Worldcoin isn’t as bad as it sounds: It’s worse
blockworks.co
blockworks.co
So this is just any other coin with extra steps, and the extra layer of trusting Sam Altman with your eyeballs to generate secret keys?
[1] https://www.coindesk.com/policy/2023/05/24/black-market-for-...
I guess crypto is fundamentally that. Trust, fraud, identity, insurance, are all very complex things that require massive institutions to manage successfully. But these crypto organizations are always just, shrug "yeah that's not our problem. Whatcha gonna do?"
I guess that is the core principle to begin with. But it's interesting to watch it in action. "Oh that big ball of wax? We don't address it. Not our problem."
The rare few which are pretty upfront in saying that in exchange for their strong privacy guarantees the user is fully responsible for everything, are the only ones with any real utility (eg Monero).
But there are only 8 billion people, which is literally an infinite improvement over the status quo.
And if worldid was ever used for a voting system, wiping out the votes of people who come from a specific area would be incredibly valuable. Attacking people’s identities even for only a few dollars each is a multibillion scam industry today.
I'm a huge fan of Wilson and Korzybski, the ideas Wilson discusses in this lecture definitely changed my life and the way that I think about science, but even I would caution that it's not all that relevant to the discussion here.
There is a chain of complexity where subatomic wavicles assemble into atoms, molecules, self-reproducing molecules, cells, multicellular life, specialized multicellular life, different clades of life, and on up to forms of intelligence and self-awareness.
It is not possible for a human-equivalent intelligence to maintain continuous awareness of all these levels of complexity, and so we operate, much of the time, in abstractions and metaphors that we mistake for being real. We code-switch, consciously and not, through sets of behaviors that pretend that various abstractions are real.
Among these abstractions: a town is a group of buildings and people, but different social abstractions don't have to agree about the contents. So the post office, the street maps, the police and the real estate agents can all be simultaneously in disagreement about the house where the author lives in terms of their mappings of "towns" and "jurisdictions", yet all agree on the street address and which building they mean.
When you can't do something because it's illegal, you can do it, but you know that various social institutions will attempt to inflict various consequences on you if they become aware of your action in the appropriate ways. But most of the time you just say "I can't" and fall back on "I shouldn't".
There's a lot more, but it's about the same: we build lots of maps, we don't agree on them, but we keep acting as though they were real even though we know that they aren't. When someone is invested enough in their current map, they can become very upset with someone who points out that it's fictional.
https://www.npr.org/sections/ed/2016/08/05/488669276/remembe...
I strongly second latexr's recommendation of Scott McCloud's "Understanding Comics", and the spread he linked to above. Scott McCloud is the Marshall Mcluhan of Comic Art.
https://web.archive.org/web/20220819061912/https://i1.wp.com...
The whole book is fantastic. I recommend it even to people who are not into comics.
I don't think it does that, though, at least when used as a currency. The irreversibility of crypto transactions means that you have to have some trust that the person you're dealing with will be willing to make things right when erroneous transactions happen.
The cypherpunk answer to this dilemma is that revertability of transactions under some circumstances is a service that, if it is desired (for quite some applications of cryptocurrencies, it is), should be build in a layer above the "bare-metal" blockchain.
It doesn't mean you can't get ripped off by the party you're transacting with directly, but neither does cash, unless you pay for some kind of insurance. Which you can also do with cryptocurrency.
Credit cards come with a form insurance built in, but that doesn't mean you're not paying for it (they charge fees), including when you trust your counterparty and don't want to pay extra for insurance on a low-risk transaction.
That's all fine if you're a cryptocurrency guy, but in terms of what ordinary people mean by "trust", I don't see how cryptocurrency removes "the need for reputation and trust." You still need those things.
> neither does cash
True. Which is why cash also has a need for reputation and trust.
All I'm asserting is that the need to trust people is not eliminated by using cryptocurrency. How is my assertion wrong?
You say that it doesn't do that, because someone could break into your house and install a hidden camera to capture you entering in your credit card number and it doesn't prevent that.
But you use other things to prevent that. That isn't the kind of security that TLS claims to provide.
And notably, there aren't a lot of alternatives to the kind of trust that blockchains would allow you to avoid placing in the likes of PayPal.
