BSIP: Proposals Scam Prevention
- Dominant language
- No language data
- Stars
- 59
- Forks
- 86
- PR merge metrics
- No merged PRs in 30d
Description
```
BSIP: NOT YET ASSIGNED
Title: Proposals Scam Prevention
Authors: litepresence finitestate@tutamail.com
Status: [ Draft ]
Type: [ Protocol ]
Created: 2019-03-10
Discussion: NO URL
Replaces: Core Issue 1644
Superseded-By: None
Worker: None
```
Abstract
=============
There are rampant scam proposals being sent to lay users posing as official sources with fake official looking names to "upgrade accounts" or "improve security". The user believes the correct thing to do is accept the proposal. Shortly thereafter they realize they've agree to give all their funds away.
Motivation
=============
It is poor business practice to create tools which are prone to be used by hackers to steal user funds.
`Competency` and `Free Contract` are legal requirements for a valid contract.
There cannot be free contract when there is misrepresentation.
There cannot be competency when all detail of contract are not disclosed.
Where there are on blockchain invalid contracts there will be legal consequences in brick and mortar courts.
Further, whenever there are invalid contracts, the standard choke points for exit from crypto markets will be burdened with the blacklisting of scammer funds. This includes Gateways, Centralized Exchange Operators, and Faucet Providers. All of which are ultimately staffed by developers who will be redirecting development time to chasing down ghosts of scammed accounts.
It is my hope that this BSIP and resultant discusssion will be a focal point for suggesting and validating technical solutions to the proposal scam issue until every vector of such attack has been shut down and stamped out.
Rational
=============
Without a technical solution in place this scam will continue to tarnish the reputation of BitShares. The day after the user, which prompted this bsip lost funds, another user reached out to me with a scam proposal. It is all to common and the results for those taken are beyond devastating.
Discussion
====================
I think we've all seen it coming. Here it is.
$80,000.00 Gone
```
Richard Hanna, [09.03.19 22:25]
OMG i had no idea wha tthat was all about
i thought it was a security enhancement...
what can i do? i want to kill my self
```
Proposals lacks a metric of trustworthiness, this needs a technical solution. I don't know what it is, but this outcome was predictable as a consequence of the code base in light of human nature, yet unacceptable from both moral or business perspective.
This needs to stop.
This is a gaping hole in the legitimacy of the platform; we cannot have new users randomly getting scammed for large sums of money. The subject needs to be fleshed out as to what is and is not possible from technical perspective to mitigate this risk.
via telegram "BitShares Community" group
(https://t.me/bitshares_community)
```
Richard Hanna, [09.03.19 22:08]
anyone- asking for your help...
maybe wrong forum but my bitshares account got hacked
and someone stole 2,000,000 BTS... im devastated...
the thief account name is: joouwoo3c...what can i do?
Krista, [09.03.19 22:20]
It looks like the newest part of a scam to update account data ....
did you click on a proposal?
Richard Hanna, [09.03.19 22:22]
im not sure, i may have, i only check in every couple months...
how would i know?
Krista, [09.03.19 22:22]
What is your bitshares account name?
Richard Hanna, [09.03.19 22:22]
rwh-9164
Krista, [09.03.19 22:24]
See this ?? [ Photo ] They proposed and you accepted
Richard Hanna, [09.03.19 22:25]
OMG i had no idea wha tthat was all about
i thought it was a security enhancement...
what can i do? i want to kill my self
Krista, [09.03.19 22:26]
Oh no, don't do that *hugs*
that is exactly what they wanted you to do
was to think it was legitimate
Krista, [09.03.19 22:26]
There are a ton of accounts that run this scam
```
Potential Specifications
====================
**HIGH FEE FOR REJECTED PROPOSALS**
If accept and reject proposal fee could be separated; not sure of technical end of this... but in theory you could set reject fee high and imposed on the initiator of the proposal. Perhaps as high as $10 equivalent such that nobody proposes anything without knowing in advance that the other party intends to accept. That is, negotiate first, agree, then propose, and finally accept. Or take risk that you will be charged $10 for failure to first disclose your intentions openly. As it is not possible to be charged a fee unless you give permission, the proposer should be charged the $10 fee ALWAYS and then REFUNDED if the proposal is accepted via a vesting balance.
**FREE PROPOSAL REJECTION**
There is currently a fee associated with rejecting a proposal. This fee should be set to ZERO. A user should not have to PAY to make a "accept scam" button to go away.
