Menese Protocol SNS announcement

Thank you, that’s very decent, we will make sure to help in this process as much as we can maybe we can include our test suites for different canister states.

We will not be proposing unless we have given reviewers 2 weeks notice to verify the hashes(and notify them of changes, we don’t want to stale our upgrade schedules), the proposal timing is just currently tied to final security reviews on cross chain infra-CLMM-Zk ledger and the entire encoders-decoders infra, we also need to migrate certain api keys relevant in production for RPC enterprise points. We are not in a rush and we might even SNS with a big surprise( a big token buy back due to an enterprise deal being negotiated fingers crossed 3-4 weeks we know)

Pride, and to me, a very big Red flag :triangular_flag:

Your past effort doesn’t reduce my investment risk.

To me, that’s confidence rather than pride, and I don’t think it’s a red flag.

In many ways this is alignment and in a common man’s language we have put our own-money and effort into it(or where our mouth is I guess), are we proud of that? We will be if it takes off as planned, is there a risk, yes, but we are taking it along with everyone else and will fight for it

Open source and control are related, but they are not the same thing. Publishing source code allows the public to inspect how a system is intended to operate, identify privileged functions, and independently evaluate security claims. However, open-sourcing code does not by itself prove that the published version is the code actually running, nor does closed-source software automatically mean that its developer controls users’ assets. Control depends on the system’s real technical and operational structure: who holds keys, who can authorize transactions, whether administrators can freeze or transfer assets, how validators are selected, and whether any party can unilaterally change the rules.

There is generally no legal requirement for a developer or blockchain project to publish proprietary source code to the public merely because a community member demands it. A person may reasonably prefer open-source software and make transparency a condition of their trust or participation, but that preference is not the same as a legal obligation. In a regulatory investigation, licensing process, lawsuit, or court proceeding, authorities may require a company to provide source code, technical documentation, or other evidence - often confidentially - to verify claims about custody, control, security, or compliance. That possibility does not create a general requirement to open-source the code for everyone.


Sorry for swooping in late, hope you didn’t share everything. There isn’t even a legal requirement asking you to open-source your proprietary code and many aren’t doing that. I think it took Dfinity 5 years to open-source theirs and something like Hyperliquid is still not fully open-source. You are obligated to do it only once authorities ask for it and then I suppose you need to prove its non-custodial and it`s the code that actually ran live. The only reason you would want to show your code is to increase public trust. You could do that by just getting few auditors to check it out in private as well. In a way you need to weight the benefits of showing it vs keeping it private. SNSes should definately not require something that even the law doesn’t require. In fact it’s a bit shady for someone to demand you to give them your proprietary code in order to launch something, given that AI can now reverse engineer it in minutes and copy it.

A community member’s demand does not, by itself, create a general legal obligation for a private software developer to publish its proprietary source code. A disclosure obligation must come from some applicable law, licence, contract, regulatory power, or court order.

It’s absolutely up to you what you want to open-source. Community members decide if they want to trust you, or your auditors or not. If you keep code closed and people don’t trust you, they just dont participate. It’s not like there is a swarm of mindless DAO lovers around here just waiting for a new SNS launch to ape into.

If I were you, given the low community participation, I would find out who is interested in joining first, verifying they are really capable of doing that and then perhaps opening the source-code to them in private if I trust they are really interested.

@Lorimer, get yourself together, man. You are hired to vote on proposals with a yes or no and provide reviews. You are not an official representative of the ICP community, nor is it your job to interrogate people over weeks, who want to build on the IC and launch their projects.

Infu pull yourself together man, it’s not your job to intimidate users of this crypto project to not post opinions or do their own due diligence on projects. It’s your job to build things and “decentralize” them.

Nate, pull yourself together, man. It’s not your job to…

Oh nevermind, carry on.

Good luck with your sns @MeneseProtocol

Um, no I’m not.

I’m a staker, I have a vote, and I have a opinion. That’s it.

Unlike the vast, vast, vast majority of other stakers, I show up. It’s all the complacent voters who, in my opinion, are doing it very wrong.

A closed source project that also does not have verifiable builds can very, very easily rug pull. It doesn’t matter how trustworthy a team may seem. This is crypto and trust is the opposite of what the whole thing is about. There’s quite literally no point in crypto and what people build on it if it requires trust in a centralised party (may as well benefit from the speed and maturity of web 2 tech).

You pull yourself together.

In many cases everyone we do want to open source this, it is a point of pride for the team, but we think the issue that will be tested whether the SNS will be capable of helping projects launch.

In many ways if we do it before and it does not get through it can have a negative effect on the projects’ success. Verifiable builds, verifying the actual code base including the amount of work done on it we are okay to have community members to see it privately. In any case I think we reached a good settlement on this.

@Lorimer @ZackDS and others we are going to release a skill file and step by step to run a subnet and from 6-8 UTC tomorrow we will have someone on call on our telegram group to help you guys out https://t.me/+blfet0L71NE4NWE8 even through a shared screen. We are also okay to take you through that shared screen into the official repo to see how the team works and how frequent is the work.

