Open
Description
Maximize privacy of Decred stakeholders and users. Remove or minimize fingerprinting in our infrastructure.
VSPs
- remove recaptcha from VSPs (privacy: Self-host CAPTCHA decred/dcrstakepool#279)wait for VSPs to upgrade to recaptcha fix (VSP self-hosted captcha upgrade progress decred/dcrstakepool#326)eliminate per-account address reuse (Eliminate address reuse decred/dcrstakepool#311)
- ~1/4 DCR reuse voting address (rough est.)
- related: Accountless VSPs (Accountless VSP #100)
- some improvements are possible even without fully removing accounts
derive new fee address for every ticket (Derive a new fee address for every ticket. decred/dcrstakepool#504)make email optional (privacy: Make email optional decred/dcrstakepool#274)- ~20 VSP entities have email identities of ~1/4 DCR (rough est.)
- most disposable email services changed to force accounts and javascript => fingerprinting increased
Politeia
- make email optional (Make email optional decred/politeia#554)ensure Pi works via Tor and TorBrowser (all use cases starting from signup)
Riot, Matrix
- remove recaptcha from Riot registration form for matrix.decred.org (should be possible according to this doc)use Matrix onboarding page to warn about recaptcha enabled for matrix.org homeserver (until it is fixed)research and eliminate Riot "calling home" to default identity server
- the default identity server is at matrix.org or riot.im
- requests are sent to it even when "identity server" field was cleared on the registration form
self-host Riot web app (Self-host Riot #62)
Other
- More mirrors for release binaries
- currently all users hit GitHub (Amazon? CloudFlare?) to download new binaries
- file archive (File archive #26) would help here
Related:
- Make email optional everywhere (Email optional everywhere #22)
Metadata
Metadata
Assignees
Labels
Type
Projects
Milestone
Relationships
Development
No branches or pull requests
Activity
[-]Fingerprinting of stakeholders[/-][+]Fingerprinting of stakeholders' browsers[/+][-]Fingerprinting of stakeholders' browsers[/-][+]Stop fingerprinting of stakeholders' browsers[/+][-]Stop fingerprinting of stakeholders' browsers[/-][+]Maximize stakeholder's privacy[/+]xaur commentedon Jul 8, 2019
decred/dcrwallet#1471 is a patch to "allow the automatic ticket buyer to derive unique voting addresses in sequence, avoiding address reuse".
[-]Maximize stakeholder's privacy[/-][+]Maximize stakeholder privacy[/+]