<oembed><type>rich</type><version>1.0</version><author_name>npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn</author_name><author_url>https://nostr.ae/npub1wtx5qvewc7pd6znlvwktq03mdld05mv3h5dkzfwd3dc30gdmsptsugtuyn</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-10-13&#xA;📝 Original message:&#xA;I think the mechanism can indeed create interesting dynamics, but not in&#xA;a good sense :-)&#xA;&#xA;&gt;&gt; I can still establish channels to various low-reputation nodes, and&#xA;&gt;&gt; then use them to grief a high-reputation node.  Not only do I get to&#xA;&gt;&gt; jam up the high-reputation channels, as a bonus I get the&#xA;&gt;&gt; low-reputation nodes to pay for it!&#xA;&gt;&#xA;&gt; So you&#39;re saying:&#xA;&gt;&#xA;&gt; ATTACKER --(no hold fee)--&gt; LOW-REP --(hold fee)--&gt; HIGH-REP&#xA;&gt;&#xA;&gt; If I were LOW-REP, I&#39;d still charge an unknown node a hold fee. I&#xA;&gt; would only waive the hold fee for high-reputation nodes. In that case,&#xA;&gt; the attacker is still paying for the attack. I may be forced to take a&#xA;&gt; small loss on the difference, but at least the larger part of the pain&#xA;&gt; is felt by the attacker. The assumption is that this is sufficient&#xA;&gt; enough to deter the attacker from even trying.&#xA;&#xA;The LOW-REP node being out of pocket is the clue here: if one party&#xA;loses funds, even a tiny bit, another party gains some funds. In this&#xA;case the HIGH-REP node collaborating with the ATTACKER can extract some&#xA;funds from the intermediate node, allowing them to dime their way to all&#xA;of LOW-REP&#39;s funds. If an attack results in even a tiny loss for an&#xA;intermediary and can be repeated, the intermediary&#39;s funds can be&#xA;syphoned by an attacker.&#xA;&#xA;Another attack that is a spin on ZmnSCPxj&#39;s waiting to backpropagate the&#xA;preimage is even worse:&#xA;&#xA; - Attacker node `A` charging hold fees receives HTLC from victim `V`&#xA; - `A` does not forward the HTLC, but starts charging hold fees&#xA; - Just before the timeout for the HTLC would force us to settle onchain&#xA;   `A` just removes the HTLC without forwarding it or he can try to&#xA;   forward at the last moment, potentially blaming someone else for its&#xA;   failure to complete&#xA;&#xA;This results in `A` extracting the maximum hold fee from `V`, without&#xA;the downstream hold fees cutting into their profits. By forwarding as&#xA;late as possible `A` can cause a downstream failure and look innocent,&#xA;and the overall payment has the worst possible outcome: we waited an&#xA;eternity for what turns out to be a failed attempt.&#xA;&#xA;Cheers,&#xA;Christian</html></oembed>