Erkan-Yilmaz / Gridcoin-tasks

tasks, wishes, ideas, ... for the Gridcoin project
26 stars 1 forks source link

Ensure that team founder roles are in the hands of trusted community members for whitelisted projects #55

Open Erkan-Yilmaz opened 7 years ago

Erkan-Yilmaz commented 7 years ago

see forum: 3 projects are currently "not in our hands"

a little above the post by @grctest: "has rejected team founder transfers and is an unknown entity. This should be considered a security concern as the user can kick users at will (manipulating the reward calculation) and see team members email addresses!

We should get in contact with the SRBASE project administrator immediately regarding a forced transfer of this position to a more trusted/known individual."

grctest commented 7 years ago

We should likewise verify that the user 'gridcoin' for each BOINC project is in fact Rob Halford.. these nickname fields are not unique, so it's possible that 'gridcoin' may be an unauthorized user.

Projects with confirmed team founder issues:

grctest commented 7 years ago

Further information!

I'm team founder for the following 4 projects:

2 are run by community members:

The rest are run by Rob, or user 'Gridcoin' (unknown if all 'Gridcoin' users are actually Rob..)


We should look into BOINC-wide team registration.

grctest commented 7 years ago

Why is this an issue?

The unapproved/unknown users with team founder rights have the ability to manipulate the DPOR reward mechanism by kicking users from the individual project's team gridcoin & can extract the team's email addresses (95% don't hide their email).


Food for thought

If the mandatory team membership requirement was removed in the future, the ability for team founders to manipulate the reward mechanism would be eliminated - the email privacy concern would remain (however users can hide their email or switch team/leave the team if hiding email isn't possible).

NeuralMiner commented 7 years ago

I'm team founder on two projects: Numberfields@Home VGTU