filecoin-project / notary-governance

113 stars 55 forks source link

Modification: Retroactive Upgrade of Notary Onboarding Process and KYC Verification #856

Closed herrehesse closed 2 weeks ago

herrehesse commented 1 year ago

Introduction:

The Filecoin+ ecosystem is constantly evolving, and as we move towards greater adoption, higher quality and a more mature ecosystem, we must ensure that our governance processes are robust and secure. However, recent incidents of identity theft and other fraudulent activities have highlighted the need for a more stringent and comprehensive notary onboarding process.

Proposal:

To address these concerns and increase the quality of the notary onboarding process retroactively, we propose that every active V4 notary should undergo an in-depth KYC process. This will ensure that all notaries in the ecosystem are thoroughly vetted and verified, and that recent incidents of fraud and identity theft can be prevented in the future.

Implementation:

To ensure the highest standards of security and trust in this process, we propose that the KYC verification process be handled by Veriff, a leading KYC company with extensive experience in this field. Veriff has a proven track record of providing secure and reliable KYC verification services, and we believe that they are the ideal partner to assist with this process.

We also propose that measures be put in place to enable the subsequent accountability of notaries for their actions and the companies they work for. The governance framework should be updated to ensure that notaries are held responsible for any fraudulent or illegal activities that they may engage in. This will include potential penalties for any wrongdoing. Holding notaries accountable by their actual identities will make it easier to identify and hold responsible any bad actors who may be attempting to engage in fraudulent activities. This measure will greatly enhance the overall security and trustworthiness of the Filecoin+ ecosystem by eliminating the ability to hide behind anonymous accounts and pseudonyms.

Potential measures:

Timeline:

We propose that this process be initiated as soon as possible to ensure that all active V4 notaries are verified and vetted retroactively. The timeline for this process will be determined by the FIL+ governance team and Veriff, based on their capacity and availability, but we aim to complete the process within a reasonable timeframe to minimize any further disruptions to the ecosystem.

Conclusion:

By upgrading the notary onboarding process retroactively and upholding every active V4 notary to take part in an in-depth KYC process, we can ensure that the Filecoin+ ecosystem remains secure and trusted. This proposal is essential to build trust during the transition from quantity to quality in the Filecoin+ ecosystem. We believe that this proposal will help to mitigate the risks of identity theft and fraud in the future, and we strongly recommend its adoption by the community.

raghavrmadya commented 1 year ago

The T&T WG is supportive of this proposal but would like to flag caution on using a single entity for KYC without doing an open call/community consensus to reach the vendor. There are interesting learnings on doing a pilot-driven KYC vendor selection process that has been led by @kevzak

If we want to implement this in the next election cycle, we should start the vendor discovery and selection process now led by either a notary WG led by @panges2 or a collaboration between an assigned DRI and the T&T WG