Open LiuZhuJunYa opened 7 months ago
Heya, thanks for your feedback. Yea, I got quite many reports that the required score is too high. I've lowered it to 5 on both instances now.
However, the number might still change. As of now it still seems a bit over-protective as the number of sessions dropped by more than 90% since activation of the minimal passport score 😅 Will keep an eye on it over the next days to collect more data & make a reasonable decision on the limit.
I present my own perspective as a blockchain research student:
Yep the best I could do is discord, google and linkedin account which got me around 2.5 points; all others require some sort of other interaction with the main network.
I've further lowered the required score to 2. This should really be easily achievable by just some social media accounts. At the end I don't want to exclude anyone from mining. The PoW stuff should still be the primary protection.
Regarding @LiuZhuJunYa's points:
Yea you can use the same accounts to sign stamps for multiple accounts, however, these points are only counted if the stamp hasn't been used for another account within the last 30 days. This deduplication is done on faucet side, so the faucet keeps track of which stamps have been used for previous sessions.
You're right, the PoW algorithm hasn't been compromised, but the sybil protection with captchas & IP checks has been compromised. There are public available tools out there that allow using my faucet with no user interaction and on a list of proxies. I can unfortunately also see that such tools are used a lot, it literally lead to tripling the mining activity just over the last 4 weeks. Farmers using such tools are luckily not very intelligent :D Spinning up like 100 sessions in seconds is quite obviously done from a automation tool and not a natural user activity. The holesky faucet has a fixed limit of 50k HolETH per day. I've constantly increased that limit over the last weeks according to the activity, so each session is still able to gather a meaningful amount. Unfortunately, I can't go higher than that to be able to keep the faucet online till the planned end of the network. The same applies to sepolia. So, to keep the faucet useful for normal users, I somehow have to limit the amount of bots & farmers. Obviously, I can't block them completely, but I can make farming with hundreds/thousands of addresses from cloud machines as hard as possible. If I wouldn't do that and just keep relying on the PoW protection, the mining rewards will become very very low at come time. End-users with normal computers or even mobile devices just can't compete against a fleet of extremely powerful cloud machines.
If anyone knows about captchas that are not covered by automated captcha resolvers like rucaptcha / 2captcha / ..., that'd be a suitable alternative to using passports. Unfortunately I haven't found one yet.
I've further lowered the required score to 2. This should really be easily achievable by just some social media accounts. At the end I don't want to exclude anyone from mining. The PoW stuff should still be the primary protection.
Regarding @LiuZhuJunYa's points:
- Yea you can use the same accounts to sign stamps for multiple accounts, however, these points are only counted if the stamp hasn't been used for another account within the last 30 days. This deduplication is done on faucet side, so the faucet keeps track of which stamps have been used for previous sessions.
- You're right, the PoW algorithm hasn't been compromised, but the sybil protection with captchas & IP checks has been compromised. There are public available tools out there that allow using my faucet with no user interaction and on a list of proxies. I can unfortunately also see that such tools are used a lot, it literally lead to tripling the mining activity just over the last 4 weeks. Farmers using such tools are luckily not very intelligent :D Spinning up like 100 sessions in seconds is quite obviously done from a automation tool and not a natural user activity. The holesky faucet has a fixed limit of 50k HolETH per day. I've constantly increased that limit over the last weeks according to the activity, so each session is still able to gather a meaningful amount. Unfortunately, I can't go higher than that to be able to keep the faucet online till the planned end of the network. The same applies to sepolia. So, to keep the faucet useful for normal users, I somehow have to limit the amount of bots & farmers. Obviously, I can't block them completely, but I can make farming with hundreds/thousands of addresses from cloud machines as hard as possible. If I wouldn't do that and just keep relying on the PoW protection, the mining rewards will become very very low at come time. End-users with normal computers or even mobile devices just can't compete against a fleet of extremely powerful cloud machines.
thanks a lot mate <3 <3 <3
@LiuZhuJunYa can you please do me a favor and remove that link from your post? :D Yea, it is one of the tools I'm talking about, it's obviously available with some research, but I don't think it should be liked here...
What puzzles me is why they would engage in such work that is "all harm and no benefit," since these currencies are only for test sites and do not possess real value.
Yea, that's the core problem :( I see two reasons for that:
It could be all soo much easier if testnets are really used for testing only.
Thank you for your reply, and I wish you all the best!
Your feedback is welcome :)
I really try to make the faucet more user friendly and not just more complex to use. The new limitation I've introduced is obviously annoying, but I've seen the farmer problem getting out of control, which directly affects regular miners as the mining rewards got lower and lower.
I see from the feedback and session numbers that the score of 10 was way too high to start with and I appreciate that feedback. I'll further monitor the situation for further adjustments, but also open for alternative Ideas :)
Hi @pk910 holesky faucet is having issues, sepolia faucet is just working fine.
In the homepage it's showing just 2 passport score is required but here it's showing 10. Also my IP seems to be blocked , no issues with sepolia faucet so it has to be something with the website right, not using any proxy or vpn btw.
worst idea ever
worst idea ever
Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.
worst idea ever
Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.
Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.
worst idea ever
Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.
Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.
Dude all you have to do is just sign up for Discord , LinkedIn and Google to get a passport score of 2. You can sign up for them with just temp accounts and use them for passport verification.
worst idea ever
Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.
Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.
you understand that what you said is the definition of sybil and gitcoin does nothing to prevent the bots, so it is useless right?
worst idea ever
Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.
Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.
you understand that what you said is the definition of sybil and gitcoin does nothing to prevent the bots, so it is useless right?
Isn't that what the whole above discussion was about ? Still something is better than nothing right.
The combination of various protection methods is the key here. The gitcoin passport alone doesn't prevent sybils, especially as the required score of 2 is very low. Mining alone also doesn't prevent sybils. Even with Captchas and IP based restrictions, the number of bots constantly increased over time.
The combination of both (mining & passport) works very nice at the moment, because the passport lowers the number of eligable addresses from basically unlimited to a semi-limited amount, just because farmers have to put in some effort to make an address eligible for mining (registering fake accounts, etc). At the same time it doesn't affect regular users that much as everyone should be able to reach such a low passport score.
Tbh. I'm aware that this step won't protect the faucet from bots forever, but it's temporarily very effective. I'm sure farmers are already preparing hundreds if not thousands account to make them eligible for mining. And I'm looking forward to make that effort useless again once I see the bot activity raising again.
I'll revise the changes once the bot problem gets out of control again. I've quite a few methods and changes in the pipeline to piss off farmers, and I'll continue activating them on purpose.
Apart from that, I'm very sorry for any regular user that get's locked out due to my protection efforts. That's really not the plan, but if users have to compete against a fleet of bots, the mining rewards gets so low that the faucet is unusable for everyone.
Tbh it affects me who I am not a sybil, bot and just a regular user who doesn't want to use a service like gitcoin and just wants to mine some tokens to test out services. I think you might be just lazy to implement your own criteria like connect with twitter+discord+telegram or email (or whatever) than use gitcoin or maybe gitcoin pays you.
I completely agree with those who have voiced concerns regarding the use of Passport as it does not function well and could act as a barrier to those who are new to crypto. Personally, I have been unable to get several stamps despite years of use that can be easily verified. Discussions with Passport support have been useless, and as someone who has been involved with cryptocurrency for many years, I question how new community members will deal with such unnecessary complexity, and forsee it as detrimental to overall blockchain development and adoption.
I think it was to hard for me, I am just a beginner in Web 3. I tried my best and could only achieve about 1 point.