Edward Snowden Slams Sam Altman's Worldcoin: 'Don't Catalogue Eyeballs'
decrypt.co
decrypt.co
Here's my take on it: You can possibly replace their biometric device with a random hash generator.
* If it works, it means the currency is not fairly distributed, but anyone sending valid hashes to their network is issued tokens, irrespective of whether the eyeballs described by those hashes exist. This is called a Sybil attack.
* If it doesn't work, it means there is some secret or centralized check that the network performs, which means the currency is not open.
This is why we still use proof-of-work in spite of its energy expense: it is simple to understand, it can not be faked, and it can be openly verified.
So, do not support this biometric-gathering enterprise.
Only losers will provide their real retinas. Smart players will obviously game the system and then dump the shitcoin on yet another group of losers.
Have you seen who they are going after?
> In order to test this model and technology, we have onboarded twenty-five Operators that run more than thirty devices in twelve countries across four continents (Africa, South America, Europe and Asia).
> To illustrate the success and potential of these Operators, we will dive deeper into the operations from the following five countries: Chile, Kenya, Indonesia, Sudan and France.
This is sickening.
Unlimited money!
If you control one of their devices, you could always just modify it fake a live input.
Even if they intend to control the scanners themselves, corruption can probably thwart that. This comment (https://news.ycombinator.com/item?id=29001214) makes it sounds like they may be operating in countries with endemic corruption.
The big logic flaw here is the same one as when the Soviet Union collapsed and shares of the state owned enterprises and assets were sold to the general public: poor people sell the assets to the wealthy.
The entire thing is strange, and doesn’t make sense.
Then again, even PoW coins with no premine can be unfair if most of the long-term supply gets distributed in just the first few years, leaving only crumbs for late adopters.
It's "fair" if you're referring to equal opportunity, not equal outcomes.
Most public places used to have bathrooms which anyone could walk into but no one could easily roll into on a wheelchair. That was equal opportunity.
Nowadays many places have been mandated to have bathrooms such that anyone who uses the space can access a bathroom without difficulty. That is an enforced equal outcome.
Which is the correct approach?
No, it's an extremely relevant debate because a certain political faction has been trying to redefine "equality" from its original definition of "equal opportunity" to a completely different one of "equal outcomes".
> Which is the correct approach?
This is a false dichotomy. You can want equal opportunity in most places, and equal outcome in a select few (just like you can want freedom of speech for everything but a select few edge cases).
This is the correct way to do it, actually - enforced equal outcome is inextricably linked with tyranny and oppression, and invariably results in massive loss of human life when it has been ((ostensibly) attempted to be) implemented in the real world.
If you have to pick one, tell me, which is better - for tens of thousands of handicapped people to not be able to access some public bathrooms, or for tens of millions to die in another Cultural Revolution?
Imagine if half of all gold on earth was already mined in the first 4 years (and over 99% in the first 27 years) of gold mining millenia ago.
Whilst anybody is forgiven for not knowing about the very start of BTC at some obscure mailing list, since then there has been a decade of mainstream media exposure, a huge amount of time to acquire BTC. Failing to make use of this enormous time window is on the individual.
If I have to believe the below articles, miners own less than 10% of supply, so the gold comparison is misplaced:
What I mean by equal opportunity is that Bitcoin treats every wallet owner the same and does not favor any elite or closed group in any way. There's not been a "hidden" period where insiders could jump in, whilst others could not.
That's much different from almost any other crypto, where the development team pre-mines supply and rewards them to themselves before opening sales of their tokens.
Likewise, owning lots of Bitcoin does not reward additional Bitcoin. This rich get richer effect is simply not there. Although rich people do tend to get richer in other ways, but that's not Bitcoin's fault.
This too is different from PoS crypto, where owning lots of crypto rewards you even more of the token.
Sure, and that's fine for equity but really bad for currency.
> Whilst anybody is forgiven for not knowing about the very start of BTC at some obscure mailing list, since then there has been a decade of mainstream media exposure, a huge amount of time to acquire BTC. Failing to make use of this enormous time window is on the individual.
Again, totally fine for equity, shameful for currency.
Fairness and equality are different. Imagine 2 people of different heights who can't see over a wall - equality is giving them both a ladder of exactly the same height even if that means just the tallest person can now see over the wall, while fairness is giving them each potentially different height ladders so they can both see over the wall.
The PoW equivalent (not factoring in premine) would be to give the first person the tallest ladder, and each successive person vanishingly small ladders, which doesn't really come under fair or equal. PoW with premine puts you in front of the wall so you don't need a ladder, plus it gives you a pile of ladders which you can sell to the people behind the wall, and maybe even some bricks so you can arbitrarily make the wall higher if you want.
The above poster was right — it's fair if you're referring to equal opportunity, not equal outcomes.
I've seen this whole ladder analogy commonly used in radical socialist, communist, CRT-type Instagram accounts, used to reframe discrimination in a positive light.
That doesn't imply simplistically equal treatment. If the definition was "equal treatment" that's what it would say instead of "impartial and just".
Impartial and just and no favoritism or discrimination isn't meant to literally complain "hey, you're discriminating in favor of car crash survivors getting physical therapy, that's not fair, everyone should get the same physical therapy".