Edit: tbh everyone it really will be the big obstacle to jump start the SNS again and make sure it will function, the last project that did this and it was a pretty cool project was not able to secure enough to succeed, I think we are all more concerned whether the system still works or not and that’s an obstacle I know everyone who participated in this thread would see as a problem(most likely)

It’s not actually that hard to deploy a subnet, as long as you accept that the key generation of the subnet’s threshold key is centralized. What is hard is deploying a production instance where the subnet threshold key is generated in a secure, decentralized way. (Doing this may then also conflict with the source code license, but I am not a lawyer.)

I think you don’t need to decentralize keys to test out upgrades and stress on specific canister states right? and you can still verify the binary build as well.

Last time I considered trying to do this was a few years ago and back then it didn’t seem so easy, but maybe that was a misunderstanding on my part.

@Zane also pointed me at ICP in a Box the other day. Seems like things have changed since the last time I reviewed an ICOS proposal, and for the better.

Ideally it should be standard practise for new ICOS releases to be run by multiple independent parties before it is adopted by the NNS, particularly if those parties host infrastructure on the IC that would be affected by that release.

Thanks that will be interesting. How costly is it to spin up nodes in the cloud and run a subnet independent of the real NNS?

The least config possible can be 2 physical nodes each with 2 VMs, you can do it per day is for 6-8 euros, that’s 24h running. You can rent 4 machines I think it’s like 50 cents per hour, if you want run automated testing suites for example the max you would need is 6 hours probably

New updates coming today on the Zk ledger, this will be one of our SNS canisters that is open source and it took a lot of time-effort because you can’t have payments-assets without privacy.

We invite you all to review it, provide feedback-critique as well. In many ways, it can offer utility to both retail, businesses and institutions and incentivize people moving into Ck assets.

https://x.com/meneseprotocol/status/2084969449258447246?s=46&t=ZbNb94M7k9y5EWO4fsxEOg

For reviewers and those interested in governance we released this documentation to help you in your duties. This allows you to spin subnet with verified builds without using DFINITY’s farm. We have found it helpful testing the impacts of upgrades on our own infrastructure. If anyone has any issues, you can message our team here or on telegram

https://github.com/Menese-Protocol/ic-subnet-without-farm

Part of the delay from our part so far is that we are finalizing our enterprise and merchants side of things which includes service level agreements, designating a sales director, fine tuning the offering to include automated invoices and employee sub accounts. We are also taking great care in ZK privacy ledger security review we received, we had a couple of critical issues and other less severe remarks we are addressing and the repo should be updated shortly they were not trivial as we had to go around what the infrastructure can do and innovate a little hopefully some of our techniques can help others

https://x.com/meneseprotocol/status/2087809129326784576?s=46&t=ZbNb94M7k9y5EWO4fsxEOg

Hey everyone, we have finally finished the amends we had to do for the privacy layer. We intend to start the privacy ceremony for the first ledger which will cover ICP on the first of September, also from the first we would like to start our two week notice period. We will highlight here how many canisters and specs for the proposal along with verifiable build for reviewers.

We really hope you participate in the ceremony and that you destroy your contribution because one contribution destroyed means we can secure this ledger for private ICP txs, this will be followed we hope with also CKBTC

https://x.com/meneseprotocol/status/2091859495739703405?s=46&t=ZbNb94M7k9y5EWO4fsxEOg

This is basically the steps to participate:

1. Sign in with Internet Identity. Their principal shows on screen.

2. Join the queue to see your position. The coordinator runs strictly one-at-a-time, so there’s a real line.

3. When it’s their turn the page says “YOUR TURN”. They click Contribute.

4. The page downloads the current parameters from the coordinator, generates a secret and mixes it in right there in the browser, uploads the result, and submits a proof.

5. The secret is thrown away the moment the transform finishes.

6. You can watch the transcript grow and later confirm their contribution is in it.

The mixing happens inside a small WebAssembly module. That module exposes exactly two functions to the surrounding

JavaScript:

transform_contribution(…)
random_nonce_hex()

Neither one returns the secret. There is no export that carries it. So even a compromised or malicious version of the page has nothing to steal and no channel to steal it through the secret exists only inside the wasm sandbox and dies there. That’s the design doing the work, not a promise.

Files are small enough to read yourself: 133 lines of Rust, 144 lines of JavaScript.

Alright everyone we are starting the clock, the contributor canister for the privacy ceremony has been blackholed and can be verified with its hash. The Hivemind ledger is also open source. The SNS docs will be shared here tomorrow, reviewers who have access to the code base we are making your lives easier and starting with just 5 canisters, our main backend(which is huge and covers all the chains we cover), the SDK which is used by ecosystem projects and enterprise, the ICP-Sol cross chain pool, The privacy ledger and a canister to allocate neurons to those already staked from our pre sale. Bear with us tomorrow we will share those and start the clock on our 14 days. Today has been hectic with everyone reading and rereading and verifying what we just unleashed, thank you in advance for your contributions https://x.com/meneseprotocol/status/2094861417799184552?s=46&t=ZbNb94M7k9y5EWO4fsxEOg