filecoin-project / notary-governance

114 stars 58 forks source link

Notary Application:SECUREXPERTS Inc. #164

Closed DarnellWashington closed 3 years ago

DarnellWashington commented 3 years ago

Notary Application

To apply as a notary, please fill out the following form.

Core Information

Please respond to the questions below in pargraph form, replacing the text saying "Please answer here". Include as much detail as you can in your answer!

Long Term Network Alignment

Time Commitment

Describe the nature and duration of your affiliation with the Filecoin project. Please include relevant Github handles, miner ids, significant projects or contributions (with links).

None

Stake Exposure

Please cite total token at stake (currently available, locked as collateral, vesting over time) and any substantiating evidence.

I don't want to disclose.

Industry Reputation

In-protocol Reputation

Please describe (in detail) your activity and tenure as a member of the Filecoin community. Please note (with links where possible) any contributions made to implementations of Filecoin, the spec, documentation, or to substantially help the Filecoin ecosystem grow.

No contribution has been done. But, as a data security expert, I hope to increase credibility to the community, and give the community a boost.

In-protocol Security

Please describe your contributions to the security of Filecoin and the duration over which you've made contributions. Please also include any links or references who might be able to substantiate your contributions (e.g. if you've filed several bugs, please cite who you've communicated with on the Filecoin side).

None

External Reputation

Please describe the nature of your organization, including the country of registration, size of the organization, and time since inception.

My name is Darnell Washington, the president of SECUREXPERTS, INCORPORATED. I have consulted with over 22 federal agencies and provide subject matter expertise for architecture and infrastructure components establishing Standard Operating Architecture and Common Secure Infrastructure Operating Architecture policy, compliance, governance, and Communications Security for Enterprise applications, including consolidation, server virtualization, operations and maintenance, and deployment of wired and wireless applications. Manage and develop procedures for oversight of Disaster Recovery and Continuity Operations of mission critical unclassified applications, and Data Center consolidation and migrations to secure facilities.
Subject matter expert for training state and local law enforcement and public safety officials nationally on securing information technology/enterprise network based communication from vulnerabilities and exploitation. Instruct Federal law enforcement agencies on protecting information, communication, and maintaining operational security of public safety and classified networks. Conduct tactical demonstration of secure network products comprising of voice, video, and data applications for emergency and mobile wireless communications.
Principal developer and inventor of patented secure enterprise video surveillance product integrating encrypted PKI based security technology with enterprise database security for the Department of Homeland Security and Department of Defense applications. Market products and services to the following industries, Banking/finance, Education, Homeland Security, Military, Medical, Gaming, retail, industrial, and government.
As an organization, SecureXperts, Incorporated, "SXI", founded in 2001 by a team of industry experts in cybersecurity, is recognized as an industry leader in the evaluation of cyber security posture for cyber-physical systems used in critical infrastructure protection such as the energy and power grid industrial control systems, healthcare, law enforcement and financial sectors to name a few.-----SecureXperts is an information security technology and consulting firm that enables organizations to generate more revenue by reducing the opportunity for information theft, improper disclosure, malicious activity, abuse, and destruction.

Please share any relevant details to help substantiate information about your organization (website, named officers, links to social media profiles).

Website:https://securexperts.com/
Linkedin:https://www.linkedin.com/company/securexperts-incorporated
Facebook:https://www.facebook.com/securexperts.inc/about/

Please share any relevant external information regarding your organization (e.g. news articles, social media profiles, etc.)

https://www.apollo.io/companies/SECUREXPERTS--INCORPORATED/5a9e681ba6da98d95ff9a359?chart=count
https://securityofficerhq.com/agency/securexperts-incorporated-4046935100
https://www.zoominfo.com/c/securexperts-inc/66569033

Diversity and Decentralization

Use Case Diversity

(Optional) Any additional information you'd like to share about the use case(s) you plan to support?

Technological related documentation, video, audio, etc. especially focus on data emergency processing technology and mobile wireless communication technology, intellectual property technology,Filecoin application tecnnology.

Allocation Plan

Concreteness of Allocation Plan

Allocation Strategy

How do you plan on allocating the DataCap requested above? Please describe your allocation strategy with as much specificity as you can.