The definition probably would be better to use the term "prejudice" instead of "discrimination". There's no reality in which people see fairness in absolute lack of discrimination. It's fair to discriminate based on something like medical diagnosis or any other sort of fair judgment of situations.
The false dichotomy of opportunity vs outcomes is stupid. We can't make true equality of either, and we can care about both. And just saying that you see extremists use an analogy is not a reason to reject an analogy. Extremists also wear pants or sleep at night. Anyway, an absolutist no-discrimination view is about as extreme as we can find.
I'm not an expert on "radical socialist, communist, CRT-type Instagram accounts", but I'd have thought they would be more into equality rather than fairness, e.g. everyone gets the same pay irrespective of how much effort they put in or the quality of results.
FWIW in the "Oxford Dictionary of English" that's built into iOS, if I look up "fairness" I get
> 1. impartial and just treatment or behaviour without favouritism or discrimination.
> [...]
(the other definitions refer to pale skin or beauty)
It sounds like your definition is more of a list of synonyms — I was using the current Oxford dictionary available on iOS and Google.
> I'm not an expert on "radical socialist, communist, CRT-type Instagram accounts", but I'd have thought they would be more into equality rather than fairness, e.g. everyone gets the same pay irrespective of how much effort they put in or the quality of results.
Yes, exactly that, and that's what your comment above was doing, no? You reframed fairness as meaning equality of outcome, and framed equality as meaning equality of opportunity. (Equality of outcome = same end-height, equality of opportunity = same ladder height)
We have had repeated instances throughout history of groups of people practicing common ownership, and they do seem to work reasonably well. (I completely grant they aren't super-popular, but, again, I'm not advocating change, I'm trying to understand why you think this qualifies as "impossible")
What do you think prevents this on a planet-level scale?
If everybody has the exact same amount of wealth, it means you've decoupled wealth from anything that is variable, most importantly human individual qualities like risk taking, hard work, talent, brilliance, persistence.
In a world where you can't better yourself economically, most incentives to innovate or produce would cease to exist. To still get a functioning society, a deeply oppressive regime is the only likely answer. After all, why would anybody work?
I suppose you're right that it's not impossible in the short term, just not sustainable in the long term. If nothing matters at all and is pointless, societies' output will degrade over time until the point it is unbearable.
That said, this is current thinking. It's possible to imagine a different equal wealth world that is futuristic. If we get so advanced as to achieve technical abundance, any citizen on the planet would have a high living standard, say upper middle class. Which satisfies almost everybody. And the standard is guaranteed over time, there's no insecurity to it. And those wanting even more things, have everything at their finger tips. Usage based, not owning things.
In such a world, money becomes meaningless. It's no longer a way to reflect scarcity, a way to secure your personal future, or a differentiator of status. Everybody is materially equal at a high and lasting standard. Differentiation might then be found intellectually or in social status. But probably the robots have taken over by then.
We also have repeated instances throughout history of groups claiming to try to implement common ownership, and instead killing millions and installing tyrannical governments (see: most communist revolutions), of consistently larger scale (orders of magnitude) than the successes.
Historically, it's far more probable that such a common ownership experiment will result in death and tyranny (and not actual common ownership!) than a success - and, given the relative difference in scale between the successes and failures, there's a strong argument to be made that as the scale goes up, the probability of tyranny goes up.
This is one of the justifications for it being impossible in a practical sense (yeah, it's annoying that there's more than one definition for "impossible"). It's a fact that power attracts corruption, and it's also a fact that planet-level-scale common ownership would require more power to implement than any government has achieved so far. So, while not "impossible" in the hard-science sense, it's improbable (with a correspondingly large chance of a catastrophically bad alternative) to the point that it's not reasonable to attempt.
That said, your comment is a measured and thoughtful answer to a potentially-inflammatory topic, and I hope that my response is equally thoughtful.
I do hear the "scale" concern, and it's interesting to think about it. I.e. for me, it immediately pops the question "why is scale a problem for common ownership, but not for individual ownership". I suspect - without having any proof - that scale is the thing that makes the transition impossible, not that it's an inherent problem for community property itself. Practically, the outcome is indeed the same - if you can't safely transition, the end state is impossible, even if it itself would be a stable state.
This also raises the question of democracy & unequal ownership as a possible stable state - Plato was certainly concerned enough about it, and history has done nothing to discourage that belief since then. There are plenty of rather deadly examples of failed non-communist states.
If nothing else, your comment (and the subthread in general) has lead me to a rather interesting paper: "Social instability and redistribution of income", by Josef Falkinger. https://www.sciencedirect.com/science/article/abs/pii/S01762... (Yeah, as usual, paywalled. Elsevier)
It's a deliberate attempt at modelling outcomes based on income distribution - which I think attempts to get to the heart of the "impossible" issue. It only tackles income, not wealth, but there's a rich set of references :)
The number of early adopters with “diamond hands”, as they say, who resisted the temptation to sell at $2, $10, $100, … is vanishingly small. History is littered with early adopters who bailed out. Everyone has had years of opportunity to buy into Bitcoin at a fraction of its current value, and if the gamble pays off then people can currently buy Bitcoin at a fraction of its presumptive future value. There’s no unfairness here.
Everyone has had equal access the entire time, and Bitcoin people have been doing their best to get as many people onboarded as possible so they’re not left with “crumbs” after a monetary transition.
