<oembed><type>rich</type><version>1.0</version><author_name>npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn</author_name><author_url>https://nostr.ae/npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-10-13&#xA;📝 Original message:&#xA;Joost Jager &lt;joost.jager at gmail.com&gt; writes:&#xA;&gt;&gt; The LOW-REP node being out of pocket is the clue here: if one party&#xA;&gt;&gt; loses funds, even a tiny bit, another party gains some funds. In this&#xA;&gt;&gt; case the HIGH-REP node collaborating with the ATTACKER can extract some&#xA;&gt;&gt; funds from the intermediate node, allowing them to dime their way to all&#xA;&gt;&gt; of LOW-REP&#39;s funds. If an attack results in even a tiny loss for an&#xA;&gt;&gt; intermediary and can be repeated, the intermediary&#39;s funds can be&#xA;&gt;&gt; syphoned by an attacker.&#xA;&gt;&gt;&#xA;&gt;&#xA;&gt; The assumption is that HIGH-REP nodes won&#39;t do this :) LOW-REP will see all&#xA;&gt; those failed payments and small losses and start to realize that something&#xA;&gt; strange is happening. I know the proposal isn&#39;t fully trustless, but I&#xA;&gt; think it can work in practice.&#xA;&gt;&#xA;&gt;&#xA;&gt;&gt; Another attack that is a spin on ZmnSCPxj&#39;s waiting to backpropagate the&#xA;&gt;&gt; preimage is even worse:&#xA;&gt;&gt;&#xA;&gt;&gt;  - Attacker node `A` charging hold fees receives HTLC from victim `V`&#xA;&gt;&gt;  - `A` does not forward the HTLC, but starts charging hold fees&#xA;&gt;&gt;  - Just before the timeout for the HTLC would force us to settle onchain&#xA;&gt;&gt;    `A` just removes the HTLC without forwarding it or he can try to&#xA;&gt;&gt;    forward at the last moment, potentially blaming someone else for its&#xA;&gt;&gt;    failure to complete&#xA;&gt;&gt;&#xA;&gt;&gt; This results in `A` extracting the maximum hold fee from `V`, without&#xA;&gt;&gt; the downstream hold fees cutting into their profits. By forwarding as&#xA;&gt;&gt; late as possible `A` can cause a downstream failure and look innocent,&#xA;&gt;&gt; and the overall payment has the worst possible outcome: we waited an&#xA;&gt;&gt; eternity for what turns out to be a failed attempt.&#xA;&gt;&gt;&#xA;&gt;&#xA;&gt; The idea is that an attacker node is untrusted and won&#39;t be able to charge&#xA;&gt; hold fees.&#xA;&#xA;The attacker controls both the sender and the HIGH-REP node. The sender&#xA;doesn&#39;t need to be trusted, it just initiates a payment that is used to&#xA;extract hold fees from a forwarding node. The HIGH-REP node doesn&#39;t&#xA;lose reputation because from what we can witness externally the payment&#xA;failed somewhere downstream. It does require an attacker to have a hold&#xA;fee charging HIGH-REP node, yes, but he is not jeopardizing its&#xA;reputation by having it fail downstream.&#xA;&#xA;Cheers,&#xA;Christian</html></oembed>