Giter Site home page Giter Site logo

Comments (18)

pk910 avatar pk910 commented on June 13, 2024 2

Heya, thanks for your feedback.
Yea, I got quite many reports that the required score is too high.
I've lowered it to 5 on both instances now.

However, the number might still change.
As of now it still seems a bit over-protective as the number of sessions dropped by more than 90% since activation of the minimal passport score 😅
Will keep an eye on it over the next days to collect more data & make a reasonable decision on the limit.

from powfaucet.

pk910 avatar pk910 commented on June 13, 2024 2

I've further lowered the required score to 2.
This should really be easily achievable by just some social media accounts.
At the end I don't want to exclude anyone from mining. The PoW stuff should still be the primary protection.

Regarding @LiuZhuJunYa's points:

  1. Yea you can use the same accounts to sign stamps for multiple accounts, however, these points are only counted if the stamp hasn't been used for another account within the last 30 days. This deduplication is done on faucet side, so the faucet keeps track of which stamps have been used for previous sessions.

  2. You're right, the PoW algorithm hasn't been compromised, but the sybil protection with captchas & IP checks has been compromised. There are public available tools out there that allow using my faucet with no user interaction and on a list of proxies. I can unfortunately also see that such tools are used a lot, it literally lead to tripling the mining activity just over the last 4 weeks. Farmers using such tools are luckily not very intelligent :D Spinning up like 100 sessions in seconds is quite obviously done from a automation tool and not a natural user activity.
    The holesky faucet has a fixed limit of 50k HolETH per day. I've constantly increased that limit over the last weeks according to the activity, so each session is still able to gather a meaningful amount. Unfortunately, I can't go higher than that to be able to keep the faucet online till the planned end of the network. The same applies to sepolia.
    So, to keep the faucet useful for normal users, I somehow have to limit the amount of bots & farmers. Obviously, I can't block them completely, but I can make farming with hundreds/thousands of addresses from cloud machines as hard as possible.
    If I wouldn't do that and just keep relying on the PoW protection, the mining rewards will become very very low at come time.
    End-users with normal computers or even mobile devices just can't compete against a fleet of extremely powerful cloud machines.

from powfaucet.

LiuZhuJunYa avatar LiuZhuJunYa commented on June 13, 2024

I present my own perspective as a blockchain research student:

  1. I have looked into the Gitcoin Passport project, and I think it's not very student-friendly because some of the ways to earn points require interaction with the actual blockchain. As students, we might be experimenting on testnets precisely because we lack substantial financial support.
  2. Additionally, I do not think the Gitcoin Passport project effectively prevents Sybil attacks. I tested the scoring potential of three components: Github Contributions on at least 30 distinct days, Discord, and Google. I found that it is possible to reuse these for different addresses to repeatedly gain points. Therefore, I believe the current reduction in session numbers to over 90% might only be due to the initial implementation of restrictions. Once Sybil accounts are verified, I expect the session numbers could rise again.
  3. Users who obtain test coins from your project also expend electricity and computing power. Why not reward them accordingly? I assume your PoW algorithm hasn't been compromised so far.

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

Yep the best I could do is discord, google and linkedin account which got me around 2.5 points; all others require some sort of other interaction with the main network.

from powfaucet.

pk910 avatar pk910 commented on June 13, 2024

If anyone knows about captchas that are not covered by automated captcha resolvers like rucaptcha / 2captcha / ..., that'd be a suitable alternative to using passports.
Unfortunately I haven't found one yet.

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

I've further lowered the required score to 2. This should really be easily achievable by just some social media accounts. At the end I don't want to exclude anyone from mining. The PoW stuff should still be the primary protection.

Regarding @LiuZhuJunYa's points:

  1. Yea you can use the same accounts to sign stamps for multiple accounts, however, these points are only counted if the stamp hasn't been used for another account within the last 30 days. This deduplication is done on faucet side, so the faucet keeps track of which stamps have been used for previous sessions.
  2. You're right, the PoW algorithm hasn't been compromised, but the sybil protection with captchas & IP checks has been compromised. There are public available tools out there that allow using my faucet with no user interaction and on a list of proxies. I can unfortunately also see that such tools are used a lot, it literally lead to tripling the mining activity just over the last 4 weeks. Farmers using such tools are luckily not very intelligent :D Spinning up like 100 sessions in seconds is quite obviously done from a automation tool and not a natural user activity.
    The holesky faucet has a fixed limit of 50k HolETH per day. I've constantly increased that limit over the last weeks according to the activity, so each session is still able to gather a meaningful amount. Unfortunately, I can't go higher than that to be able to keep the faucet online till the planned end of the network. The same applies to sepolia.
    So, to keep the faucet useful for normal users, I somehow have to limit the amount of bots & farmers. Obviously, I can't block them completely, but I can make farming with hundreds/thousands of addresses from cloud machines as hard as possible.
    If I wouldn't do that and just keep relying on the PoW protection, the mining rewards will become very very low at come time.
    End-users with normal computers or even mobile devices just can't compete against a fleet of extremely powerful cloud machines.

thanks a lot mate <3 <3 <3

from powfaucet.

pk910 avatar pk910 commented on June 13, 2024

@LiuZhuJunYa can you please do me a favor and remove that link from your post? :D
Yea, it is one of the tools I'm talking about, it's obviously available with some research, but I don't think it should be liked here...