Except it doesn’t. That’s exactly what we’ve learned over the last decade. It never did either of those things. What it did is that it clouded reputation and trust just about enough to trick people into the illusion of a “trustless” system. There is no such thing. In the end you trust the coders trusted by the people who use the apps implementing the blockchain. There’s no tangible difference to trusting the coders trusted by the banks you use. Yes, with some cryptocurrencies they’re not associated directly with a centralised organisation. But that will absolutely change over time if the cryptocurrency ever becomes relevant to the big corporations of the world. Just as the WWW in practice now is controlled by Google and Apple.
The point of selling the idea that a cryptocurrency is “trustless” is to trick you into trusting it just long enough to pull off a Ponzi-scheme or rug-pull. And yes, that goes for Bitcoin too.
Holding a bunch of bitcoin or mining a bunch of blocks does not allow you or anyone else to redefine bitcoin's fundamental rules.
These are incorrect statements.
I buy this.
Daniel Suarez had a very similar idea, although he referred to it as the bot problem[0]. I believe this approach of identities withstanding "the test of time" solves the oracle problem but at the cost of a delayed solution. Initially you have lots and lots of bots and Sybil attacks are common. Then after a while, identities/nyms that exist and interact with the world increase in trustworthiness. Trustworthy identities will eventually be stolen or sold to bad actors, but like fake identities today they will be expensive.
My identity on hackernews is over 11 years old. Creating such an identity with the comment history, connection to a true name, and content over 11 years would be very expensive. Likely more expensive that a fake passport.
For instance Islamic State terrorists were buying counterfeit passports allowing them to enter the EU for 15,000 USD [1].
The major downside of such a system is that isolated people or people with few resources would be at a major disadvantage and we would essentially be replicating much of inequality of the credit score system.
[0]: Daemon: Bot-mediated Reality, Daniel Suarez, https://www.youtube.com/watch?v=RS5i1S8FXno
[1]: "One such network, run by an Uzbek with extremist links living in Turkey, is now selling high-quality fake passports for up to $15,000 (£11,132) purporting to be from various countries. In at least 10 cases the Guardian is aware of, people who illegally crossed the Syrian border into Turkey have used his products to depart through Istanbul airport.", https://www.theguardian.com/world/2022/jan/31/revealed-how-f...
I think you can get there with something like Urbit IDs that are easy to ban. If IDs are not infinite you can some protection against abuse - pairing that with some proof-of-humanity and you can get closer, but there are still issues of someone doing the proof and then selling their ID to a bot. At least if it's easy to ban you can try to make that not economical. Doubly true if the IDs have a non-zero (but low) cost.
Helps make you resistant to a sybil attack: https://en.wikipedia.org/wiki/Sybil_attack
The problem isn't trivial though - it's not obvious what will work best and it'll likely always be somewhat of an arms race, especially if you want to keep privacy.
I think something like this could've worked, which is why I was so sad over its demise. I think Keybase (like the MIT PGP keyring, which it is sort of a fancier version of) was predicated on the idea that it's much easier to build a centralized keyring and then decentralize it once it's widely adopted than to build a decentralized keyring from the ground up.
I'm curious where Keybase would have gone if they were better incentivized to explore that before its demise.
Not if you have access to the HN database :^)
Not that everyone writes great comments, all the time, but I'm arguing you probably won't break into the 1000s of HN karma if you try to automate it (because you'll probably get shadowbanned first)
Sounds like a great system, let's do it.
I've tried to recover them, and faced a (perhaps justified) customer support brick wall. Was Neopets to anticipate Millennial nostalgia (and our preteen willingness to circumvent COPPA) in their sign-up processes a generation ago? How obligated is Reddit to investigate someone's claim to any single account?
But without those accounts, I'm two closer to being a digital non-entity, for significant portions of my life.
I also wrote about almost the exact same thing as what Worldcoin is doing back in 2006:
https://www.alexkrupp.com/fourwebs.html
As proof of the original publication date, not only is it in the Wayback Machine, but it's also cited in several academic papers and books. It's great that someone is actually doing it, but I'm also kind of ticked they didn't cite this essay as prior art in their patent application.
You can buy very old accounts on any platform for very cheap. Like under $100 for a 10 year account on a popular platform cheap. Most platforms offer comment editing, and most people don't archive everyone else's profiles nor do they have access to the database to check for consistent changes.
Meaning that if we use your account for example, if someone bought it from you (or it was hacked after inactivity and you don't care for it, etc), they could easily rewrite what they need to paint the picture that your user isn't actually about using your real name, but a pseudonym. Most aren't going to care about this that far anyways, as usernames are easily ignored on most sites, same with comment histories. Just indicating how easy it is to rewrite both of those aspects.
The only platforms where this would be difficult are platforms that already partake in substantial identity verification like Facebook.
A fake passport can trick some people some of the time but not all people all of the time. As such those $15k do not represent a full fake identity. Your history of enhancing with the state in some way, paying taxes, requesting a new passport, getting your drivers license, whatever, serves as defense in depth.
States are pretty good at this, actually.
Also, you account is worthless. Hard or impossible to replicate, sure, but if there is no buyer it‘s worth zero.
To expand on this and correct your first statement, physical engagement can't be a proof of personhood either.
There can never be a proof of personhood, or if someone is a human or not, or if someone is conscious, etc.
It's more practically applicable than it sounds. Think conjoined twins (sharing a brain), disabled people, people in coma, long memory loss and all other edge cases.
The mistake he made is adding blockchain and crypto to that physical verification.
But if there was a bot that was well behaved (for whatever that means for a given service), and somehow legitimately viewed ads, and could legitimately decide to buy something with real money from an ad, there's a lot of sites that would no longer want to ban that particular bot. Now they need to distinguish between that bot and the other "bad" bots. In general, if a bot can "behave well" we don't necessarily want to kick them out just for being bots.
In the end, the more bots become like humans and humans through things like the Mechanical Turk become more like bots, service providers will be required to very carefully think through what it is they actually want to demand of their users. Splitting people into "human" and "bot" is already only an approximation on the grounds that there's plenty of humans services don't want around, and there's already some bots that services are fine with (e.g., some helpful reddit bots), so that split isn't going to be good enough. The process of thinking through what is really desirable at a much higher level of detail will be fun to watch, and there will be a lot of different answers for different services.
Not even. People have been having double-lives for a lot longer than we've had the Internet. The difference is that in physical space it's a lot harder to do so, because you can only be in one place at one time and you have to move from place to place rather than teleporting. So if you want to catch someone in the act of, say, voting twice, you just need to trace their movements.
That being said, there are also plenty of situations in which we consider having multiple identities online to be a good thing. Facebook's "real name" policy - forcing everyone to tie themselves to a government issued legal name instead of just a consistent one - was and is cancer. The whole industry of V-Tubers literally runs on talent living a double life and a healthy dose of kayfabe. And we don't yell at character actors because Robert Downey Jr. is also Iron Man.
Anonymity is considered a vital bedrock of liberal values. But so is voting, and this is where being able to create additional identities becomes a problem very quickly.
Wikipedia has an interesting problem of "ripened socks" where people will register multiple accounts and keep them in reserve, specifically to defeat accusations of sock puppeting. This can be detected, but it's murky - are you actually a sock puppet, or do you just lurk Wikipedia a lot[0]? You could probably even go further and split your editing history across multiple sock puppets. Statistical analysis might be able to reveal that, say, two accounts tend to edit the same set of articles, but that would also have a high false positive rate and disenfranchise other editors.
The underlying base assumptions of the crypto crowd is a sort of extreme para-identitarianism. Anti-identitarianism in its extreme would be something like Japanese-style imageboards[1], with their obsession over anonymous posting. Identitarianism would be Facebook's real name policy. Paraidentitarianism instead wants identity to be a side effect of resource scarcity. An identity like a signing key is non-scarce, I can just make more keys, so you cannot hold elections by simply counting the signing keys. But the money in your Bitcoin wallet is a paraidentity: it is provable scarcity, and thus can be bent into a sort of identity, at the expense of disenfranchising everyone who has not bought into the system. In fact, crypto hucksters explicitly threaten people who do not buy their coins of being left out of their future utopia.
[0] I am in this situation
[1] 2channel, Futaba, 4chan, etc
- They clearly don't want accounts that don't belong to a person ("Keep the Bots Out" is an explicit goal).
- They also don't want one person with more than one account (World ID is intended to solve the problem of governance by ensuring that each person gets only one vote).
Cool.
Ssh is a scam. Got it.
Separately, I strongly suspect that your idea of worldcoin's "stated purpose" is not something they have ever stated.
If the lock manufacturer asserts or implies greater protection than the product offers (which is actually quite common), then yes, it's a scam.
I encourage you to read their whitepaper, where they state that world id is indeed a proof of personhood. The allegation in this thread is that it fails at proving that someone is a unique person, and it cannot possibly due so because of the oracle problem. Therefore it is a scam.
"proof of personhood" is something of a term of art which worldcoin did not invent. They are not literally claiming they can prove, in a mathematical sense, personhood. What would that even mean? See for example this, which seems to have originated the term in 2017: https://berkeley-defi.github.io/assets/material/Proof%20of%2...
"proof of personhood" was created in contrast to "proof of work" and "proof of stake". If you want to get technical "proof of work" is also not a mathematical proof, it is more of an argument of work, since it's possible to get lucky and find a low hash without doing all the work. The word "proof" is not doing what you think it is doing.
There are a couple other "proof of personhood" protocols and none of them mathematically prove personhood, because that is obviously impossible, some of them are listed at the beginning of this post: https://vitalik.eth.limo/general/2023/07/24/biometric.html
The value of the biometric is in ensuring a ~ more fair ~ airdrop. With bitcoin the people who discovered it first and who were able to run miners received an outsized reward, and consequently the distribution of bitcoin is extremely unequal. The usage of biometrics doesn't _completely_ solve this problem, there is still a pool of insiders who have an outsized amount of wld, but a very large number of people will be able to walk up to an orb to claim some wld and they will all receive roughly equal amounts. The initial distribution of wld will be much more fair than the initial distribution of any other token or currency I know of. That is the value of the biometric.
Assuming this thing actually works and won't accept irises grown in a vat or someone scanning a chimpanzee, it at least rate-limits you to creating new wallets with new coin at the rate at which you can find and coerce other humans, but it doesn't actually guarantee the 1:1 mapping of wallet:human or an equal initial distribution of coin.
All it's doing is shifting the balance of power from people who command many machines to people who command many other people. It's like reverting industrialism back to feudalism, a digital replay of the same mistake made by every communist revolution of the 20th century.
> What prevents a factory owner from having all of his employees grab an orb, scan their irises, claim their coin, and then hand over their wallets to him as a condition of employment?
The airdrop is gated in multiple places. Everybody needs to visit an orb to claim worldcoin but the set of active orbs is managed by worldcoin and when one of them acts suspiciously the orb can be deactivated, among other counter-measures. A set of wallets all owned by distinct people will act differently than a set of wallets controlled by one person.
This is obviously not perfect, some fraud will occur. It is still a more fair initial distribution than any other currency I know of.
And how is this not a lie when it's so easy to game? It's only shifting the distribution from people who were running a computer early to people who buy biometrics early, steal biometrics or find ways to fake biometrics. And even worse, if you were once robbed of your biometrics in that system, you have lost it forever as I understand it? Is there even any way to get back what was robbed from you?
And just out of curiosity, does this system handle collisions of biometrics? Or is it just assuming and hopes for none to happen?
I'm not sure what you mean by buying biometrics early, stealing them seems very uneconomical, and faking them is an engineering challenge which seems quite difficult.
> And even worse, if you were once robbed of your biometrics in that system, you have lost it forever as I understand it? Is there even any way to get back what was robbed from you?
The biometric is only used for the airdrop. It is possible to create a wallet and send and receive transactions without ever visiting an orb. The only thing the biometric does is send an initial amount of WLD to your wallet and ensure that you can only receive that initial amount once.
If someone steals your wallet there is no getting it back, it is not linked to your identity it is just a private key. I'm not really sure what it means in this context to steal your biometrics?
> And just out of curiosity, does this system handle collisions of biometrics? Or is it just assuming and hopes for none to happen?
This is territory I don't know very well. I believe irises were chosen specifically because they were not invasive and they contain enough entropy that the chance of collisions is quite small. I don't know if it has enough entropy that they can be sure there are no collisions or if it has enough entropy that the expected number of collisions was tolerably low.
Then Worldcoin is a scam.
https://www.technologyreview.com/2022/04/06/1048981/worldcoi...
https://www.buzzfeednews.com/article/richardnieva/worldcoin-...
If we're going to be critical, let's at least understand how it works first.
Just some simple examples:
> Imagine that your digital identity has been lost in some way — shut down by authorities for non-compliance, or otherwise blocked. With traditional cash — and other cryptocurrencies — you can always make a new wallet and stash some fresh coins in it. But this isn’t Minority Report, and you can’t get a new iris from your neighborhood surgeon.
