<oembed><type>rich</type><version>1.0</version><author_name>npub1uyhgpz5nsfnvdlcqm3erjsdjasd9pdeaejeetwtkvumm6mp3ujlqxt9vwk</author_name><author_url>https://nostr.ae/npub1uyhgpz5nsfnvdlcqm3erjsdjasd9pdeaejeetwtkvumm6mp3ujlqxt9vwk</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2023-05-10&#xA;🗒️ Summary of this message: The Lightning Network&#39;s reputation system is susceptible to sudden behavioral changes and whitewashing attacks, but fees can put a price on having a good reputation. Nodes do not gossip about peer reputation, and data collection will inform future decisions.&#xA;📝 Original message:&#xA;Hi Christian,&#xA;&#xA;Thanks for your comments! We will discuss this further in the upcoming call&#xA;on the 15th, would be great to see you there!&#xA;&#xA;&#xA;&gt; this is an intrinsic issue with reputation systems, and the main&#xA;&gt; reason I&#39;m sceptical w.r.t. their usefulness in lightning.&#xA;&gt; Fundamentally any reputation system bases their expectations for the&#xA;&gt; future on experiences they made in the past, and they are thus always&#xA;&gt; susceptible to sudden behavioral changes (going rogue from a prior&#xA;&gt; clean record) and whitewashing attacks (switching identity, abusing&#xA;&gt; any builtin bootstrapping method for new users to gain a good or&#xA;&gt; neutral reputation before turning rogue repeatedly).&#xA;&gt;&#xA;&#xA;In the Lightning Network, fees are a native way to put a price on having a&#xA;good reputation (see details here [0]). In the design that we suggest, the&#xA;reputation gained today cannot be used in the distant future, and funds&#xA;need to be invested continuously to keep a good reputation. Good reputation&#xA;is also a function of the general environment, and so if there is a fee&#xA;spike, reputation will change. It is true that nodes can go rogue, but this&#xA;is why we aim for the price of a good reputation to be similar to the&#xA;amount of damage they can create.&#xA;&#xA;&#xA;&gt; This gets compounded as soon as we start gossiping about reputations,&#xA;&gt; since now our decisions are no longer based just on information we can&#xA;&gt; witness ourselves, or at least verify its correctness, and as such an&#xA;&gt; attacker can most likely &#34;earn&#34; a positive reputation in some other&#xA;&gt; part of the world, and then turn around and attack the nodes that&#xA;&gt; trusted the reputation shared from those other parts.&#xA;&gt;&#xA;&#xA;Notice that we are not gossiping about our peer&#39;s reputation. The only&#xA;thing that a node communicates to its neighbor is whether they see an HTLC&#xA;as endorsed or just neutral, that is, should this HTLC be granted access to&#xA;all of the resources or just the restricted part.&#xA;&#xA;&#xA;&gt; I&#39;d be very interested in how many repeat interactions nodes get from&#xA;&gt; individual senders, since that also tells us how much use we can get&#xA;&gt; out of local-only reputation based systems, and I wouldn&#39;t be&#xA;&gt; surprised if, for large routing nodes, we have sufficient data for&#xA;&gt; them to make an informed decision, while the edges may be more&#xA;&gt; vulnerable, but they&#39;d also be used by way fewer senders, and the&#xA;&gt; impact of an attack would also be proportionally smaller.&#xA;&gt;&#xA;&#xA;This is something we hope to learn once we&#39;ll start collecting data from&#xA;our brave volunteers :)&#xA;&#xA;Cheers,&#xA;Clara&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20230510/e8f3be68/attachment-0001.html&gt;</html></oembed>