Skip to content

Anonymizing User's Position Information

RejectedDraft

Proposal Details

Author0xb878…a672
PublishedMay 03, 2024 17:25
Voting beginsMay 03, 2024 17:25
Voting endsMay 10, 2024 17:25
Snapshot#ad57ebd

Description

There were [extensive and heated debates regarding the disclosure of users' wallets with their current positions](https://decentraland.org/governance/proposal/?id=32ab78a0-1cda-11ed-96c7-2fa07c6df25b). Ultimately, the decision was made to maintain open data, leading to the emergence of new wallet analytics apps in Decentraland. However, the fact that anyone could get a detailed analytic dashboard with users names and activity for any wallet raised concerns about data privacy breaches, causing discomfort and preoccupation about privacy safeguards.

Voting Rationale

0xC8b5…7034Yes2,000,000

Exposing user behavior is undesirable. We must balance open data with protecting user information.

0x247e…b418No888,396

Vote NO as I didn't received answer on my question!

11 Comments

daoMay 10, 2024

Anonymizing User's Position Information This proposal is now in status: REJECTED. Voting Results: * Yes 40% 3,539,453 VP (68 votes) * No 60% 5,172,435 VP (13 votes) * Abstain 0% 0 VP (0 votes)

paralaxMay 10, 2024

I didn’t mean to say that there will be an only allowed version built by the foundation. The point here is that as nose owner, with an open protocol and open source code there is no way to guarantee that the owner cannot access the data and collect it. What we are discussing here is about publicly exposing user wallets and positions which enable the public user behavior analytics.

DedHeadJMay 10, 2024

Thank you for this HP, changing my vote to NO.

HPrivakosMay 10, 2024

The Foundation proposing this while collecting metrics on everyone is really a joke :slight_smile: [quote="paralax, post:8, topic:22434"] However, as a node owner, you wouldn’t be using the allowed version of the catalyst node. If such manipulation is detected, a DAO poll could be conducted to take down the node. [/quote] Enforcing a single "Foundation version" is very dangerous =) (also, if you modify your catalyst, you can modify it in such a way it reports the correct docker hash while not using that docker image) > `We must balance open data with protecting user information.` "open data for us for not for you" It will make keeping track of unique users visiting parcels harder and make accountability for grantees nearly impossible.

paralaxMay 10, 2024

sorry, I didn't see your question before and I missed it, didn't mean to avoid your question. I'm uncertain if I grasp the concern entirely. The services won't disclose the data, and the published service version won't inherently expose any of these metrics. If you host a catalyst, it's entirely open-source, and there's always a way for the potential for manipulation. However, as a node owner, you wouldn't be using the allowed version of the catalyst node. If such manipulation is detected, a DAO poll could be conducted to take down the node.

web3nitMay 07, 2024

Can you clarify please how the proposal manages the risk of data access centralization ?

paralaxMay 06, 2024

You still have access to user profiles as it is public, and if there's a need to validate a game interaction between a specific user and their location, a new endpoint will be provided for that purpose and nothing else will change.

NikkiFuegoMay 06, 2024

So will game makers have access to the wallet on the client side to prevent abuse/exploitation from certain wallets? @paralax

paralaxMay 06, 2024

What @HPrivakos mentions is correct. The session ids won't be preserved in history and there will be one new per session.

HPrivakosMay 05, 2024

As far as I understand, it would be anonymizing the user address only on the catalyst endpoint (https://peer.kyllian.me/comms/peers for example), not the one in world. It might cause some changes in the POAP dispenser for example as instead of just checking the user address, the user will have to send their new session ID to the server so it can verify the user position against a catalyst.

NikkiFuegoMay 04, 2024

Would there be a new ID generated upon each visit? Or would the user retain the same ID throughout their history of visits the parcel? I ask because this could raise a security issue for game makers who need to ban certain players for exploitation/breach of game terms.