Repository navigation
DIP #14- Spoof Assets #14
Description
Activity
First of all, I think this issue should be solved.
Second, we need more ideas because the specification that requires curation in the asset listing process involves complicated UX.
How about stopping reward withdrawal until fulfilled certain conditions?
For example, until passed the curate - In this case, it becomes can be applied for curate when DEV equivalent to ETH to be deposited to list has accumulated. (This idea implies an automatic sale of DEV, so that would be unfavorable for security.)
Reacted by Scott GHi,
Dev users wouldn't need to interact with a Kleros interface. They could submit/challenge/appeal in a Dev interface.
You can see a curate interface here. It allows to interact with curate TCRs, but you can perfectly have your own specific frontend allowing Dev users to interact without leaving the Dev frontend.By being displayed both in a Dev frontend and a Kleros one, we could expect members of both communities to interact with it.
Reacted by Scott G, Mayumi, aggre and MattReacted by Mayumi and MattWhile I do believe that we need to move forward with DIP 9 and remove rewards for unverified assets. I think at the current time Kleros brings a bigger barrier to entry and will hurt initial user growth. We dont know the extent of spoofed assets at this current time and the amount of gas cost to create a property cuts into the profitability of spoofing assets. Our goal at the current time is onboarding new users and asking them to not only pay the gas fees for a new property, but also put down a deposit, will deter many potential users from joining. I think the best plan of action for the moment is push forward dip 9 but hold off on any third party protocols until our user base is larger.
Reacted by aggre and Akira TaniguchiHi @clesaege, thanks for the information! It's nice to have a seamless experience available.
I'm still exploring ideas because barriers as a mandatory requirement make it difficult for newcomers.
@calaber24p I agree with you. Ideally, it's an algorithm where creators get paid appropriately, whether they're lying or telling the truth.
For reference, a lesser-known concept, the concept of authentication fee is built-in. In the current Policy, the authentication fee is zero until the total number of assets exceeds 10000. The authentication fee is paid by burning DEV, and discounted for properties that already have a sufficient amount of staking.
Reacted by calaber24p"Ideally, it's an algorithm where creators get paid appropriately, whether they're lying or telling the truth."
Comment from DIP #9 on using Web 2.0 Metrics in an algorithm to determine spoof assets:
There's a flaw with using downloads x staking as a weighted average. Staking and downloads are highly correlated since users have a bias to support large projects. This ultimately becomes a network effect on Dev Protocol as seen by Chalk. Therefore, successful attackers could have a lot of DEV staked from unknowing stakers which will get them approved in your formula. The proposal put forward would allow effective bad actors to be accepted and non effective bad actors to be rejected.@defi-er Yes, I think using Web 2.0 metrics is a bad idea. The ideal is to be optimized with tokenomics instead of relying on oracle.
Second, we need more ideas because the specification that requires curation in the asset listing process involves complicated UX.
In addition, curate has an SDK for interacting from the dev UI -> https://gtcr-sdk.readthedocs.io/en/latest/. For now it is only for reading data but we can add more features to ease development.
Reacted by Scott GAnother solution would be for the team to handpick which projects join, stake for them, and allow the projects' creators to authenticate to redeem rewards. Upon authentication the general community will be allowed to stake for these projects.
Reacted by aggre- addedcoreCore features of Dev ProtocolCore features of Dev Protocol
on Oct 15, 2020
What is a spoof asset?
A spoof asset is an authenticated asset that has no intrinsic value and is meant to deceive the community and protocol in order to generate rewards. For example, currently, a "creator" could generate npmjs repos with one line of code and become an authenticated asset on Stakes Social.
Why are spoof assets bad?
Potential solution for spoof assets?
A potential solution to mitigate spoof assets is to implement Kleros Curate. Kleros Curate uses the Kleros protocol to organize information. Other uses cases for this product are exchange listings, fake news, or marketplace products. For more information on how it works click here --->: Kleros Curate blog post. Verified assets/creators will receive a badge once Kleros' network of jurors approve the submission.
Potential Issues?
Kleros requires submitters to deposit ETH for the submission. If they are accepted then they will get the ETH back. If they lose then the ETH is used as a fee to pay for the jurors. If creators apply then this decreases the UX experience and creates more gas prices. If the Dev Protocol paid for the ETH then this could open an attack vector to drain company finances.
Submitters will have to interact with the Kleros protocol to submit evidence
All assets must get approved in Curate before being listed on Dev Protocol which will increase the time to launch for creators.
Unpopular Solution?
Admin keys.