Skip to content

Manage Bounty program for vulnerability reports

PassedDraft

Proposal Details

Author0x8795…26ed
PublishedJul 15, 2022 19:05
Voting beginsJul 15, 2022 19:05
Voting endsJul 22, 2022 19:05
Snapshot#fkreihs

Description

As the DAO owns the smart contracts and manages the development of the protocol, we are requesting to cover the rewards needed for every vulnerability found in the Decentraland bounty program. The Decentraland foundation is committed to triage, answering, and fixing every disclosure received. Every payment will be published publicly.

Voting Power

00.5M1MRequired to pass07/1507/1707/1907/2007/22
YesNo

5 Comments

daoJul 22, 2022

Manage Bounty program for vulnerability reports This proposal is now in status: PASSED. Voting Results: * Yes 100% 2,727,944 VP (43 votes) * No 0% 0 VP (0 votes)

ZESTYBEAMJul 21, 2022

Nacho, Thanks for the reply with links to back it up. I was explaining the bug bounty program to some friends, who expressed an interest due to the payout amounts. The answers you've provided are more than enough to point them in the right direction, should they decide to pursue anything.

NachoJul 21, 2022

[quote="ZESTYBEAM, post:2, topic:13166"] How does one properly test a vulnerability in a safe manner, if exploitation isn’t allowed? Let’s pretend, for example, that a LAND contract vuln (Like the one discovered by BirdofParadise69) is found. Would it be acceptable to have 2 wallets (Let’s call them Wallet A and Wallet B), hold LAND in Wallet A, and test an exploit to transfer it to Wallet B? In that scenario, on-chain activity would be taking place, but the tester/bounty hunter would effectively be hacking themselves. [/quote] For smart contracts, [you can fork Mainnet with Hardhat and/or Tenderly](https://hardhat.org/hardhat-network/docs/guides/forking-other-networks). For websites you can run it locally and test it. > Is there a process by which the DAO can authorize or prevent the payment from happening? Or is that part of the service provided by [Immunefi](https://immunefi.com/bounty/decentraland/), so by approving the proposal, we are effectively agreeing to their arbitration? We agree on the SAB criteria/arbitration. Let me know if that answers your questions.

MatimioJul 21, 2022

Thanks for submission of this proposal @Nacho and for the work of the SAB. Question about the clause below, that could potentially be answered in the final binding governance proposal: [quote="dao, post:1, topic:13166"] the DAO is in charge of providing the funds needed once a confirmed bug report is reviewed and confirmed. So basically when a payment has to happen due to a valid report under the program, the Decentraland Foundation will inform DAO with case #, the recipient wallet address, and the amount to be paid and also, shall contact the SAB in order to fix the vulnerabilities disclosed. [/quote] Is there a process by which the DAO can authorize or prevent the payment from happening? Or is that part of the service provided by [Immunefi](https://immunefi.com/bounty/decentraland/), so by approving the proposal, we are effectively agreeing to their arbitration?

ZESTYBEAMJul 15, 2022

I personally love this proposal because bug bounty programs tend to be so hit or miss. I do have a question though. There's a line item in the ImmuneFi page: "Attacks that the reporter has already exploited themselves, leading to damage" How does one properly test a vulnerability in a safe manner, if exploitation isn't allowed? Let's pretend, for example, that a LAND contract vuln (Like the one discovered by BirdofParadise69) is found. Would it be acceptable to have 2 wallets (Let's call them Wallet A and Wallet B), hold LAND in Wallet A, and test an exploit to transfer it to Wallet B? In that scenario, on-chain activity would be taking place, but the tester/bounty hunter would effectively be hacking themselves. I didn't see this covered in the ImmuneFi page, so forgive me if I missed it. Again, my vote is a resounding YES, but I'm interested in having some discussion around this as well.