What puzzles me is why they would engage in such work that is "all harm and no benefit," since these currencies are only for test sites and do not possess real value.

Yea, that's the core problem :(
I see two reasons for that:

  1. Most impact is probably caused by crypto projects who abuse public testnets as their incentive test environment...
    These projects put a value on testnet funds as it makes their testers eligible for future airdrops, which naturally attracts airdrop farmers on farming funds to be more eligible.
    Most recent example for this is eigenlayer, who dropped a massive amount of tokens to former goerli operators. But also various L2s that used their goerli/sepolia based testnets as base for their token airdrops.
  2. Users remember what happened on goerli, where a previously worthless testnet token suddenly became valuable and could be traded for mainnet funds. With recent testnets (sepolia/holesky), there's a significant higher amount of funds available, so that hopefully won't repeat. However, we can still see various testnet traders that put a value on these testnet funds, which attracts users on farming those funds..

It could be all soo much easier if testnets are really used for testing only.

from powfaucet.

LiuZhuJunYa avatar LiuZhuJunYa commented on June 13, 2024

Thank you for your reply, and I wish you all the best!

from powfaucet.

pk910 avatar pk910 commented on June 13, 2024

Your feedback is welcome :)

I really try to make the faucet more user friendly and not just more complex to use.
The new limitation I've introduced is obviously annoying, but I've seen the farmer problem getting out of control, which directly affects regular miners as the mining rewards got lower and lower.

I see from the feedback and session numbers that the score of 10 was way too high to start with and I appreciate that feedback.
I'll further monitor the situation for further adjustments, but also open for alternative Ideas :)

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

Hi @pk910 holesky faucet is having issues, sepolia faucet is just working fine.

rand

In the homepage it's showing just 2 passport score is required but here it's showing 10.
Also my IP seems to be blocked , no issues with sepolia faucet so it has to be something with the website right, not using any proxy or vpn btw.

from powfaucet.

AIWhispererDev avatar AIWhispererDev commented on June 13, 2024

worst idea ever

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

worst idea ever

Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.

from powfaucet.

AIWhispererDev avatar AIWhispererDev commented on June 13, 2024

worst idea ever

Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.

Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot?
Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

worst idea ever

Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.

Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot?
Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.

Dude all you have to do is just sign up for Discord , LinkedIn and Google to get a passport score of 2. You can sign up for them with just temp accounts and use them for passport verification.

from powfaucet.

AIWhispererDev avatar AIWhispererDev commented on June 13, 2024

worst idea ever

Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.

Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.

you understand that what you said is the definition of sybil and gitcoin does nothing to prevent the bots, so it is useless right?

from powfaucet.

pvnotpv avatar pvnotpv commented on June 13, 2024

worst idea ever

Huh how exactly ?, If you can't get a passport score of 2 then you're literally a bot.

Am I a bot because I don't want to use a crap service that sells my data and thinks it can really find out who is human or bot? Then how do I write this message? maybe I am using a bot to reply to you and I shitpost about gitcoin being the worst idea ever implemented in crypto.

you understand that what you said is the definition of sybil and gitcoin does nothing to prevent the bots, so it is useless right?

Isn't that what the whole above discussion was about ? Still something is better than nothing right.

from powfaucet.

pk910 avatar pk910 commented on June 13, 2024

The combination of various protection methods is the key here.
The gitcoin passport alone doesn't prevent sybils, especially as the required score of 2 is very low.
Mining alone also doesn't prevent sybils. Even with Captchas and IP based restrictions, the number of bots constantly increased over time.

The combination of both (mining & passport) works very nice at the moment, because the passport lowers the number of eligable addresses from basically unlimited to a semi-limited amount, just because farmers have to put in some effort to make an address eligible for mining (registering fake accounts, etc).
At the same time it doesn't affect regular users that much as everyone should be able to reach such a low passport score.

Tbh. I'm aware that this step won't protect the faucet from bots forever, but it's temporarily very effective.
I'm sure farmers are already preparing hundreds if not thousands account to make them eligible for mining.
And I'm looking forward to make that effort useless again once I see the bot activity raising again.

I'll revise the changes once the bot problem gets out of control again.
I've quite a few methods and changes in the pipeline to piss off farmers, and I'll continue activating them on purpose.

Apart from that, I'm very sorry for any regular user that get's locked out due to my protection efforts.
That's really not the plan, but if users have to compete against a fleet of bots, the mining rewards gets so low that the faucet is unusable for everyone.

from powfaucet.

AIWhispererDev avatar AIWhispererDev commented on June 13, 2024

Tbh it affects me who I am not a sybil, bot and just a regular user who doesn't want to use a service like gitcoin and just wants to mine some tokens to test out services. I think you might be just lazy to implement your own criteria like connect with twitter+discord+telegram or email (or whatever) than use gitcoin or maybe gitcoin pays you.

from powfaucet.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.