Nxt Forum
_______________________________________________________________________________
________
Quote from: cynicSOB on February 10, 2015, 08:51:02 pm
updates:
- I found no advantage in splitting the stake in various accounts.
- NXT's POS using block generator signatures is robust, probably even better than PPC's stake modifiers. You should probably thank Cunicula for that: his discussions with cfb led to that design.
- It's still POS, so 20% of the staking weight, which is at best 10% of the total supply, is enough to double spend once every 30hs. Here, double-spend is calculated for 10 confirmations. For 4 confirmations (like some exchanges use) half of that much is more than enough
- I found a hole that allows me to (aprox) double my staking weight: I can make 1M NXT forge as often as 2M should. This would allow a 51% attack with 25% stake. This is still theory, I need to modify the client to generate the attack.
So, I can't attack testnet with only 200K.. that thing was an underestimation... but I could with 2M. And I found a serious security problem, so please organize a bounty and set the goals to claim it. Come on, let's gather some 200K real NXT (not just testnet) I'm sure once the devs understand this they'll agree and fix it.
Since I don't need to split the NXT in several accounts, if I wanted to try to double spend with 10% of the supply I could do it with leasing.
Leasing is a good idea: I think it's the reason why the total network staking weight is high for NXT compared to others._______________________________________________________________________________
____
Quote from: jones
I'm skeptical, as always
I'm not sure how 20% staking weight can double-spend a transaction every thirty hours if the person waits the normal 10 confs. A finney attack would be regular, the evil forger wouldn't include the block when it forged, and the person that accepted after one confirm would be double spent on, when we wait more than one confirm, the security increases with all the different forgers that pile blocks on top, with 10 confirms, the chance of a person with 20% staking power forging 10 consecutive blocks would be (0.2)^10 would take over a million blocks to happen. (0.2)^4 is much less, but since the largest staker has about 10% right now (0.1)^4 is small enough to only happen twice so far in nxt's existence.
Doubling the staking power is interesting, I'll do some more thinking and try to figure this out for myself, my bounty is 0 though
_______________________________________________________________________________
__
@cynicSOB
It looks like NXT devs are trying to welch on any bounty, bad form on their part.
You could just post their vulnerability for them acting that way.