gridcoin-community / Gridcoin-Tasks

Gridcoin community tasks repository
https://gridcoin.us
MIT License
24 stars 5 forks source link

Ensure that team founder roles are in the hands of trusted community members for whitelisted projects #58

Closed skcin closed 5 years ago

skcin commented 7 years ago

Issue by Erkan-Yilmaz Tuesday Jan 24, 2017 at 00:23 GMT Originally opened as https://github.com/Erkan-Yilmaz/Gridcoin-tasks/issues/55


see forum: 3 projects are currently "not in our hands"

a little above the post by @grctest: "has rejected team founder transfers and is an unknown entity. This should be considered a security concern as the user can kick users at will (manipulating the reward calculation) and see team members email addresses!

We should get in contact with the SRBASE project administrator immediately regarding a forced transfer of this position to a more trusted/known individual."

skcin commented 7 years ago

Comment by grctest Tuesday Jan 24, 2017 at 11:17 GMT


We should likewise verify that the user 'gridcoin' for each BOINC project is in fact Rob Halford.. these nickname fields are not unique, so it's possible that 'gridcoin' may be an unauthorized user.

Projects with confirmed team founder issues:

skcin commented 7 years ago

Comment by grctest Tuesday Jan 24, 2017 at 11:31 GMT


Further information!

I'm team founder for the following 4 projects:

2 are run by community members:

The rest are run by Rob, or user 'Gridcoin' (unknown if all 'Gridcoin' users are actually Rob..)


We should look into BOINC-wide team registration.

skcin commented 7 years ago

Comment by grctest Tuesday Jan 24, 2017 at 11:37 GMT


Why is this an issue?

The unapproved/unknown users with team founder rights have the ability to manipulate the DPOR reward mechanism by kicking users from the individual project's team gridcoin & can extract the team's email addresses (95% don't hide their email).


Food for thought

If the mandatory team membership requirement was removed in the future, the ability for team founders to manipulate the reward mechanism would be eliminated - the email privacy concern would remain (however users can hide their email or switch team/leave the team if hiding email isn't possible).

skcin commented 7 years ago

Comment by NeuralMiner Thursday Mar 16, 2017 at 16:38 GMT


I'm team founder on two projects: Numberfields@Home VGTU