As long as the client meets the use case scenario and has data property rights as well as the data is real and public available, we are willing to grant the request.
We will approve more and more DataCap with the number of applications times.
The first time will be 1T, the second 2T and the third 4T...Each time will be doubled as the previous one but the total amount for one client shall not exceed 50% of my own.

Are there any internal processes you plan on impelementing regarding the target, amount, or rate at which you'll allocate DataCap?

We will check the application twice a week.
Once receiving the application, we will organize a three-person team to conduct vetting and client due diligence. When all team members agreed , we will file an application for the person in charge to allocate DataCap who has access of private key.

How do you plan on securing the DataCap to ensure your organization (and its delegated members) are the ones allocating the DataCap?

Our hardware wallet is kept by the person in charge.

Client Due Diligence

How will you vet your Client to ensure they are spending that DataCap responsibly?

After each application DataCap is used up, we will ask the applicant to provide a detailed description of the useage, including the miner ID, proportion of the storage, the timestamp, the query way of the stored data, the data content and so on.

What questions will you ask to ensure the Client can properly handle the DataCap you intend to allocate to them?

1.Please describe you and your organization.
2.Whether you fit the use case?
(Use Cases: Technological related documentation, video, audio, etc. especially focus on data emergency processing technology and mobile wireless communication technology, intellectual property technology,Filecoin application tecnnology)
3.Please describe the data you need to store: amount/source/type/property conditions.
4.What is the relationship between your business and the data to be stored?
5.Is your data public available? How could other people retrive it?
6.What is your allocation proportion to each miner? How will you find them?
7.Do you agree to disclose  the transaction?

What processes will you employ to confirm that a Client is not improperly over-allocating DataCap to a single entity?

In our allocation strategy, each client is required to allocate no more than 80% of the total allocation per miner ID.
The question includes a question about allocation proportion, and if the client is not willing to disclose, the application will not be approved.
We require the client to make the data to be stored public, and if the client does not agree, the application is not approved.
Before the next application, the client is required to disclose transaction information.
We will also follow up the approved clients every week. Once I find any non-compliance operation, I will communicate with the client immediately. If necessary, I will ask for official assistance to retrieve the DataCap allocated.

Bookkeeping Plan

Do you plan on keeping records of your allocation decisions? If so, with what level of specificity do you intend to respond to any audit requests?

Yes, we will keep all records, consisting of clients' name, DataCap allocation, and usage,etc.

Do you plan on conduct your allocation decisions in public (e.g. Github repo), private (e.g. over email, Telegram, etc), or both?

Our allocation process and decisions will be made public on GitHub.

Track Record

Past allocation

Have you previously received DataCap to allocate before? If so, please link to any previous applications.

None

Cumulatively, how much DataCap have you previously successfully allocated?

None

Have there been (or are there still) any disputes raised against you from your previous DataCap allocations?

None
dkkapur commented 3 years ago

Hi @DarnellWashington - thanks for submitting your application to be a Notary! The initially scored rubric can be found here: https://docs.google.com/spreadsheets/d/1owmSQwLZlokiCAE6cW20EMBE6g9G8O6BmT7IimgvlVg/edit?usp=sharing

Please take a look at the notes (column I) and share any relevant additional details here in comments so we can update your score ideally within the next 2 days.

Your initial unrounded score is: 0.9.

dkkapur commented 3 years ago

@DarnellWashington - final scores for this election cycle are:

The final scores therefore for this election cycle are:

Link to the rubric: https://docs.google.com/spreadsheets/d/1owmSQwLZlokiCAE6cW20EMBE6g9G8O6BmT7IimgvlVg/edit?usp=sharing

dkkapur commented 3 years ago

@DarnellWashington - based on this Notary election cycle's final scoring, you/your organization has qualified to be a Fil+ Notary! Per your application and the scored rubric, you will be receiving an allocation of 10 TiB (qualified for 10 TiB based on rubric scoring). In order to confirm your participation as a Notary in the Fil+ ecosystem, please respond to the following:

  1. Please confirm that the region of operation for client applications you will focus on is [North America]

  2. Please confirm each of the following items below (you can do this by quoting each of the following bullets and adding a line under each section agreeing that you'll abide by these operational principles.

