<oembed><type>rich</type><version>1.0</version><author_name>npub1g5zswf6y48f7fy90jf3tlcuwdmjn8znhzaa4vkmtxaeskca8hpss23ms3l</author_name><author_url>https://nostr.ae/npub1g5zswf6y48f7fy90jf3tlcuwdmjn8znhzaa4vkmtxaeskca8hpss23ms3l</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-10-13&#xA;📝 Original message:&#xA;Good morning Joost,&#xA;&#xA;&#xA;&gt; &gt; * I convince Rene to make a channel to me.&#xA;&gt;&#xA;&gt; You may succeed, but Rene is probably not going to pay you a hold fee because you&#39;re untrusted.&#xA;&#xA;Immaterial: I am interested in damaging the Joost-Rusty and Rusty-Rene relationships, not necessarily recouping these funds.&#xA;&#xA;&gt;  &#xA;&gt;&#xA;&gt; &gt; * I connect to Joost.&#xA;&gt; &gt; * I prepay to Joost.&#xA;&gt; &gt; * I forward Me-&gt;Joost-&gt;Rusty-&gt;Rene-&gt;me.&#xA;&gt; &gt;   * I am exploiting the pre-existing tr\*st that Rusty has to Joost, and the tr\*st that Rene has to Rusty.&#xA;&gt; &gt; * When the HTLC reaches me, I dicker around and wait until it is about to time out before ultimately failing.&#xA;&gt; &gt; * Rusty loses tr\*st in Joost, and Rene loses tr\*st in Rusty. &#xA;&gt;&#xA;&gt; But most importantly: you will have paid hold fees to Joost for the long lock time of the htlc. This should keep you from even trying this attack.&#xA;&#xA;But I might be interested in paying money in order to damage your reputation with Rusty, and damaging the reputation of Rusty with Rene.&#xA;Thus my capacity to disrupt the network is increased linearly by the number of hops involved, thus my point: I think what should be paid should be for the entire route, not the first hop.&#xA;&#xA;For that matter, how certain are you that Rene and Zeeman are not secretly the same person, have you seen them in the same room together?&#xA;&#xA;&#xA;As I pointed out before, the main reason to engage in these attacks is to lock up the capacity of less-capitalized competitors in the payment forwarding business.&#xA;Cases of slow payment resolution caused by intermediate nodes are more likely to be because of incompetence (crashing nodes, ISP disconnections, clumsy humans tripping on power supplies) than active malice.&#xA;Thus, the primary motivated attackers are the ends of the payment: the payer and payee, who, in this attack, are coordinating with each other to lock up the funds of multiple other lesser-capacity nodes (and which might be a single node).&#xA;&#xA;To an extent, to protect against such attacks, we need to know the payer and payee and somehow judge their tr\*stworthiness --- but we want to not have to reveal their identities, since that works against our privacy.&#xA;&#xA;Hmmm.&#xA;&#xA;Regards,&#xA;ZmnSCPxj</html></oembed>