Anonymizing User's Position Information
Proposal Details
Description
There were [extensive and heated debates regarding the disclosure of users' wallets with their current positions](https://decentraland.org/governance/proposal/?id=32ab78a0-1cda-11ed-96c7-2fa07c6df25b). Ultimately, the decision was made to maintain open data, leading to the emergence of new wallet analytics apps in Decentraland. However, the fact that anyone could get a detailed analytic dashboard with users names and activity for any wallet raised concerns about data privacy breaches, causing discomfort and preoccupation about privacy safeguards.
Voting Rationale
Exposing user behavior is undesirable. We must balance open data with protecting user information.
Vote NO as I didn't received answer on my question!
Anonymizing User's Position Information This proposal is now in status: REJECTED. Voting Results: * Yes 40% 3,539,453 VP (68 votes) * No 60% 5,172,435 VP (13 votes) * Abstain 0% 0 VP (0 votes)
I didn’t mean to say that there will be an only allowed version built by the foundation. The point here is that as nose owner, with an open protocol and open source code there is no way to guarantee that the owner cannot access the data and collect it. What we are discussing here is about publicly exposing user wallets and positions which enable the public user behavior analytics.
Thank you for this HP, changing my vote to NO.
The Foundation proposing this while collecting metrics on everyone is really a joke :slight_smile: [quote="paralax, post:8, topic:22434"] However, as a node owner, you wouldn’t be using the allowed version of the catalyst node. If such manipulation is detected, a DAO poll could be conducted to take down the node. [/quote] Enforcing a single "Foundation version" is very dangerous =) (also, if you modify your catalyst, you can modify it in such a way it reports the correct docker hash while not using that docker image) > `We must balance open data with protecting user information.` "open data for us for not for you" It will make keeping track of unique users visiting parcels harder and make accountability for grantees nearly impossible.
sorry, I didn't see your question before and I missed it, didn't mean to avoid your question. I'm uncertain if I grasp the concern entirely. The services won't disclose the data, and the published service version won't inherently expose any of these metrics. If you host a catalyst, it's entirely open-source, and there's always a way for the potential for manipulation. However, as a node owner, you wouldn't be using the allowed version of the catalyst node. If such manipulation is detected, a DAO poll could be conducted to take down the node.
Can you clarify please how the proposal manages the risk of data access centralization ?
You still have access to user profiles as it is public, and if there's a need to validate a game interaction between a specific user and their location, a new endpoint will be provided for that purpose and nothing else will change.
So will game makers have access to the wallet on the client side to prevent abuse/exploitation from certain wallets? @paralax
What @HPrivakos mentions is correct. The session ids won't be preserved in history and there will be one new per session.
As far as I understand, it would be anonymizing the user address only on the catalyst endpoint (https://peer.kyllian.me/comms/peers for example), not the one in world. It might cause some changes in the POAP dispenser for example as instead of just checking the user address, the user will have to send their new session ID to the server so it can verify the user position against a catalyst.
Would there be a new ID generated upon each visit? Or would the user retain the same ID throughout their history of visits the parcel? I ask because this could raise a security issue for game makers who need to ban certain players for exploitation/breach of game terms.
11 Comments