{"type":"rich","version":"1.0","author_name":"npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2","author_url":"https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2022-07-08\n📝 Original message:On Tue, Jul 05, 2022 at 08:46:51PM +0000, alicexbt wrote:\n\u003e Hi Peter,\n\u003e \n\u003e \u003e Note that Wasabi already has a DoS attack vector in that a participant can stop\n\u003e \u003e participating after the first phase of the round, with the result that the\n\u003e \u003e coinjoin fails. Wasabi mitigates that by punishing participating in future\n\u003e \u003e rounds. Double-spends only create additional types of DoS attack that need to\n\u003e \u003e be detected and punished as well - they don't create a fundamentally new\n\u003e \u003e vulerability.\n\u003e \n\u003e I agree some DoS vectors are already mitigated however punishment in this case will be difficult because the transaction is broadcasted after signing and before coinjoin tx broadcast.\n\u003e \n\u003e Inputs are already checked multiple times for double spend during coinjoin round: https://github.com/zkSNACKs/WalletWasabi/pull/6460\n\u003e \n\u003e If all the inputs in the coinjoin transaction that failed to relay are checked and one or more are found to be spent later, what will be punished and how does this affect the attacker with thousands of UTXOs or normal users?\n\nPoint is, the attacker is thousands of UTXOs can also DoS rounds by simply\nfailing to complete the round. In fact, the double-spend DoS attack requires\nmore resources, because for a double-spend to be succesful, BTC has to be spent\non fees.\n\nIt's just a fact of life that a motivated attacker can DoS attack Wasabi by\nspending money. That's a design choice that's serving them well so far.\n\n-- \nhttps://petertodd.org 'peter'[:-1]@petertodd.org\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 833 bytes\nDesc: not available\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220708/99636bb4/attachment.sig\u003e"}
