Upgrading the Bug Bounty program - potential AGP

Bumping this as it’s incredibly relevant. Aragon is now shipping more apps with Autark and Aragon Black. These apps are amazing and could unlock tons of value, but only if people use them…

People are wary of DAOs just because of “the DAO” hack. If we want people to actually use Aragon we need to go above and beyond to prove that the Aragon platform and all major releases of Aragon apps are secure. This is easier said than done.

  • Security audits are not perfect. Even with an audit all you know is what was reported. They might have missed something.
  • Security audits are highly technical and the process is opaque to people who are not involved in the Ethereum security commuinty.
  • Security audits are expensive. Having strategic and financial help to navigate that negotiation is extremely important!

Aragon is trying to attract talent and users. Having the worlds easiest to build on and most secure platform is a HUGE selling point. If developers see that they will have help shipping professional and production ready applications they are more likely to choose to build on Aragon vs other platforms. If users see that all major Aragon apps are secure, they’re more likely to use them. To do this we need a multi layered approach to security. This can include audits for all major projects (Nest and Flock) as well as a comprehensive Bug Bounty program that covers all major apps. This is a small price to pay to establish credibility and trust in the Aragon platform and developer ecosystem.

2 Likes