On Property rights and threat models for ENS

The quorum question isn’t easy to answer if you are looking for one consistent value. if you are willing to adopt a dynamic value, then it is easier. The reason: the delegate vote distribution (as well as threat score) will always be a power law (Rankγ) like you said, but it could be of different index γ which decides the slope. In utopia, γ = 0. In real life, you’d still want this value to be as low as possible and the power law to be as flat as possible. Flatter power law will require more number of colluders to attack and therefore decrease the likelihood. Having said that, the delegate vote count is not fixed, so the power laws are always shifting. Currently, threat to ENS starts at 4 colluders and Brantly, Coinbase, Nick feature in roughly 80%, 65%, 40% of these hypothetical attacks respectively as a reference. What number do you think is safe? It is a dynamic question (γ is varying) and should be treated as such. Beyond that, even if you flatten the power law, there will still be a finite number of colluders who could attack the protocol.

However, it doesn’t hurt to run a simulation with a higher quorum and with the current delegate vote distribution, a quorum of 2,000,000 will require a minimum of 7-8 colluders. This is obviously far better than 4 colluders but not very safe in a general context. Other list of values below:

quorum       min_colluders
1,000,000    4
2,000,000    7-8
3,000,000    13-14
4,000,000    27-28

Having looked at these values, quorum should be raised to 2,000,000 in my opinion. The “attacks” are only attacks on quorum so relatively safe and don’t need a hyper-strict criteria. I will run more simulations for a full on-chain voting. If I find something meaningful, I’ll go ahead and attack the protocol. You know where to find me. :smiling_imp: