Potential Anti-Scam Measures
- Dominant language
- Python
- Stars
- 12
- Forks
- 21
- Avg merge
- 5d 19h
- Merged PRs (30d)
- 5
Description
**TL;DR**: This issue has a list of ideas for reducing "fake participants" on CHS.
**Details**
Scam prevention ideas from my Minerva summer interns:
- require SMS dual-factor authentication for participant accounts (and monitor what phone numbers are used--must match country you are claiming to be from)
- biometrics like faceprint (third-party solutions available here)
- IP tracking
- government ID
- best practices training materials for RAs at any lab processing consents, etc.
- Full details of these ideas [here](https://docs.google.com/document/d/1F1uK9j6khHZ5qWq-HA8JfB7DKBlhz1ZI8pgxCravKkI/edit?usp=sharing) including their descriptions of weaknesses/limitations of each idea
Melissa already shared these thoughts in Slack:
- Awesome - IP tracking is the most straightforward (and there's current internet policy mishegos around government IDs/ "age verification" so I would like to stay out of the radar on that for as long as possible/ until some of the obvious wrinkles have been ironed out by other people than us.)
- But also something we've resisted up until now in order to store minimal information about participants who are just coming to potentially "drive by" and take a single study.
- There is a future version of CHS/Lookit that potentially has a "verified participant" type qualification like I think both MTurk and Prolific offer, which would probably require more like this.
- For now, what would be ideal would be to be able to maintain a blacklist of IP addresses known to be associated with scammers (known how...?) and selectively block them without storing the IP of every user, but I'm not sure that's actually technically possible.
Contributor guide
Research direction
No files, tests, or entry points are identified. Start by reviewing the linked proposal and the current participant-account data model and authentication flow; done requires a selected, technically scoped scam-prevention approach with agreed privacy and storage requirements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100