**DUE CONSIDERATION ACCOUNT UPGRADE**
By default a new account cannot receive proposals at all without explicitly "upgrading" the account and signing some contract that makes clear the type of scams proposals are prone to. I would be in favor of having to PAY to upgrade to receive proposals as a matter of contractual "due consideration".
**WHITELIST**
Bhuz, [10.03.19 13:58]
What about adding a whitelist for proposals? How hard would it be and how would that impact legit business? I think just having a whitelist on proposals make both sense and potentially solves the majority of scams without really affecting legit business that may want to use proposals. For whitelist on proposals I mean a user defined list that contains account names that are allowed to create proposals for the account in question. Cons I see is more RAM needed for consensus witness node, probably need to set an hard limit on the list length
Christopher Sanborn, [10.03.19 15:40]
I like this idea. Vast majority of users don't need or expect others to propose transactions on their behalf. Those that do, could/should take steps to enable it.
**NAME REGULATION**
The majority of these scams seem to arise from users that are either using an account name that sounds like a legitimate business or initiating a proposal with the word "security" in it as a method of deceit. A potential solution is to regulate any account name with "BitShares", "security", "open-ledger", "rudex" and disallow accounts with specific words in them from proposing transactions.
In most countries the word "bank" cannot be used by anyone except a state approved bank. eg Australia: "APRA limits use of ‘bank’, ‘banker’, ‘banking’ and ‘ADI’, and by extension words or expressions with like meanings (such as ‘banque’)."
Bhuz, [10.03.19 14:38]
It's hard to define what names need to be "regulated", it's hard to defend from similar/misspelled names, it's hard to update such a global list
**DELAY TRANSFER WITH OPTION TO REVERSE**
What about any funds that transfer via proposal move to some type of "vesting" balance and are non accessible for some period and there is option for reversal/refund within 24 hours? Is this possible?
**P2P SOCIAL CREDIT SCORE**
Is it possible to know percent of proposals accepted/denied by this user?
Would it be possible to have some form of rating system like you do at ebay where post transaction you rate the other party?
**UI LEVEL FILTRATION**
Stefan, [09.03.19 23:55]
The recent UI update 190227
needs double checking to see the approve button,
with a warning hint.
One first step could be to allow the UI to use an on chain whitelist on top of hard-coded scam account names to allow swift react
**MAKE EXPLICIT THE NATURE OF THE CONTRACT**
There is no attempt currently made by the bitshares-UI to parse the nature of the proposal. Until such time as the proposals are `1) TRANSLATED` from Graphene into English `2) DISPLAYED` to the user, then under no circumstance should a button be presented to the lay user to `ACCEPT` terms of a contract both presented in obscure foreign language and without any apparent link to greater detail.
**BASIC AND ADVANCED UI VERSIONING**
h/t @murda_ra
There could be two versions of the reference UI:
1) standard / basic - which DOES NOT include proposal abilities
2) advanced version - which includes all features and includes a disclaimer upon download
**RELATED ISSUES**
differentiate between scam and unkown proposals
https://github.com/bitshares/bitshares-ui/pull/2429
Show required fee amount on permanently-reject-proposal page
https://github.com/bitshares/bitshares-ui/issues/2527
Clearly render proposal contents
https://github.com/bitshares/bitshares-ui/issues/2499
Increased user failsafe and security
https://github.com/bitshares/bitshares-ui/issues/2460
Whitelist tab enhancement
https://github.com/bitshares/bitshares-ui/issues/2423
Handle proposals related to phishing accounts
https://github.com/bitshares/bitshares-ui/pull/2178
Document how proposals work
https://github.com/bitshares/bitshares-core/issues/731
UI Scam Alert
https://github.com/bitshares/bitshares-ui/issues/2529
**KNOWN BLACKLISTED ACCOUNTS**
https://github.com/bitshares/bitshares-ui/blob/develop/app/lib/common/scamAccounts.js
**EXAMPLE SCAM PROPOSALS**
https://open-explorer.io/#/objects/1.10.24449
Screen Capture of $80,000 loss
=========================

Summary for Shareholders
=======================
1) The proposal mechanism can be used to defraud unexpecting users through misrepresentation.
2) Contractual misrepresentation is a criminal act of theft in virtually all jurisdictions
3) The User Interface is being exploited to hide the true nature of scam proposals.
4) There are a multitude of potential solutions to the issue, each of which needs to be thoughtfully considered.
Copyright
=================
`WTFPL`
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.