Of course, it’s not totally unreasonable to have believed that Bitcoin wasn’t going to work out, but in that case people have no grounds to complain about unfairness - they simply made a wrong choice (by current appearances).
Making money by buying and selling bitcoin is zero sum. People are only making money because other people are losing out. There is no possible way that everyone buys bitcoins and gets rich from it. Bitcoins depends on the existence of rubes and the continual expansion of the pyramid to make money for "investors".
Real estate is not a monetary asset, it's a productive asset - because people need a place to live and you can either live in a house yourself or you can rent it to others. This demand doesn't go away through the introduction of Bitcoin.
Gold is a commodity, not a monetary asset. While a large amount of its value is attributable to speculation it has myriad industrial uses, and jewelry use. Some of this demand may go away as there's a large overlap between goldbuggery and bitcoin maxis.
Dollars have no intrinsic value, but instead their value is derived from demand which is created for them when they enter circulation. They're created via fractional reserve lending meaning that when a loan is issued, new dollars are created but also a debt is recorded - creating demand for those same dollars. That means dollars are 100% backed by demand for those dollars. This demand doesn't go away through the introduction of Bitcoin.
Bitcoin is nothing. It has no intrinsic value, it has no demand, it's simply a speculative number-go-up machine. It's not money, that's for sure. You could try and use it as money but that would be an utter disaster from a macroeconomic perspective.
So yeah, parent is right, its roughly a pyramid shaped MLM with a negative-sum component - the $60,000,000 per day you have to pay to miners to keep the music playing.
[edit] Also note that gold and real estate are not classically defined as "monetary assets" - those are for instance cash, bank deposits, investments in debt capital markets and lease investments. Monetary assets need to have a prescribed value in exact dollar terms.
> Real estate is not a monetary asset, it's a productive asset… Gold is a commodity, not a monetary asset.
This is wrong. Any asset with monetary properties can (and will, in the right environments) be monetized. When the primary medium of exchange is inflationary, people will use whatever non-inflationary value stores they can find with sufficient liquidity. Most of the value of gold, and much of the value of real estate, lie in their capacity as a wealth storage mechanism. They are monetized. Bitcoin does a better job of this and will likely subsume their monetization value.
> It has no intrinsic value
Invocation of “intrinsic value” is a 100% surefire sign of a dysfunctional economic mental model.
That is not the definition of a monetary asset.
"A monetary item is an asset or liability carrying a value in dollars that will not change in the future. These items have a fixed numerical value in dollars, and a dollar is always worth a dollar. The numbers do not change even though the purchasing power of a dollar can potentially change." [1]
Words have meaning, so I guess I'm not 100% sure what you're talking about.
> Invocation of “intrinsic value” is a 100% surefire sign of a dysfunctional economic mental model.
[citation needed]
> citation needed
Give me a minute to find a copy of the Official Rules of Economic Epistemology.
If you’d like to put forward any particular theory that assigns “intrinsic value” to objects I could address it specifically.
I weep daily for my zombie coins.
I'm certainly not defending any of this … however, it should be noted that "creators can allocate arbitrary amounts to themselves" is a typical thing even in regulated markets. Notice how Trump's new social media became a public company through a SPAC? The man behind that move has two degrees from MIT.
If you want to go down that rabbit hole, go for it. But people become very wealthy, very fast, via allocating "arbitrary amounts to themselves" even in regulated markets. Financial shenanigans.
If you haven't heard of the $100 million deli in New Jersey, feel free to Google that one.
I only deal with facts.
Orbs will be remotely monitored and compared to other Orbs. Such monitoring is based on non-biometric metadata from the Orb, including battery level, temperature, and network strength. Anomalies will be flagged and lead to Orbs being deactivated. This anomaly detection happens in the cloud and therefore comes with higher security guarantees than device-level spoof and tamper detection.
What you're mistaken about is that the "currency" is not the same as this biometric airdrop (initial distribution). The airdrop is not open at all. The currency itself, once distributed, is just a token on Ethereum (with optimistic rollups). It's essentially as open as any other Ethereum token.It's a stupid idea. You can appreciate it's simplicity and how everything fits together like puzzle pieces, but it is ultimately a stupid idea because it lives in the real world and has predictable real world consequences.
High energy use in itself is not the issue, it's CO2 emissions. Energy can be locally abundant, renewable, yet remote, hard to transport to civilization. That would be an idealistic example of sustainable mining. Bitcoin mining isn't fully at that level of sustainability yet, but it's a solvable problem.
Bitcoin isn't for rich people. It's for all people. It's highly popular in deeply inflationary regimes, amidst refugees and particular immigrants. The fastest growth in Bitcoin addresses for years has come from the African continent.
No it's not.
These sorts of arguments fundamentally misunderstand the Sisyphean design of Bitcoin's proof-of-work algorithm: difficulty is scaled to absorb any changes in hash power, and expending hash power is rewarded with a chance of minting coins and/or collecting fees.
Bitcoin could be made sustainable and clean today, with no extra infrastructure, no optimised hardware, no new solar panel breakthrough, etc.: miners simply have to turn off their equipment, then difficulty will adjust downwards, and Bitcoin would become efficient enough to run off a solar-powered RaspberryPi.
