Make JuiceboxDAO's multisig a 6/9 multisig with updated membership.
It has become more difficult to get transactions signed and executed in time, which has led to several close calls in executing governance. In the event of an exploit or another situation where the multisig needs to move fast, this could pose a major risk.
In my view, a larger multisig may actually decrease DAO security by spreading the burden of verification, making signers feel less individual responsibility for ensuring that transactions have been properly queued. When queuing transactions for JBP-384, I set the memo for the v2 reconfigureFundingCyclesOf(...) transaction as:
Verification check. If you see this, directly message Filip a cowboy emoji.
I only received cowboy emojis from twodam and 0xBA5ED. This was a complex multisend transaction and may not have been representative, but it seems likely that most multisig members are not carefully verifying each part of every transaction.
The last multisig membership update was completed on nonce 175. The signing statistics for the 79 transactions since then:
Conduct a weighted Snapshot vote with the following options:
Any vote other than a "Against" or an "Abstain" will be counted as a "For" for standard governance purposes. If this proposal passes, multisig ownership will be updated to include 9 addresses which receive the most votes. The threshold shall at all times remain at the lowest possible number greater than the total number of multisig owner accounts times 0.6.
Prospective multisig signers may designate another address which they prefer to the one listed in this proposal.
There may be risks associated with being on the multisig.
A smaller multisig is more susceptible to internal collusion.
To be completed within 21 days of this proposal's approval.