pull down to refresh

Unfortunately, I think good intentions will pave the way for a Cloudflare on lightning. I don't see why this wouldn't happen for lightning, when it happened for HTTPS? But I haven't thought about it for longer than it took me to write this post.

Are you aware of a firewall like this? Afaik, one would need a lightning dissector first, and the one for Wireshark is unmaintained (last commit 7 years ago).

good intentions will pave the way

Then good intentions will destroy sender anonymity and one can just subpoena the dragnet of good intentions. Be very very very careful what you wish for here.

Are you aware of a firewall like this?

I've seen an in-house one for LND... in the early days. I think having sovereign security isn't that expensive anymore in 2026; all that prevents it is lack of imagination.

reply
150 sats \ 5 replies \ @ek OP 21 Sep
Then good intentions will destroy sender anonymity

You mean when both ends use the same WAF, similar to how ACINQ knows everything about Phoenix-to-Phoenix payments? It would be the same problem on a massive scale, yes.

reply

When you say the word Cloudflare, that is exactly what you're describing. Or do we think that TLS termination and re-encryption to a private PKI does not make them see the content of every encrypted HTTP call?

reply
128 sats \ 3 replies \ @ek OP 21 Sep

Maybe PTLCs would help decorrelate payments across hops in this case, too?

reply

It could (maybe) help against traffic being direct hard evidence, but would not prevent heuristics like timing and overall money movement. And for some reason all the heuristics bullshit is way overrated in the cases I've seen it used.

Multi-path may help a bit more depending on total penetration rate, but still it is risky. Bottom line, I think that delegating security to centralized coercible service providers is not how we create robust, private networks. It instead creates single points of failures.

reply
128 sats \ 1 reply \ @ek OP 21 Sep

Yeah, I think it could be enough to have a self-hostable FOSS version of such a protocol-aware firewall. Doesn't need to morph into a dragnet. I should research Cloudflare's history.

reply

So the reason to centralize is (traditionally) DDoS risk.

If something FOSS needs to be built, that is ok, as long as it is extremely lean and configurable.

reply