That won't happen; and for exactly the same reason miners won't stop burning cheap fossil fuels as well as diverting as much renewable power as they can away from useful projects like electrified transport, desalination, aluminium smelting, HVAC, etc.
It doesn't help to speak in simplistic absolutes. Miners can definitely become more green and rapidly so. The massive move from China to the US that took place over the last few months likely has dramatically changed the energy mix to mine Bitcoin, for the better. There's also a Bitcoin mining council to promote best practices in renewable mining. There can be additional incentive structures (CO2 tax) to further discourage dirty mining.
Bitcoin interprets carbon tax as damage and routes around it
We've ignored the issue for decades and fully embraced ACs, huge cars, big TVs, high-end gaming PCs, cheap products from China, air travel and the excessive eating of meat.
Even in these times of peak awareness, the typical consumer continues to add more electrical devices to their homes, install jacuzzis in their garden and get ever bigger cars.
Nobody is outraged about any of this behavior. We deserve these toys and justify them.
Bitcoin simply stands out as an easy scapegoat. It's not that people actually care about sustainability, they simply see something they don't understand or need, hence let's ban it. Compare it to the outrage regarding very large trucks, and people calling for a ban.
The trouble is, there's only a few of such trucks, so it does nothing. It would be much more fruitful to ban or heavily tax big TVs, as there's many more of them. And just like that, nobody's interested in sustainability anymore. Not when it personally hurts. So it's all optics, not outcomes.
I see no value in high-end gaming PCs and think they should be banned. They have no meaningful societal value to justify their energy use. You see no value in Bitcoin and think it should be banned.
Neither of us has the moral high ground. We're all a bunch of hypocrites that hand pick whatever we consider of personal value, and to disregard anything else that others may consider of value.
Silicon brains are the spice of civilization. The only limit on who much e-waste we produce is how fast we can churn them out.
We do new things, and figure out how to manage the fallout for the successful things after the fact.
I could be wrong, but isn't this because distribution of 'free' worldcoin is centralized? Meaning you can create identities on the network that may or may not be tied to a real person's eyeballs, but that identity only gets free Worldcoin if scanned by lets say an Approved™ Orb scanner operated by an Approved™ Orb operator, who is (presumably) verifying that the orb is scanning real humans only.
This is basically Yet Another Shitcoin With Airdrop, but with some effort to try and control 1 human adopter = 1 free coin in the airdrop.
Regardless, that doesn't imply that the network is centralized / controlled, just the distribution of the initial 8 billion worldcoins is (philosophically, you might say that the centralization of the initial distribution of coins means that the network is effectively not decentralized, but presumably the network is running similar code as any other blockchain).
If bitcoin somehow managed to create a system in which general CPUs were the only thing that can be used to mine, it would just mean that we'd have CPU shortages as the people with wealth and power would buy them all up. Or at least, they'd buy up all the best ones and the plebs would get the low clock speed units that can only hash at a fraction of the rate.
The "one CPU, one vote" idea sounds nice to those of us with democratic ideals believing all humans should have an equal vote, but it just fundamentally doesn't work in practice.
Any form of computing power, whether CPU-based or GPU-based or ASIC-based or memory-based, is a possession that can be accumulated by the wealthy in order to grant themselves power.
Mining is not (and cannot be) a perfectly private thing that the wealthy and powerful have full control over. Ultimately, they operate at the pleasure of governments. They are subject to political whims. A nation state could theoretically nationalize all miners in the country if the political capital to do so existed.
What makes bitcoin unique to fiat currencies, is that it is democratic on a global scale between organizations and entities that control energy production and the technological capacity to produce efficient computation. And how these organizations use their voting power is still ultimately driven by the politics within, whether that's democratic or otherwise. It's not "one person, one vote", it's "one hash, one vote". The distribution of voting power across the globe is a constantly evolving thing that depends on how much electricity and computational efficiency different localities can muster.
This is why I personally think bitcoin will be the next global reserve currency. It automatically gives proportional voting power to countries based on how effectively they can summon computation, rather than how effectively they can summon violence and destruction.
Monero has implemented just such a system already (the RandomX PoW algorithm).
By the way, bitcoin miners do not vote. It's not a democracy. Proof of work is not voting. That's important. Democracy would be a terrible system for governing money. Bitcoin is not a democracy. (Some of the proof of stake coins are, and that's bad.)
And why should CPUs get the vote?
I wonder if the NSA is one of their investors?
For marketing, of course. Blockchains are magic, the rubes won't flock otherwise.
Justifying the use of proof-of-work appears to be a fallacy of relevance though
You need a form of scarcity to prevent a Sybil attack. Solved cryptographic puzzles of an adjustable difficulty is one such form of scarcity.
Does this address your concern about relevance?
How is it irrelevant?
A Sybil attack is a single or a small number of entities counterfeiting multiple peer identities so as to compromise a disproportionate share of the system. The actual network of communicating nodes that have copies of the distributed ledger (whether they be participant wallets, miners, validators, stakers, or any other kind of node), and the append-only list or tree of wallet-to-wallet transactions (i.e. the distributed ledger) are distinct, and may be what's tripping up some.
