Cloudflare published a blog post claiming to have built a production-ready Matrix homeserver on Workers, allegedly porting the Rust-based Tuwunel server. Investigation reveals the project is actually AI-generated TypeScript code with critical security flaws: missing authentication checks, no state resolution, unimplemented
Table of contents
Initial reception ¶Breaking down the Cloudflare blog post ¶Let's take a look at the code ¶The ensuing cover-up ¶Conclusion ¶The response from the Matrix.org Foundation ¶Actual conclusion ¶Sort: