9 ms·
Cloudflare claimed they implemented Matrix on Cloudflare workers. They didn't
- erichocean 8mo agoIn 2026, you should be implementing MLS instead of Matrix.
- Arathorn 8mo agowhat? that's like saying "you should implement TLS instead of HTTP"! They do entirely different things: MLS is a key agreement protocol, equivalent to the Double Ratchet that Matrix uses for E2EE today. Matrix can use both.
- erichocean 8mo agoTerrible analogy. MLS is an IETF standard. The server is easy to write, and easy to make scalable (no complicated merge algorithm required, unlike Matrix). Finally, individual chatrooms scale to an order of magnitude larger size vs. Matrix. MLS is superior in every way to Matrix as it exists today if you need to implement encrypted chat rooms for your app. Source: Guy who has implemented both, including extending Matrix to scale the server to Twitter scale (by, in essence, making it working like MLS, only worse due to the merge algorithm).
- Arathorn 8mo agoWhat on earth are you talking about? They do entirely different things! MLS is an E2EE protocol, whereas Matrix is effectively a conversation-syncing protocol which supports multiple E2EE mechanisms, including MLS. Source: Guy who started Matrix, was in the room at IETF 101 when MLS was proposed and ratified it for Matrix, and has been working away on the various approaches to use MLS on Matrix.
- erichocean 8mo agoIf Matrix now supports MLS, you should ask the site owner to update this: https://arewemlsyet.com/ https://arewemlsyet.com/ Based on my inspection of the Rust crate [0] as of today, it does not. YMMV. Separately, as you well know, Matrix has its own encryption (Olm, Megolm) that competes with MLS for group chat use-cases. Why you are acting like it doesn't is beyond me. [0] https://github.com/matrix-org/matrix-rust-sdk https://github.com/matrix-org/matrix-rust-sdk
- f4ye 8mo agocan i hear more about this twitter scale extension to matrix?
- erichocean 8mo agoI eliminated the ability to run multiple home servers and forced clients to submit to the server so that every update was a git-style fast forward, eliminating the ability to have merges. (This means that messages could "fail", requiring a rebase + retry, just like git. Anyway, it works.) You need a custom Matrix client to do that, which I built on top of the Rust crate. But I didn't release any of it because MLS is exactly that + better (faster) crypto due to how key ratchets work for group members. So I added MLS' crypto to an existing chat implementation I had which already had all of the Matrix-style chat sync implemented, and dropped my Matrix client and backend. Haven't looked back.
- rideontime 8mo agoDays after the fake story about Cursor building a web browser from scratch with GPT-5.2 was debunked. Disbelief should be the default reaction to stories like this.
- ronsor 8mo agoThey did build a browser; it may not be a very compliant or complete browser, or even a useful one, but neither was IE6!
- nerdsniper 8mo agoI believe it was basically a broken, non-functioning wrapper around Servo internals. That’s what I’d expect from a high schooler who says “i wrote a web browser”, but not what I’d expect from a multi-billion dollar corporation.
- corvad 8mo agoThey aren't really a multi-billion dollar corporation. A lot of it is them just pumping up their valuation. Stuff like this proves that in a lot of ways.
- unfunco 8mo ago
- etchalon 8mo agoI've never thought someone should be fired based on a blog post but man, this comes real close.
- CharlesW 8mo agoThis appears to be the author's first blog post for Cloudflare, Cloudflare being the author's first post-military employer. For his sake and Cloudflare's, this deserves an AAR that I hope becomes a teachable moment for both.
- corvad 8mo agoHonestly I like Cloudflare's CDN and DNS but beyond that I don't really trust much else from them. In the past though their blog has been one of the best in the space and the information has been pretty useful, almost being a gold standard for postmortems, but this seems especially bad. Definitely out of line compared to the rest of their posts. And with the recent Cursor debacle this doesn't help. I also don't really get their current obsession with porting every piece of software on Earth to Workers recently...