Within that distributed ledger, proof of work or proof of stake aren't what prevents the Sybils from using your (or others') identities on a cryptocurrency's network without your private key. Transaction signatures alone are the mechanism that prevents impersonation. Sybils can flood a cryptocurrency network with transactions with fake signatures all they want, but the transactions would be invalidated the moment that any node appending to the distributed ledger attempts to verify those transactions against its copy of the blockchain or ledger. In Bitcoin's case, the wallet address is the public key for that wallet, and the transaction signature is easily verified by using the source wallet (the one that has a balance) address as the public key for signature verification. (The wallet address is a hash of the public key, and I'm oversimplifying.)
The function of Proof of Work is to mitigate double spending by the same identity, which is a different concept from a Sybil attack, and is not even a type of Sybil attack. That double spending would otherwise "fork" the distributed ledger, and cause two different parallel versions of the distributed ledger to exist - one in which the destination wallet A has the transacted coin, and another in which the destination wallet B has the transacted coin. The iterated game miners play in PoW makes it computationally infeasible for a single party to double spend without controlling more than 50% of mining (e.g. hashing) power in the communications network of participating nodes. In the case of Bitcoin, for example, spending the same Bitcoin wallet balance twice by signing two different transactions using the same wallet private key. That is not a Sybil attack because the double spend (i.e. both transactions) originate from the same wallet. Double spending by a single identity is irrelevant to TFA, and not what TFA is talking about.
TFA responds to a coin faucet proposal (Worldcoin's "Orb" mechanism) that uses a biometric challenge to verify that coins are distributed to flesh and blood humans only, and exactly once. They're mitigating an identity problem with coin faucets, not an integrity or double spending problem that Proof of Work mitigates. (And in a creepy, biometric privacy destroying way, we'll get to that later.)
Coin faucets can be used to give some value (e.g. a small amount of cryptocurrency) to as large a population as possible to enable, for example, developers to play around with the cryptocurrency and new users to try it out before buying in with their own money. The referenced coin faucet is proposed as a wealth (re?)distribution mechanism. Currently, coin faucets mitigate a single or small number of individuals from consuming all of their cryptocurrency by restricting IP addresses, browser cookies, wallet addresses, and other forms of identification. The "Worldcoin Orb" hardware device for that identification collects biometric information (i.e. facial recognition, eye recognition, etc.) centrally to ensure that only flesh and blood humans receive the initial grant of their cryptocurrency. One of the comments here previously mentioned that you might be able to just spoof the output phashes of these "Orb" devices to perform a Sybil attack on the coin faucet in TFA that uses biometric phashes.
Hopefully this helps explain why this type of Sybil attack is distinct from attacks on the proof of work or proof of stake mechanisms, such as owning 51% of the mining power on a POW network or all the validators on a POS network.
As an aside: An encoded, encrypted, or hashed version of your biometrics that can be used to identify you from those biometrics is still biometrics. As long as it is generated from the source material, and uniquely identifies an individual, it's still biometrics, and still creepy facial recognition, IMO.
The concept is simple: give everybody an equal amount of coins. You need a unique identifier / derivative of it
What prevents anyone from mass-generating unique identifiers?
for(;;) new GUID();So al this comes down to several rather simple steps:
- if the algorithm for the hash is known, generate new hashes programmatically
- if not, but the hash is simple, reverse engineer/brute force the hash, generate new hashes programmatically
- if not, generate synthetic retina images and feed them to the algorithm
--- cut off point, and a really don't think you would need anything beyond this point for a shitty cryptocoin like worldcoin ---
- if the algorithm can differentiate between flat images and "actual" retinas, for some definition of "actual", iterate through artificial eyes until they trigger the required response
First, retina scanning output hash is deterministic - it is supposed to generate the same result for the same eyeball. So it can't be replaced with random number generation.
Second, network does not interpret hashes, except for making sure that single hash is awarded funds only ones. Network however pays attention to whom is sending the hashes. It must be "legitimate" Orb units, likely considered to be legitimate because their public keys were whitelisted.
Third, process of distribution of initial tokens is obviously NOT OPEN. You need a "legitimate" Orb unit to participate. Which has nothing to do with how the network will behave for users already on-boarded.
Fourth, PoW has nothing to do with it. PoW is antisybil for people who might add new blocks. PoW has nothing to do with people who just want to transfer or hold funds. Or even with people who can create money according to network rules.
His argument is valid, what stops you from replacing the retina scan with a random hash replicating a different person scanning each time and collecting new tokens? What ties the hash to the actual retina other than the device that you can mess with?
We’ve really come full circle when a blockchain relies on DRM to work.
1. User has a "fake" biometric A, generated via GAN or [1], that's cheap and easy to produce.
2. Suppose they can present A to any orb device, generating hash(A), which signs hash(A) using its built-in private key as usual.
As long as the user can generate a fake iris biometric scan accepted by an orb, no other part of the system needs to be compromised for this attack to work.
1: http://iab-rubric.org/papers/ICPR14_1649_FI.pdf , note that liveness detection is a cat-and-mouse game
or leaked
Admittedly I never bothered to read about it but the problem they are solving is purely the distribution. Currently there's just no way to do a fair distribution where everyone gets equivalent amounts of it except perhaps with KYC but then they have to store way more personal data.
I'm much more comfortable with someone having a hash based on my biometric data than having my passport and other details.
Same here. My point is - fair distribution is just a means to achieve a goal of "more equality". As a mean it is an equivalent of giving man a fish instead of teaching him how to fish. At most a PR stunt.
Actually, the lowest state of the art false positive rates for biometric id is achieved by iris scans, so I have to wonder why they went with retinal scanning in this case.
Note that I'm not saying you can intentionally cause a false positive or false negative very easily. These are both highly reliable identification methods. But they're not deterministic, so if you're hashing the literal scanned signature, the hash output won't be deterministic, either. Presumably, what they're doing isn't hashing at all. Normally, for biometric id you just store the signature in a database and use a thresholding function to match against it when new scans comes in.
They didn't. It's an iris scan. The article just used "retina" and "iris" interchangeably for some reason. https://worldcoin.org/how-it-works
I don’t know much about retinal scanning. But for this use case, wouldn’t it be trivial to fake via something like different coloured contact lenses?
So the distribution seems completely centralized. A central authority distributes the coins however they wish.
Today they might use a process involving eye scans. Or maybe not. There is no way to check. Tomorrow they might change their approach however they like. And we would have no way of knowing.
The issue that seems to be overlooked is that there is no way to look at a hash and decide if it was created via scanning an eye. The hash is signed via some key that - according to the makers of WC - sits in an eye scanning device which behaves a certain way. But we have no way of checking that.
It includes a projection graph that has a scale in 500m user increments and 2 years. Then you have the real data: over 6 months they've signed up 120k users. Or to put it another way - their real data doesn't even appear on the scale that their projections are displayed. They've basically extrpolated from 0 to 1.5bn. Oh and the graph lists sign ups per orb as if manufacturing the orbs is the limiting factor for signing people up to your shitcoin.
It also claims they're going to give out thousands of these orbs. But these orbs are the trusted hardware devices for generating unique hashes from biometric data. So if 1 of these thousands of devices falls into the hands of a hacker who can crack the hashing algo they're done. Not only will they have no guarantee that the users are unique, and probably they've also leaked huge amounts of biometric data. They actually mention this on their how it works page - don't worry guys, they'll make it hard to spoof! Honestly. It'll be tamper proof!
I kind of understand how you could try and argue that these devices are ok if you're going to have a small number of them extremely securely protected, but the plan is literally to manufacture 4,000 of these per month and hand them out to random people. Honestly, it's like they've just never had a conversation with someone who thinks critically about anything.
Having met Altman, "fluffy bunny" is not a too far off assessment.
Is there a word for knowingly becoming the villain because you've decided that the force of Moloch in civilization is unstoppable and if it's not you who uses your power to take control of something vulnerable and weak, someone else eventually will, and they might actually be malicious.
The regulation can take into account several factors to make the barrier for smaller projects not too high.
Except that making more rules doesn't actually remove social problems. You have to pay for judges, lawyers, courts and prisons; and the lives of rulebreakers get ruined. And the problem persists.
Engineers sign off on a building, if it falls hundreds could die. We don't do anything that grandiose usually, but sometimes software can have extreme impact on the world, and thus we should be prepared to consider the consequences of our actions thoroughly.
FYI this project (and basically every cryptocurrency project) already falls under some kind of financial regulation in most jurisdictions.
Similar to tax and accounting regulations, as you grow these regulations grow, too. For example you might need to provide risks and threats analyses for your technology.
You're liable to provide this information to the best of your ability given context (e.g., they wouldn't require a 30 page risk analysis from a indie hacker who has 20 users). If it turns out that you provided false information delibrately, or acted in bad faith, there are consequences like fines, bans, and so on.
Of course, based on your technology the government can prohbit you from bringing it to market, add constraints or require more info.
I think the idea is terrible. You want laws to be prescribed and debated, not allow some administrators to make shit up on the spot.
> sends eye-scanning Orbs (his name) to Africa to pump up the value of Altmanbucks that his team owns 20% of
I'm laughing now at how cartoonish this guy is, but might not be laughing later when my children must Surrender to the Orb to pay off their fathers' crypto-debts.
I understand what Sam is going for here (equitable distribution of wealth) but this is absolutely the wrong way to go about it.
Not for or against Worldcoin with this comment just saying there is likely a different motive.
So con artist and VCs created "crypto" where every con artist has there own money
When VCs hate it, it means it really, really good.
There's no such thing as the money supply. There are many currencies, each one with its own supply.
I doubt very much that the masses will be scanning their retinas into The Orb so that they can get Worldcoin, but these people are not going to stop coming for your retina, your DNA, even more of your digital fingerprints, etc. Sadly, they're eventually likely to get it all.
But now, I can see a clear line between the data we're collecting today and the data that would be that much more useful like DNA.
Not mine! But WTF, I'm just a paranoid weirdo.
If I have access to the data of 95% of people in a society, I have enough to model and predict behavior, and maybe even the hooks to inject information and influence future behavior.
The long tail of paranoid weirdos who spend all their time and energy fighting to maintain their privacy are irrelevant to the goal of societal domination.
FWIW I don't spend a lot of energy; it's become habitual. I just don't hand out my PII simply because someone asked. And if people ask me for PII when I don't think they need it, I'll deal with the hassle of finding another way to solve my problem.
I know that my attitude is irrelevant to the behaviour of the snoopers. I'm not trying to train them.
I had a conversation that touched on privacy once with a person I met at a bar who works for Big Evil Tech Co. and she basically came out and said this in slightly more diplomatic terms.
SV elites have understood that you can wrangle money and control out of unsuspecting and uninformed consumers for decades. Which is exactly what they are doing here via. a new shitcoin; they get both control and money!
I'd say they are very much in touch with the real world.
Does the specific mechanism they're attempting to employ raise some concerns? Sure. Instead of the vitriol though, how about some suggestions for a better mechanism?
Trying to tear people down who pretty clearly seem to be making a good faith attempt to make the world a better place is reprehensible in my opinion. What does that say about you?
Also, >Trying to tear people down who pretty clearly seem to be making a good faith attempt to make the world a better place is reprehensible in my opinion.
Seriously? What an absurd notion. Oh hey, X attempt was in good faith! What a terrible person you are for criticizing it... Not to compare Altman with people like Lenin but I suppose that by this logic, one is bad for criticizing revolutionary demagogues because their hearts were always in the right place?
You should never let your minors or relatives or friends close to this app. If somehow they scanned their eye with this Blockchain app, it will stay.
Your personality and opinions may change but this will be a mistake you will always regret.
This seems like a solution to a problem that isn't really a solution.
2) currently some countries planning/want to implement covid check-in at every place you wanna enter
3) and now you have to worry that some private company want to make a modern fingerprint (irisprint?) that most likely is going to be used to at least another way of ad tracking.
However with 3) you won't be able to easily protect yourself - you cannot change eyeballs. Maybe you will have to wear some special contact lenses.
- Iris scans have false positives at scale
- You can have eye surgery changing your iris
- Cheap scanners can be fooled by photos, so you'd need to require live-tissue scanners which are really expensive
Apart from the arguable concept itself, I'm genuinely wondering why betting on yet another scanning device, instead of using fingerprint scan, which is now available on most smartphones ?
Is it that much more reliable that it's worth going through the pain of engineering a new hardware ?
Finally, how they could expect any other reactions than doubt, fear, and reject, out of this solution, while fingerprint and face detection already go through so much ethical issues ?
It looks to me like they're targeting people who are not as concerned or thoughtful about such issues.
Could Altman perhaps sit down and fucking program something himself? Show us your code.
That or orb-owners will just set up a booth in poor areas of the world and give people cash for a scan, pocketing the distributions forever.
From the article: "We use the open-source Semaphore[19] zero-knowledge proof system to transfer the uniqueness of IrisHashes to the uniqueness of user accounts, without linking them."
Now, of course, one needs to trust that Worldcoin is actually doing what they say they are doing, but that is a different discussion.
Edit: I see now that they are saving this data during field testing. But it looks to me that the long term plan is to use ZK crypto to unlink the hash from the account. Snowden's "hot take" ignores this.
https://semaphore.appliedzkp.org/ https://z.cash/technology/zksnarks/
See this page: https://worldcoin.org/privacy-during-field-testing
We collect the following data through the Orb after the user gives us their consent: Images of users’ body, face, and eyes, including users’ irises (visible, near infrared and far infrared spectrum) Three-dimensional mapping of users’ body and face
If their system were hacked or misused by authoritarian governments, the damage would be huge. And they're basically telling the world "trust us, we'll figure it out" without proving they can do it.
The risks as I see it are authoritarian governments figuring out the tech and using it. Or compelling Worldcoin to do their bidding.
Storing hashes in itself doesn't seem like it can be abused. Suppose Worldcoin has a database of a billion hashes, then an authoritarian government decides to compel Worldcoin for some nefarious purposes. What then? What bad stuff could happen?
Right, and that's a big part of the problem.
With all of the data abuse that the industry has already engaged in, it's silly to trust any company just because they say "trust us". Worldcoin has given no reason to trust them.
I guess if you want to be part of the new world currency you better not have any disabilities or disfigurements.
"“What’s in the case, Buschel?” Seersucker bunched in his fist, knuckles white and shaking.
“Damn it, Turner,” the man jerking free, the handle of the case clutched in both hands now. “They weren’t damaged. Only some minor abrasion on one of the corneas. They belong to the Net. It was in her contract, Turner.”"
Like other crypto projects, they misleading fit their data with the wrong curve. If you fit growth numbers with an S-curve instead of an exponential, you get results that are highly sensitive to noise in the initial data:
https://constancecrozier.com/2020/04/16/forecasting-s-curves...
This is why it will end up being the case that the actual number of users signed up for Worldcoin in 2 years was assigned a probability of ~0.00 by their growth model.
Still, there are so many ways this is bad, it's not even funny. Starting with the question of granting anyone without a retina access to the technology...
The scan is in no way tied to your account at any time.
Many of the comments here would be better informed by reading how this process works. There are issues to discuss, but a lot of what's in these threads has nothing to do with the actual workings of the project.
>We collect the following data through the Orb after the user gives us their consent: Images of users’ body, face, and eyes, including users’ irises (visible, near infrared and far infrared spectrum) Three-dimensional mapping of users’ body and face
I'm very doubtful about this. This process is either completely centralized (which means privacy is at risk), or not going to work properly.
My experience has been: the more you think about the Sybil problem, the harder it becomes.