  • Upfront Disclosures: Prior to being confirmed as a Notary, Notaries are expected to disclose all relevant addresses which they control, have a financial stake in, or are strongly connected to by other means. For the disclosure, the Notary should state the relevant addresses and the nature of the relationship

  • Promoting Client Best Practices: Notaries agree to educate approved clients about the best practices for using their DataCap (e.g. how to request additional services from miners, storing data redundantly across many miners, etc). Some reference information can be found here.

  • Commitment to efficiently serving the Network: Notaries agree to serve as fiduciaries of the Network, striving to work towards bringing useful data onto Filecoin and improving the experience for clients to do so. Notaries should generally be able to respond to Client applications and updates within 3 days, and should be comfortable communicating with Clients and Notaries if an application needs to be redirected.

  • No Self Dealing: To prevent conflicts of interest, Notaries should not allocate DataCap to Clients over which they control the private keys, or to a Client who intends to specifically spend the allocated DataCap with an address affiliated with the Notary. When in doubt, Notaries should bias towards transparency (i.e. public disclosure) or to getting a different Notary to handle the individual request.

  • Operating in Good Faith: Notaries hold a position of trust in the network, and as such it is expected that they operate keeping the Principles of this mechanism in mind. While each form of abuse cannot be exhaustively defined, Notaries are expected to bias towards caution and act in a way that promotes transparency. Notaries should expect to potentially receive requests or questions for allocation decisions (within reason) - and should make decisions with this in mind.

  • Community Governance Participation: It is expected that Notaries make an effort to regularly attend the scheduled Governance calls. As these calls are a forum to shape this process, it is important to ensure Notaries are present to provide their context, learnings, and input.

  1. Please list any addresses you are affiliated with, and state the nature of the relationship. Please refer to the first bullet point in (2) for the definition of "affiliated", and bias towards transparency when in doubt.

  2. Please affirm that you will abide by the allocation / client due diligence plan you laid out above.

  3. (If ready) Please confirm the address that should receive DataCap. This is the address which you will use to sign messages on-chain to verify clients (through using a Ledger and the Fil+ Registry App). If you have an active (non-zero) DataCap grant from a previous election cycle, please provide a different address here.

DarnellWashington commented 3 years ago
  1. Confirmed.
  2. Upfront Disclosures Confirmed. Promoting Client Best Practices Confirmed. Commitment to efficiently serving the Network Confirmed. No Self Dealing Confirmed. Operating in Good Faith Confirmed. Community Governance Participation Confirmed.
  3. None
  4. I will abide by the allocation / client due dilig ence plan we laid out above.
  5. f1bjdcjxha3ldcstw5zmvkyu3r2p5x2bsm745kgsi
dkkapur commented 3 years ago

Request Approved

Address

f1bjdcjxha3ldcstw5zmvkyu3r2p5x2bsm745kgsi

Datacap Allocated

10TiB

filecoin-plus-bot commented 3 years ago

The request has been signed by a new Root Key Holder

Message sent to Filecoin Network

bafy2bzacebbkwov3e66lqocuonn7vlvbir3cxum63eiuzj7vr2owofcf5zjje

You can check the status of the message here: https://filfox.info/en/message/bafy2bzacebbkwov3e66lqocuonn7vlvbir3cxum63eiuzj7vr2owofcf5zjje

filecoin-plus-bot commented 3 years ago

The request has been signed by a new Root Key Holder

Message sent to Filecoin Network

bafy2bzacecm3bg2nbza4hjmv3sbzx6aabmq774xoypazgabiu5zk6goujorpo

@dkkapur There was an error processing the message >bafy2bzacecm3bg2nbza4hjmv3sbzx6aabmq774xoypazgabiu5zk6goujorpo

You can check the status of the message here: https://filfox.info/en/message/bafy2bzacecm3bg2nbza4hjmv3sbzx6aabmq774xoypazgabiu5zk6goujorpo

dkkapur commented 3 years ago

This grant seems to have gone through correctly and should not be in Error status. Fixing this now!

DarnellWashington commented 2 years ago

Notary Ledger Verified

Message sent to Filecoin Network

message CID: bafy2bzacebjehrmcs2svbiqkrptuzeq4qi26sde5slojjgcry7hyqkjtkwlr6

You can check the status of the message here: https://filfox.info/en/message/bafy2bzacebjehrmcs2svbiqkrptuzeq4qi26sde5slojjgcry7hyqkjtkwlr6