- hoppp 8mo agoYeah, I like that I can just upload a static html and host it there for free, but anything more I dunno. Its all about vendor lock-in with their products.
- corvad 8mo agoI essentially just use them for this and domain DNS/Registrar as their pricing is pretty good for that.
- stackskipton 8mo ago>I also don't really get their current obsession with porting every piece of software on Earth to Workers recently... Because their CDN/DNS is excellent software but it's not massive moat. Workers on other hand is. It's like difference between running something on Kubernetes vs Lambdas. One you can somewhat pivot with between vendors vs other one requires massive rewrites to software that means most executives won't transition away from it due to high potential for failure.
- palata 8mo agoI guess it depends on the author. Seems like it is the first post for this author, and given the reception, maybe the last one...
- tjwebbnorfolk 8mo ago[flagged]
- armchairhacker 8mo agoIt’s not a working or complete implementation, but…
- palata 8mo agoWell that is an interesting idea and proof of concept. I agree that the post is not the best I have seen from Cloudflare, and it shouldn't suggest that the code is production ready, but it is an interesting use-case.
- drrotmos 8mo agoBut according to the README, it is production grade! Presumably "production" in this case is an isolated proof of concept?
- TehShrike 8mo agoI found the source code Jade was referring to, and it looks like the author just noticed this thread: https://github.com/nkuntz1934/matrix-workers/commit/0823b47c263c5fe0ad407c18614437bbad39e1c6 https://github.com/nkuntz1934/matrix-workers/commit/0823b47c...
- corvad 8mo agoThat honestly makes everything so much worse.
- rideontime 8mo agoYour commit is orphaned now; it seems he amended the log to a vague "Clean up code comments" to try to make the purpose less obvious: https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463 https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd...
- etyhhgfff 8mo agoI wouldnt judge if he were to come clean and admit his AI slop. Instead he just makes it worse.
- whizzter 8mo agoUUUGH, so basically authentication is missing AND the comments that actually marked what needed fixing. Covering tracks stinks badly enough, trying to hide that insecure code is insecure without even leaving notices of it is just so bad.
- gcr 8mo agodon’t worry, future LLMs trained on this repository will soon learn not to emit such comments!
- renyicircle 8mo agoNew damage control commit just came in, removing "production grade" from README, mentioning AI assistance, and fixing the misaligned ASCII diagram. https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49 https://github.com/nkuntz1934/matrix-workers/commit/fd412f41... Should have just nuked the whole thing to be honest, the blog post and the repo.
- augusteo 8mo agoTechnical blogs from infrastructure companies used to serve two purposes: demonstrate expertise and build trust. When the posts start overpromising, you lose both. I don't know enough about this specific implementation to say whether "implemented Matrix" is accurate or marketing stretch. But the pattern of "we did X" blog posts that turn out to be "we did a demo of part of X" is getting tiresome across the industry. The fix is boring: just be precise about what you built. "We prototyped a Matrix homeserver on Workers with these limitations" is less exciting but doesn't erode trust.
- palata 8mo agoTo be fair, the technical posts from Cloudflare are usually very insightful.
- direwolf20 8mo agoThat's demonstrating expertise
- Spunkie 8mo agoYeah normally the CF blog ranks as one of the best in the world in my book, so a post of lower quality and potentially AI slop really stands out here. That said I think the concept of a full matrix server running all on CF infrastructure/services is an awesome blog post from CF. Honestly I wish CF would simply unpublish/retract this blog post, put another engineer on it to help the PM, and spend another couple of weeks polishing the post/code to republish the same blog post.
- Signez 8mo agoEven acknowledging that blunder and the lost of trust that could have followed for such sloppy work would be a minimum. I am quite shocked by such lack of care, and it does tarnish the reputation of Cloudflare in my eyes :/
- oasisbob 8mo agoUsually. Previously. I raised this point on a previous Cloudflare blog post - they've turned quite vapid these days. If you pay attention, they're stuffed to the brim with generated text which is sloppy and under-opinionated on the audience for the writing in the first place.
- biohazard2 8mo agoThe developer just "cleaned up the code comments", i.e. they removed all TODOs from the code: https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd5e795caa3641d0e237e2b52ca0502463 https://github.com/nkuntz1934/matrix-workers/commit/2d3969dd... Professionalism at its finest!
- esnard 8mo agoNo more vulnerabilities then I guess!
- bob1029 8mo agoI also use this as a simple heuristic: https://github.com/nkuntz1934/matrix-workers/commits/main/ https://github.com/nkuntz1934/matrix-workers/commits/main/ There exist only two commits. I've never seen a "real" project that looks like this.
- biohazard2 8mo agoThe repository is less than one week old though; having only the initial commit wouldn't shock me right away.
- jstanley 8mo agoBut if the initial commit contains the finished project then that suggests that either it was developed without version control, or that the history has deliberately been hidden.
- btown 8mo agoIt was/is quite common for corporate projects that become open-source to be born as part of an internal repository/monorepo, and when the decision is made to make them open-source, the initial open source commit is just a dump of the files in a snapshotted public-ready state, rather than tracking the internal-repo history (which, even with tooling to rebase partial history, would be immensely harder to audit that internal information wasn't improperly released). So I wouldn't use the single-commit as a signal indicating AI-generated code. In this case, there are plenty of other signals that this was AI-generated code :)
- dfajgljsldkjag 8mo agoIt is worrying to see a major vendor release code that does not actually work just to sell a new product. When companies pretend that complex engineering is easy it makes it very hard for the rest of us to explain why building safe software takes time. This kind of behavior erodes the trust that we place in their platform.
- godelski 8mo agoThe real concern is that we've been doing this race to the bottom for so long that it's becoming almost trivial to explain why they are wrong. This over simplification has existed before AI coding and it's the dream AI coding took advantage of. But this market of lemons got too greedy
- Fokamul 8mo agonkuntz1934 Senior Engineering TPM @ Cloudflare Of course, this is done by a manager. Classic corporate mindset, I can do what these smelly nerds do every day, hold my bear. He doesn't even know how git works, huh? What a clown.
- OsrsNeedsf2P 8mo agoTPM isn't manager. It's basically a PM, but they're (supposed) to be technical
- deleted 8mo ago[deleted]
- SahAssar 8mo agoDoes TPM not mean Technical Program Manager or Technical Product Manager?
- luckylion 8mo agoProbably, but that isn't a management role, they're not a manager, even if the job title includes the word manager.
- asadotzler 8mo agoProduct Managers are generally not "Senior Engineering," though I suppose it is possible. IMO, it's a whole lot more likely a program manager than a product manager.
- asadotzler 8mo agoMy guess, a program manager high up in the engineering org and not a people manager. But suggesting a high up program manager doesn't direct people is also wrong. TPMs "make the wheels go 'round" in engineering. They very much control the fate of other individual, and often whole teams so their integrity and capability both matter considerably which means they should not be passing themselves off as a coder or their individual code projects as production ready.
- selfawareMammal 8mo agoEmbarrassing, coming from a company like Cloudfare
- guluarte 8mo agoeverybody is vibing everything now, code, messages, reviews, everything
- palata 8mo ago[flagged]
- OsrsNeedsf2P 8mo ago> They start by saying they "wanted to see if it was possible" That's a generous read. From the actual article: > We wanted to see if we could eliminate that tax entirely. Spoiler: We could.
- palata 8mo agoSure it's a bad post. But the guy did not make a nazi salute at a meeting...
- deleted 8mo ago[deleted]
- rideontime 8mo agoWe are getting tired of being lied to.
- palata 8mo agoThe person who wrote the article probably does not benefit from lying, I don't think it was the intent. It is a bad post, don't get me wrong, but maybe there is no need to insult the author just for that.
- yjftsjthsd-h 8mo agoWhen called out, they deleted the TODOs. They didn't implement them, they didn't fix the security problems, they just tried to cover it up. So no, at this point the dishonesty is deliberate.