Let’s ignore the fuzzy utopia talk and pretend that this is just a creepy plot to get a hash of every single person’s eyeballs.
What’s Sam’s next move?
What do you do when you have the hash of everyone’s eyes?
The same thing you do with everyone's Amazon purchase habits, porn watching habits, and their social media behaviour: sell it!
The only real question is to what end, and to be honest one need only look at the dystopia the CCP are creating with their survielence model in Xianjing to see how pernicious this all is when it's in the wrong hands.
You have entities hell bent on creating some sort of minority report type prediction system, though to be honest I think it's more like Psycho Pass at this point: one where their is a clear divide between classes of people and their obedience to the system, which I guess in this case would be 'the Orb.'
In psycho pass it's a sort of Hivemind of the most brilliant to the most violent members of society to try and predict any and all possible outcomes.
Silicon Valley tropes have bled into real life for far too long, be it wokeness, to the fomenting of discord via social media as a business model to sway elections (something intelligence agencies and political parties have clearly made use of) or create discord in Society and to be honest it's exactly why SV's influence has to be curbed. The honest answer to what they will do with the data is: we can't possibly know, and that's why it shouldn't be done.
Auroracoin was trying to achieve a UBI drop in Iceland as a response to the calamity from the 2008 financial crisis, with noble goals but failed in 2014, and while I think it is something that I think should warrant more focus from developers and VC money it's hard to envision how they completely bypassed how Microsoft's ION [1] has been working on ID on the Bitcoin blockchain for years they could have built on top of.
I'd normally lambast anything MS has done, but it's open source and operates over the most secure network, why are we allowing Altman and his YC/SV cronies to hi-jack the narrative that collectively those of us in this space have been working on trying to address this in a trust-less manner for nearly a decade?!
0: https://en.wikipedia.org/wiki/Auroracoin
1: https://topbitcoinbuyer.com/2021/03/26/microsoft-launches-id...
If your wallet is unique to your person (eyeball) and the public key is ever leaked, everyone can see your account balance and transactions.
Would that be the case or am I missing something?
The device itself is likely tamper resistant, has built in DRM and will have a high fidelity camera + signal processor. So you will need a system to write a 200MP image on the surface the size of an eye ball.
Also, since the light passes through a lens in your eye, there are probably optical tricks that can validate the surface is curved like a retina and has been distorted by a lens.
Oh yeah. And the vascularization of the retina means that you can view heart rate pulses. So your image will need to pulsate too.
One could also imagine marrying this with a stereoscopic camera to image detect that a real face is. It could even ask you to smile or frown to validate it's a real face.
Lots of ways to harden this technology to the point where even intelligence agencies would struggle to defeat it.
Even without the Demolition Man scenario, an even worse issue is that you can't change your biometrics in case somebody steals them. Fake fingerprints are already easy to do, other things surely can be cloned, too.
Those are scenarios that biometrics are handling really well.
Biometrics against sophisticated attackers is not good idea. I don't encounter in my life "sophisticated attackers" that would spend time making copy of my fingerprint.
If you are person that has risk of running into sophisticated attackers then don't use biometrics and biometrics are bad idea.
For convenient security you want just enough complexity a bot wont automatically unlock it, for proper security something that can be even a bit unconvenient as long as it's more secure.
I agree, biometrics should probably be in the "breakable, convenient" category.
Personally, I don't see any reason to make overly easy for any of those parties. So no biometrical data to be exchanged for some new form dogecoin.
Don't underestimate the lenghts some people will go through for a harmless prank. But you are probably correct a modern phone's fingperprint-reader is probably not fooled by an etched stick of gummibear.
Incidentally - I always wanted to have a device that you could stick your finger into, that would use a, let's say, laser to etch different fingerprints onto the tip of my finger.
IIRC there was an attack that was able to get past the liveliness checks by putting the fingerprint replica (a thin piece of dried elmers glue) onto a real finger.
The sensible approaches for biometrics use them to unlock strong keys which never leave the device. If implemented correctly, this is somewhat resistant to offline brute-force attacks — certainly not impossible but not economical for going after most people.
In truth I have seen this done to mess with people using cellotape and creativity, so I have to warn you this is not a reasonable assumption.
> Biometrics against sophisticated attackers is not good idea. I don't encounter in my life "sophisticated attackers" that would spend time making copy of my fingerprint.
You don’t yet, but we’re talking about a new form of currency in this thread, not unlocking your phone to text your spouse or show your kids a youtube video.
Money is power, which will draw in sophisticated attackers who want to amass more of both.
I know a few kids and coworkers who absolutely would, if it would get a laugh.
Some people would set their pin the same as their debit card just to remember one number instead of multiple.
That is why finger print unlocking is quite great for day to day use.
Of course it is not enough for more complex security scenarios, but as someone else mentioned lock on my doors is quite easy to pick but still it is good enough for most of people.
https://www.macrumors.com/2019/01/14/forced-biometric-unlock...
You can easier be forced to face unlock or fingerprint unlock your phone than be forced to remember your PIN
But seriously, damn are this the best we can come up with other than captchas good lord so dystopian
Same with intentionally vague headlines. One this morning was "Why you should avoid this large European country after latest CDC update". It's a great signal that the article is full of fluff wording and unlikely to add useful additional insight and if I really care I should go check the CDC news bulletins for the actual news.