Zcash Ecosystem Security Lead

Hi everyone,

We had a great conversation with @earthrise on Friday about his grant proposal. We discussed Taylor’s background, motivations for this grant, and his vision for success for this grant and the Zcash ecosystem. We also discussed some expectations the ZCG committee has and clarified a few points of concern.

Our outline of expectations include:

  • Monthly milestone payments will be adjusted based on work completed in a given month, not to exceed the overall approved grant funding cap.
  • The applicant will participate in a monthly call with the ZCG committee before billing the current month’s work to discuss the following:
    • Proof of work to be billed for the current month.
    • Work planned for the next month
    • Prioritization of future work with input accepted from the ZCG and broader Zcash community.
    • Relationship building accomplished within the community.
  • The applicant is required to work with ecosystem developers and partners via their preferred communication channels.
  • The applicant is required to follow responsible bug disclosure best practices, and when available, adhere to the disclosure policies and channels of the organization in which they are supporting.
  • All testing software, hardware, and other expenses related to the work performed under this grant are the responsibility of the grant applicant.

We are less concerned about there being enough work to fulfill the full year of support Taylor is proposing. We think Taylor has a lot of great ideas and is on the right path in terms of prioritization of the efforts he envisions pursuing. In addition to performing audits, Taylor also wants to provide ad-hoc security guidance to developers in our ecosystem which can be achieved through the building of relationships with the ecosystem of developers. These kinds of relationships could help projects get ahead of security issues before they occur rather than waiting for an audit finding to come knocking. We like this proactive approach.

While we are deliberating internally and getting our newest ZCG member @dontpanicburns up to speed on the grant we want to hear more from developers in this ecosystem - Are you open to building a relationship with Taylor, interested in seeking his guidance for security related topics, and open to leveraging his expertise for security audits and other purposes?

@adityapk00 @NighthawkApps @hanh @skyl @birdify @zancas @little.slingshot @pitmutt (The forum will only let me tag 10 people total)

:smiley:

14 Likes