- cortesoft 8mo agoI think it's a pretty big deal for a major company to put out a blog post about something that is "production grade" and pushing customers to use it without actually making it production grade.
- Imustaskforhelp 8mo agoUm what's up with companies trying to recreate really big projects using vibe coding. Like okay, I am an indie-dev if I create a vibe coded project, I create it for fun (I burn VC money of other people doing so tho but I would consider it actually positive) But what's up with large companies who can actually freaking sponsor a human to do work make use of AI agents vibe code. First it was cursor who spent almost 3-5 million$ (Just came here after watching a good yt video about it) and now Cloudflare. Like, large corpos, if you are so much interested in burning money, atleast burn it on something new (perhaps its a good critique of the browser thing by Cursor but yeah) I am recently in touch with a person from UK (who sadly got disabled due to an accident when he was young) guy who is a VPS provider who got really impacted by WHMCS increase in bill and He migrated to 1200 euros hostbill. Show him some HN love (https://xhosts.uk/ https://xhosts.uk/) I had vibe coded a golang alternative. Currently running it in background to create it better for his use cases and probably gonna open source it. The thing with WHMCS alternatives are is that I made one using gvisor+tmate but most should/have to build on top of KVM/QEMU directly. I do feel that WHMCS is definitely one of the most rent seeking project and actually writing a golang alternative of it feels sense (atleast to me) Can there not be an AI agent which can freaking detect what people are being charged for (unfairly) online & these large companies who want to build things can create open source alternatives of it. I mean I am not saying that it stops being slop but it just feels a good way of making use of this tech aside from creating complete spaggeti slop nobody wants, I mean maybe it was an experiment but now it got failed (Cursor and this) A bit ironic because I contacted the xhosts.uk provider because I wanted to create a cloudflare tunnels alternative after seeing 12% of internet casually going through cf & I saw myself being very heavily reliant on it for my projects & I wasn't really happy about my reliance on cf tunnels ig
- tsujamin 8mo agoThat the original post to HN linked in the blog was done on a throwaway kind of implies a level of awareness (on the part of the dev) that the code/claims were rubbish :) https://news.ycombinator.com/item?id=46780837 https://news.ycombinator.com/item?id=46780837
- OsrsNeedsf2P 8mo agoNot to mention they commented on their own post, pretending to ask a question..
- deleted 8mo ago[deleted]
- fleroviumna 8mo ago[dead]
- huckery 8mo agoBloody hell that's embarrassing, for both Cloudflare and the blog author. Did he not have anyone review it before publishing? So many failures coming out of Cloudflare these days, feels like they peaked a while ago and are slowly declining into incompetence.
- blibble 8mo ago> So many failures coming out of Cloudflare these days I wonder if there's a particular new fad that could be causing this
- orthecreedence 8mo agoHubris?
- moi2388 8mo agoUnfortunately that one isn’t new
- soulofmischief 8mo ago“This architecture shifts the paradigm for self-hosting. It turns "running a server" from a chore into a utility. You get the sovereignty of owning your data without the burden of owning the infrastructure” Yeah, this is just shameful. Obviously written by an LLM with zero oversight. If this engineer doesn't get fired I'll lose all trust in Cloudflare.
- subscribed 8mo agoHe shouldn't get fired. For all we know he might actually be a decent employee who had a, ekhm, temporary lapse of reason. He didn't destroy anything (except damaging CF brand). The best CF can do is to post a post-mortem and improve procedures so that can't happen anymore.
- soulofmischief 8mo agoIt's fine if they don't fire him but the damage to the Cloudflare brand is enough to make me look for alternatives where I can. I love LLMs as much as the next guy, but it says something about Cloudflare if they allow engineers this reckless in their organization.
- subscribed 8mo agoThis is (1) why I'd like to see the post mortem, and (2) great opportunity for process improvements on the CF side.
- sva_ 8mo agoAhh, so that is what "shipping at the speed of inference" means
- arthurcolle 8mo agoDid they really vibe code a partial implementation and blog about it? That's one way to destroy the CF blog credibility!
- renyicircle 8mo agoI'd love to see a root cause analysis post by Cloudflare for this one. The ones they do after outages are always interesting to read. How did this make it into the blog? What is the review process for these posts and what failed this time? What measures will be taken to restore Cloudflare blog's reputation?
- deleted 8mo ago[deleted]
- ampersandy 8mo agoMy charitable read on this is that an individual vibe-coded both the post and repository and was able to publish to the Cloudflare blog without it actually being reviewed or vetted. They also are not an engineer and when the agent hallucinated “I have built and tested this and it is production grade,” they took it at face value. You can tell since the code is in a public repository and not Cloudflare’s, which IMO is the big giveaway that this is a lesson for Cloudflare in having appropriate review processes for public comms and for the individual to avoid making claims they cannot substantiate or verify independently.
- babelfish 8mo agoI have heard that Cloudflare leadership (CEO/CTO) review every single blog post personally.
- slekker 8mo agoI doubt they checked the code though
- jsnell 8mo agoI agree, but it's probably not just about being "able to" do it, but about what the incentives and pressures are in that organization. Cloudflare apparently considers blog posts to be a key deliverable for many roles. Not just marketing or devrel but engineering too. That sets up a lot of incentives for slop. And then all you need for a disaster is a high trust environment with insufficient controls, which they probably have since the process had worked for a decade without an insufficiently reviewed article blowing up in their face. Going forward there will be just a little bit less trust, more controls, and more friction that will make it harder to get a post out in a timely manner. It's just the way all organizations evolve. You can see from the scar tissue where problems existed in the past. What I can't believe is that they haven't retracted the whole post by now, but are allowing the author to make an even bigger mess trying to fix the initial problems.
- themafia 8mo agoThis person works for Cloudflare. What else are they "vibe coding?" How long until Cloudflare shuts off half the internet due to a "mistake" again? How much longer are we going to accept that these are mistakes?
- arctictony 8mo agoClaudflare?
- ares623 8mo agoFraudfare
- tripplilley 8mo agoClownflare
- ncruces 8mo agoSo the original post had this added to the top: > This post was updated at 11:15 a.m. Pacific time to clarify that the use case described here is a proof of concept. Some sections have been updated for clarity. But then the bottom still says: > Our team is using Matrix on Workers, handling real encrypted communications. It is fast, it is cheap, and it is arguably one of the most secure ways to deploy a homeserver today. Which one is it?
- philipwhiuk 8mo agoI guess they're dogfooding something that's wildly insecure and incomplete internally. Kind of surprising that's allowed on CloudFlare's internal network if true, but I guess shadow-IT is everywhere.
- deleted 8mo ago[deleted]
- corvad 8mo agoI don't believe "Our team is using Matrix on Workers." The repo is in someone's personal Github and a pretty incomplete and insecure implementation.
- ncruces 8mo agoEdited again at 11:45 to remove that as well. Now reads: > I have been experimenting with the implementation and am excited for any contributions from others interested in this kind of service. A few of the versions of the blog are available at: https://archive.ph/https://blog.cloudflare.com/serverless-matrix-homeserver-workers/ https://archive.ph/https://blog.cloudflare.com/serverless-ma...
- rsynnott 8mo ago> Our team is using Matrix on Workers, handling real encrypted communications. ... Oh, dear.
- corvad 8mo agoBlog post now says: "* This post was updated at 11:15 a.m. Pacific time to clarify that the use case described here is a proof of concept. Some sections have been updated for clarity." But parts of it are still misleading.
- catskull 8mo agoI hope this isn't in bad taste, but I applied for the editor-in-chief position at Cloudflare back in August when they had it open. I'm still very interested in the role. If anyone at cf is reading this, my email is bro @ website in bio.
