CrimeFlare using Large Lying Models to write their code now

https://github.com/cloudflare/workers-oauth-provider?tab=readme-ov-file#written-using-claude

"Written using Claude [...] Every line was thoroughly reviewed and cross-referenced with relevant RFCs, by security experts with previous experience with those RFCs"

Meanwhile - CVE-2025-4143 - https://github.com/advisories/GHSA-4pc9-x2fx-p7vj

"Readers who are familiar with OAuth may recognize that failing to check redirect URIs against the allowed list is a well-known, basic mistake, covered extensively in the RFC and elsewhere. The author of this library would like everyone to know that he was, in fact, well-aware of this requirement, thought about it a lot while designing the library, and then, somehow, forgot to actually make sure the check was in the code. That is, it's not that he didn't know what he was doing, it's that he knew what he was doing but flubbed it."

🔥🔥🔥🔥🔥

#CloudFlare #LLM

GitHub - cloudflare/workers-oauth-provider: OAuth provider library for Cloudflare Workers

OAuth provider library for Cloudflare Workers. Contribute to cloudflare/workers-oauth-provider development by creating an account on GitHub.

GitHub

Nachrichten in TV & Radio schalte ich schon lange ab, selektive Berichterstattung, vermengt mit zu viel Meinung, nicht nur bei der Meldungsauswahl - gefällt mir nicht. Setze auf freie Kanäle diverser (inter)nationaler Nachrichtenagenturen sowie Newsaggregatoren wie #newstral - aber deren Seite kann ich seit Kurzem durch den Einsatz von #cloudflare für das #captcha nicht mehr aufrufen. Schade. Erfreulich hingegen, daß wider Erwarten viele Online Zeitungen #RSSfeed anbieten 😁

#vpn #dnsblocking

🚀💸 It's a cosmic comedy! NASA's #budget is now a 🤡 #circus act, while trying to access the details feels like navigating a virtual minefield guarded by #Cloudflare ninjas. Who knew that understanding government funding would require a degree in cybersecurity? 🔒😂
https://badastronomy.beehiiv.com/p/trump-threatens-to-eviscerate-nasa-cb96 #NASA #Comedy #Cybersecurity #HackerNews #ngated
Trump threatens to eviscerate NASA

The Presidential budget proposal is a death sentence for the space agency

Bad Astronomy Newsletter
Mike #Kuketz entlarvt Teil 7 Noch immer verbreitet er den Bullshit, dass #Signal #MetaDaten schützen würde Der gesamte Traffic der #SignalApp läuft über die Clouds von #Google, #Amazon, #Microsoft & #Cloudflare und die können jeden über die IP de-anonymisieren Siehe: nostr.band/note154hta9d...
🌕 GitHub - cloudflare/workers-oauth-provider:Cloudflare Workers 的 OAuth 提供者函式庫
➤ 為 Cloudflare Workers 帶來簡潔安全的 OAuth 2.1 解決方案
https://github.com/cloudflare/workers-oauth-provider/
這個 GitHub 倉庫提供了一個 TypeScript 函式庫,用於在 Cloudflare Workers 上實作 OAuth 2.1 協定,支援 PKCE。它簡化了 API 端點的授權流程,自動處理權杖管理,並允許開發者以標準的 fetch handler 方式撰寫 API 處理程式。該函式庫不與特定使用者管理或 UI 框架綁定,且儲存機制僅儲存密碼的雜湊值,確保安全性。目前處於測試階段,API 可能會變更。
+ 這個函式庫看起來很方便,能省去自己實作 OAuth 流程的麻煩,尤其對在 Cloudflare Workers 上開發 API 的人來
#開發者工具 #OAuth 2.1 #Cloudflare Workers
GitHub - cloudflare/workers-oauth-provider: OAuth provider library for Cloudflare Workers

OAuth provider library for Cloudflare Workers. Contribute to cloudflare/workers-oauth-provider development by creating an account on GitHub.

GitHub

"NOOOOOOOO!!!! You can't just use an LLM to write an auth library!"

"haha gpus go brrr"

https://github.com/cloudflare/workers-oauth-provider/?tab=readme-ov-file#written-using-claude

#AI #CloudFlare #oAuth #Claude #GPUsGoBrrr #LLM

Looking at my snac status for debugging landlock, I've seen quite some 403 errors. It seems cloudflare doesn't like the snac user agent? (If I attribute that typical phrase correctly)
Well I don't like cloudflare, so we're good I think.

|sort|uniq -c
337 https://furry.engineer/inbox (403 Forbidden) [<!DOCTYPE html><html lang="en-US"><head><title>Just a moment
91 https://gimmeloli.cc/inbox (403 Forbidden) [<!DOCTYPE html><html lang="en-US"><head><title>Just a moment
169 https://pawb.fun/inbox (403 Forbidden) [<!DOCTYPE html><html lang="en-US"><head><title>Just a moment
116 https://pixelfed.social/f/inbox (403 Forbidden) [<!DOCTYPE html><html lang="en-US"><head><title>Just a moment
#cloudflare #Snac2 #snac #federation
@zeh I agree with the idea that using cloudflare is not a really good idea on several aspects, thus my post.
It did help me on some occasions (but also generated some issues when applying too strict rules), for example last month an ecommerce website I manage was suddenly attacked by AI bots that managed to push the server CPU to its limits. Activating the anti AI bot feature in Cloudflare helped to contain the attack that last about 20 minutes.
However, despite those handy tools, I'm willing to stop using it, thus my interest in hearing what others use (I was especially interested in hearing people who use Bunny to manage their DNS).
#dns #cloudflare

Speaking of vindictiveness, if I had money and there was a subscription service that could punish CloudFlare the company every time I either can't go to a website because of CloudFlare or have to deal with some hostile BS because of CloudFlare, I would surely pay to do so. (In this hypothetical scenario where I have money.)

If #CloudFlare wasn't destroying the internet for people with older devices, linux, and/or accessibility needs, I wouldn't have this much of a vendetta against it.

But here we are. Net being destroyed site by site by a large and unaccountable service.

(Not interested in hearing about A.I. scrapers. Other anti-A.I. scraping tools have demonstrated that it's possible to ruin A.I. scrapers' days without ruining accessibility. Anubis isn't an example of that. Their "proof of work" stuff requires a modern JavaScript capable and enabled browser, damaging older devices' access and probably causing accessibility issues. I wouldn't dare say they were "just as bad" as CloudFlare but they're not meeting any of the needs I'm referring to here.)

#Fedify 1.6 is approaching with three major enhancements: RFC 9421 HTTP Message Signatures support with double-knocking for seamless backward compatibility, a new builder pattern for better code organization in large applications, and native #Cloudflare #Workers support for serverless deployments. These additions strengthen Fedify's standards compliance while expanding deployment flexibility across different environments. Stay tuned for the official release! 🚀

#ActivityPub #fedidev #fediverse #RFC9421 #CloudflareWorkers