Cloudflare published a blog post claiming to have built a production-ready Matrix homeserver on Workers, allegedly porting the Rust-based Tuwunel server. Investigation reveals the project is actually AI-generated TypeScript code with critical security flaws: missing authentication checks, no state resolution, unimplemented

30m read time From nexy.blog
Post cover image
Table of contents
Initial reception ¶Breaking down the Cloudflare blog post ¶Let's take a look at the code ¶The ensuing cover-up ¶Conclusion ¶The response from the Matrix.org Foundation ¶Actual conclusion ¶

Sort: