3 ms·
Security wise Nano is DOA. Currently any attacker can effectively DDOS the network with trivial resources. I’ve personally proposed a complete solution to this
by manjalyc 6y ago
Security wise Nano is DOA. Currently any attacker can effectively DDOS the network with trivial resources. I’ve personally proposed a complete solution to this problem over a year ago but it’s implementation is complex and would require a network split and my proposal has effectively been ignored in favor of other mitigation’s that fall far short of protecting the network. I’m not a security researcher and hell I’m not even in the CS field anymore so if I could figure out and implement an network wide attack on my own the barrier to entry is low (to be clear I have not executed any such attack). If you want to read further, the issue is a precomputed PoW attack. Nano’s very benefit - speed - is it’s biggest pitfall.
- onelastjob 6y agoI'd be interested to know more about your proposal to solve the precomputed work attack vector. Also, I think if you can easily create an attack that would DDOS network, you should absolutely try it on the Nano test net. That's what the test net is there for. To my knowledge, the precomputed spam attack has been mitigated by the Dynamic PoW feature that was added in v19. See my other reply with more details on that. I would like to know more about your proposal. You can email me at purplewumpus@protonmail.com
- manjalyc 6y agoI simply do not have the time nor motivation to conduct an attack on the Nano testnet. I've responded to your other reply with the technical shortcomings of the mitigation, my proposal is still open somewhere in github's issues but I've since moved on from cryptocurrency as a whole.