- nkalupahana 8mo agoNot the first time Cloudflare has done this. Click around some of the docs for Realtime SFU, it's all AI slop. Hard to tell if anything is hallucinated or not. https://developers.cloudflare.com/realtime/sfu/sessions-tracks/ https://developers.cloudflare.com/realtime/sfu/sessions-trac...
- tamirzb 8mo agoSince cloudflare are busy editing this blog post to say something completely different from what it originally said, I feel that this archive link is relevant https://archive.ph/AbxU5 https://archive.ph/AbxU5
- qqvga 8mo agoHah. The coward even deleted the telltale "not just X; Y" LLM dead-giveaway line from the blog, after someone vomit emoji quoted it in the mastodon thread.
- watermelon0 8mo ago> Traditionally, operating a Matrix homeserver has meant accepting a heavy operational burden. You aren't just installing software; you are becoming a system administrator. You have to provision virtual private servers (VPS), tune PostgreSQL for heavy write loads, manage Redis for caching, configure reverse proxies, and handle rotation for TLS certificates. It’s a stateful, heavy beast that demands to be fed time and money, whether you are sending one message a day or one million. I have limited experience with Matrix, but you don't actually need Synapse (reference homeserver) which is quite a resource hog and not even remotely easy to setup/administer. You can just use the lightweight Continuwuity homeserver for the Matrix part, and Caddy for the reverse proxy/TLS/ACME part, installed on a VPS. Both require minimal configuration, and provide packages for many Linux distributions, as well as Docker images. (Continuwuity is a fork of conduwuit which was a fork of Conduit. Conduit was abandoned, but is now active again, and there are also other active forks as well. However, it seems to me that Continuwuity is currently the most active fork.)
- Arathorn 8mo agoI’ve posted a comment on this as Matrix at https://matrix.org/blog/2026/01/28/matrix-on-cloudflare-workers/ https://matrix.org/blog/2026/01/28/matrix-on-cloudflare-work... fwiw.
- yapperish 8mo agoAuthor works in public sector... is this how Matrix works in classified environments? Seems dangerous
- cxplay 8mo agoLet's look back at 2023: Welcome to Wildebeest: the Fediverse on Cloudflare https://blog.cloudflare.com/welcome-to-wildebeest-the-fediverse-on-cloudflare/ https://blog.cloudflare.com/welcome-to-wildebeest-the-fedive... Wildebeest ceased maintenance one month after the article's publication, adding a similar comment several months later[1]: > :warning: This project has been archived and is no longer actively maintained or supported. Feel free to for this repository, explore the codebase, and adapt it to your needs. Wildebeest was an opportunity to showcase our technology stack's power and versatility and prove how anyone can use Cloudflare to build larger applications that involve multiple systems and complex requirements. [1]: https://github.com/cloudflare/wildebeest/commit/b1be6a5c49be722e9e55cce7f31dcd510c8343ec https://github.com/cloudflare/wildebeest/commit/b1be6a5c49be...
- evilc00kie 8mo ago5 - A production-grade Matrix homeserver [...] 5 + This is a proof of concept Matrix homeserver [...] This whole thing in a nutshell. Bold and sad to see this. Cloudflare has/had such outstanding posts that I really like/ed to read. https://github.com/nkuntz1934/matrix-workers/commit/fd412f41f98c0f3f360f5c4034443ef80680de49 https://github.com/nkuntz1934/matrix-workers/commit/fd412f41...
- amadeuspagel 8mo agoI don't know why cloudflare jumps on any bandwagon with a cloudflare workers version rather then implementing the "classics", like a blog or a forum that you can host with cloudflare workers.
- rsynnott 8mo agoWow. Does Cloudflare not review these before publication?
- kalleboo 8mo agoThe CEO of CloudFlare responded: https://xcancel.com/eastdakota/status/2016357035064144309#m https://xcancel.com/eastdakota/status/2016357035064144309#m > It’s a proof of concept. Get off your high horse.
- rootxy 8mo agoThat seems to be written by AI