{"type":"rich","version":"1.0","author_name":"npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn","author_url":"https://nostr.ae/npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2020-10-13\n📝 Original message:\nJoost Jager \u003cjoost.jager at gmail.com\u003e writes:\n\u003e\u003e The LOW-REP node being out of pocket is the clue here: if one party\n\u003e\u003e loses funds, even a tiny bit, another party gains some funds. In this\n\u003e\u003e case the HIGH-REP node collaborating with the ATTACKER can extract some\n\u003e\u003e funds from the intermediate node, allowing them to dime their way to all\n\u003e\u003e of LOW-REP's funds. If an attack results in even a tiny loss for an\n\u003e\u003e intermediary and can be repeated, the intermediary's funds can be\n\u003e\u003e syphoned by an attacker.\n\u003e\u003e\n\u003e\n\u003e The assumption is that HIGH-REP nodes won't do this :) LOW-REP will see all\n\u003e those failed payments and small losses and start to realize that something\n\u003e strange is happening. I know the proposal isn't fully trustless, but I\n\u003e think it can work in practice.\n\u003e\n\u003e\n\u003e\u003e Another attack that is a spin on ZmnSCPxj's waiting to backpropagate the\n\u003e\u003e preimage is even worse:\n\u003e\u003e\n\u003e\u003e  - Attacker node `A` charging hold fees receives HTLC from victim `V`\n\u003e\u003e  - `A` does not forward the HTLC, but starts charging hold fees\n\u003e\u003e  - Just before the timeout for the HTLC would force us to settle onchain\n\u003e\u003e    `A` just removes the HTLC without forwarding it or he can try to\n\u003e\u003e    forward at the last moment, potentially blaming someone else for its\n\u003e\u003e    failure to complete\n\u003e\u003e\n\u003e\u003e This results in `A` extracting the maximum hold fee from `V`, without\n\u003e\u003e the downstream hold fees cutting into their profits. By forwarding as\n\u003e\u003e late as possible `A` can cause a downstream failure and look innocent,\n\u003e\u003e and the overall payment has the worst possible outcome: we waited an\n\u003e\u003e eternity for what turns out to be a failed attempt.\n\u003e\u003e\n\u003e\n\u003e The idea is that an attacker node is untrusted and won't be able to charge\n\u003e hold fees.\n\nThe attacker controls both the sender and the HIGH-REP node. The sender\ndoesn't need to be trusted, it just initiates a payment that is used to\nextract hold fees from a forwarding node. The HIGH-REP node doesn't\nlose reputation because from what we can witness externally the payment\nfailed somewhere downstream. It does require an attacker to have a hold\nfee charging HIGH-REP node, yes, but he is not jeopardizing its\nreputation by having it fail downstream.\n\nCheers,\nChristian"}
