285804

                                  h5e@tech.lgbtH 1 Reply Last reply
                                  0
                                  • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                    Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                    https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                    amd@gts.amd.imA This user is from outside of this forum
                                    amd@gts.amd.imA This user is from outside of this forum
                                    amd@gts.amd.im
                                    wrote sidst redigeret af
                                    #87

                                    @JadedBlueEyes thank you for your work on continuwuity. An actually good matrix implementation.

                                    1 Reply Last reply
                                    0
                                    • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                      Cloudflare just published a vibe coded blog post claiming they implemented Matrix on cloudflare workers. They didn't, their post and README is AI generated and the code doesn't do any of the core parts of matrix that make it secure and interoperable. Instead it's littered with 'TODO: Check authorisation' and similar

                                      https://blog.cloudflare.com/serverless-matrix-homeserver-workers/

                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.social
                                      wrote sidst redigeret af
                                      #88

                                      @JadedBlueEyes lol

                                      1 Reply Last reply
                                      0
                                      • jadedblueeyes@tech.lgbtJ jadedblueeyes@tech.lgbt

                                        @h5e https://tech.lgbt/@JadedBlueEyes/115968861622285804

                                        h5e@tech.lgbtH This user is from outside of this forum
                                        h5e@tech.lgbtH This user is from outside of this forum
                                        h5e@tech.lgbt
                                        wrote sidst redigeret af
                                        #89

                                        @JadedBlueEyes oh sorry I missed that!

                                        h5e@tech.lgbtH 1 Reply Last reply
                                        0
                                        • h5e@tech.lgbtH h5e@tech.lgbt

                                          @JadedBlueEyes oh sorry I missed that!

                                          h5e@tech.lgbtH This user is from outside of this forum
                                          h5e@tech.lgbtH This user is from outside of this forum
                                          h5e@tech.lgbt
                                          wrote sidst redigeret af
                                          #90

                                          @JadedBlueEyes ah we posted around the same time. I did check 😅

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper