{"type":"rich","version":"1.0","author_name":"npub1uyhgpz5nsfnvdlcqm3erjsdjasd9pdeaejeetwtkvumm6mp3ujlqxt9vwk","author_url":"https://nostr.ae/npub1uyhgpz5nsfnvdlcqm3erjsdjasd9pdeaejeetwtkvumm6mp3ujlqxt9vwk","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2023-05-10\n🗒️ Summary of this message: The Lightning Network's reputation system is susceptible to sudden behavioral changes and whitewashing attacks, but fees can put a price on having a good reputation. Nodes do not gossip about peer reputation, and data collection will inform future decisions.\n📝 Original message:\nHi Christian,\n\nThanks for your comments! We will discuss this further in the upcoming call\non the 15th, would be great to see you there!\n\n\n\u003e this is an intrinsic issue with reputation systems, and the main\n\u003e reason I'm sceptical w.r.t. their usefulness in lightning.\n\u003e Fundamentally any reputation system bases their expectations for the\n\u003e future on experiences they made in the past, and they are thus always\n\u003e susceptible to sudden behavioral changes (going rogue from a prior\n\u003e clean record) and whitewashing attacks (switching identity, abusing\n\u003e any builtin bootstrapping method for new users to gain a good or\n\u003e neutral reputation before turning rogue repeatedly).\n\u003e\n\nIn the Lightning Network, fees are a native way to put a price on having a\ngood reputation (see details here [0]). In the design that we suggest, the\nreputation gained today cannot be used in the distant future, and funds\nneed to be invested continuously to keep a good reputation. Good reputation\nis also a function of the general environment, and so if there is a fee\nspike, reputation will change. It is true that nodes can go rogue, but this\nis why we aim for the price of a good reputation to be similar to the\namount of damage they can create.\n\n\n\u003e This gets compounded as soon as we start gossiping about reputations,\n\u003e since now our decisions are no longer based just on information we can\n\u003e witness ourselves, or at least verify its correctness, and as such an\n\u003e attacker can most likely \"earn\" a positive reputation in some other\n\u003e part of the world, and then turn around and attack the nodes that\n\u003e trusted the reputation shared from those other parts.\n\u003e\n\nNotice that we are not gossiping about our peer's reputation. The only\nthing that a node communicates to its neighbor is whether they see an HTLC\nas endorsed or just neutral, that is, should this HTLC be granted access to\nall of the resources or just the restricted part.\n\n\n\u003e I'd be very interested in how many repeat interactions nodes get from\n\u003e individual senders, since that also tells us how much use we can get\n\u003e out of local-only reputation based systems, and I wouldn't be\n\u003e surprised if, for large routing nodes, we have sufficient data for\n\u003e them to make an informed decision, while the edges may be more\n\u003e vulnerable, but they'd also be used by way fewer senders, and the\n\u003e impact of an attack would also be proportionally smaller.\n\u003e\n\nThis is something we hope to learn once we'll start collecting data from\nour brave volunteers :)\n\nCheers,\nClara\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20230510/e8f3be68/attachment-0001.html\u003e"}
