Skip to content

Manage a bounty program for vulnerability reports

EnactedGovernance

Proposal Details

Author0x8795…26ed
PublishedJul 25, 2022 17:18
Voting beginsJul 25, 2022 17:18
Voting endsAug 08, 2022 17:18
Snapshot#fkreiem

Description

As the DAO owns the smart contracts and manages the development of the protocol, we are requesting to cover the rewards needed for every vulnerability found in the Decentraland bounty program. The Decentraland foundation is committed to triage, answering, and fixing every disclosure received. Every payment will be published publicly.

Voting Power

03M6MRequired to pass07/2507/2908/0108/0408/08
YesNo

8 Comments

daoSep 22, 2022

Manage a bounty program for vulnerability reports This proposal has been ENACTED by a DAO Committee Member (0xfe91c0c482e09600f2d1dbca10fd705bc6de60bc)

daoAug 08, 2022

Manage a bounty program for vulnerability reports This proposal is now in status: PASSED. Voting Results: * Yes 100% 7,520,426 VP (87 votes) * No 0% 0 VP (0 votes)

DrGreenthumbAug 08, 2022

Much needed these have been proven to work well. Thought i already voted yes and commented.

ckbubblesJul 26, 2022

Thanks for your response, and glad to know this will be considered! I do think this is super important and needs to exist, so I wish y'all luck with the program!!

CanessaJul 26, 2022

As a land owner I voted yes on this proposal because I can't think of anything more important than protecting our smart contracts. We need incentives large enough to encourage those to have found vulnerabilities within the system to report them.

NachoJul 26, 2022

Hi! Thanks for raising this point. The DAO won't be forced to pay rewards if they consider that the treasury is being compromised. It is hard to estimate how many reports are we going to have and pay but we are conscious that every development must be audited until goes to production. I think that if we start having too many valid reports per day, we will need to slow down the development and improve the quality. How we can mitigate this? well, I believe that the DAO will stop sending the funds and raise its voice to have a better development process.

ckbubblesJul 26, 2022

Hey I am so for this program existing. I even voted yes and asked a few questions on the original poll. But before this gets passed — I would like to call attention to this being a **governance proposal** and not a grant proposal, meaning once it is approved it is binding forever, as I understand. I am curious to know the allocation of funds, and if there are caps per year? I understand and believe in the importance of these bounty programs, but what stops them from draining all the dao funds if there are multiple threats? Hopefully not, but how do we mitigate this possibly scenario? Or do you have data from previous bugs to show that this wouldn't be an issue? Sorry if I'm stuck on the wrong issue here, but would like to know how this will be handled before I vote, but thanks for all you do!

FrankJul 25, 2022

I voted YES because I believe there is nothing more important than ensuring the security and stability of our platform. By incentivizing security researchers with appropriate bounties, I believe this will both: 1) Prevent those with knowledge of exploits from taking advantage of them. 2) Encourage well qualified individuals to audit the smart contracts. Best wishes with this proposal.