You don't need to walk up to an Orb to create a wallet. You can own and transact worldcoin without ever showing your iris to an orb.
> When your immutable digital identity is locked — imagine merchants who won’t take your coins from you without a digital signature announcing your World ID — it’s over for you. No old account. No new account. No soup for you. You just lost your digital personhood.
This is also possible... with every other form of payment? Imagine merchants who refuse to accept cash. Once the government locks your credit card you're out of luck. Imagine a world where you have to sign in with google before you can pay for anything (why is the worldid dystoia apparently so easy to imagine, while the google one seems silly?). Once the government locks your google account you're out of luck. A dystopia has _many_ levers to pull and refusing to deploy worldcoin is not have any impact on the success of that dystopia.
There is really so much that it's not possible to clarify "exactly" what others aren't getting in a single comment, there are a dozen different misconceptions, if you have specific concerns I'm curious to hear them and attempt to reply to them.
From worldcoin.org
> could drastically increase economic opportunity, scale a reliable solution for distinguishing humans from AI online while preserving privacy, enable global democratic processes, and eventually show a potential path to AI-funded UBI.
This breaks down into 3 claims:
1. Be able to identify humans from AI online in a privacy preserving manner 2. Provide a platform for global democratic processes 3. Provide a universal basic income.
If we cannot agree that these claims are Worldcoin’s main goals then I am afraid Worldcoin is going to need to update their website as I do not see how it could be interpreted any other way in the language they use.
So now that we have their claims we can begin to look at some concerns. Starting with the ones you provided:
> You don't need to walk up to an Orb to create a wallet. You can own and transact worldcoin without ever showing your iris to an orb.
If this is possible, they why is the orb necessary and how can Worldcoin provide the guarantee that everyone using their wallet and blockchain is in fact a person? If UBI and voting are to happen using this as the platform, not needing verification via their iris scanning mechanism calls into question how they can claim to prove that each world id maps to one and only one unique human. If anyone can create an account without verification and transact using Worldcoin then voting and fair distribution of UBI cannot happen the way they describe.
The second concern is something that can happen in the non-crypto space. But if this is a valid concern of the current system, replacing it with something like Worldcoin doesn’t resolve that concern. We would have that same problem. So if we are to replace the current system with a new one, why would we willingly carry over these kind of issues if it were possible to not do so?
Now on to my concerns. I am not an expert in cryptographic mathematics and the nature of zero-knowledge proofs. So I will accept the following:
1. Iris Hash generation is cryptographically unique, privacy preserving, and the database of Iris hashes will be deleted.
2. Iris Hash to World Id is generated in a sufficiently zero-knowledge proof way that makes it so an Iris Hash cannot be used to identify any one specific World Id.
3. World Id to Wallet Private Key is also generated in a sufficiently zero-knowledge proof way that makes it so an Wallet’s private key cannot be used to identify any one specific World Id.
With those assumptions, I have the following concerns:
1. Has the company behind Worldcoin allowed for 3rd party audits? Code reviews, attestation of the zero-knowledge proofs, and other standard security audits we would expect of a global biometrics hardware company?
If they haven’t, and we cannot independently verify any of their claims, they really cannot be trusted. The Worldcoin company has a financial incentive in becoming the global identity solution. Saying they are safe from any vulnerabilities, privacy issues, or flaws in implementation is not good enough for me.
2. Sybil attacks. What has Worldcoin done to prevent sybil attacks? If I can modify the appearance of my iris with the use of a contact lense, and any other biometric data they would collect, can they identify me as the same person? Are chimpanzees inhuman enough to not be allowed to verify? Can attacking the orb operator by completing a sybil attack be enough to perform a denial of service attack against Worldcoin? If my goal is to prevent people from accessing the UBI or voting process then if this attack is possible, as an attacker, I win if my fake personas go undetected and I can collect the UBI and vote fraudulently or if my attack is detected but this compromises the identities of anybody scanned using that orb thus invalidating their accounts or preventing people from accessing accounts by being scanned for the first time as a replacement orb for that area is needed.
3. Which leads to the orbs. If you or I am unable to build our own orbs and join them to the network, then any claims of decentralization is invalid. Of only official orbs are allowed, if they cannot be examined to verify behavior then we cannot trust them either (ties into the audit issues).
I could go on with more but at least based on my surface level understanding of Worldcoin and their operations, I can see several attacks that if this is widely implemented as the global ubi and voting system would be untenable.
If there is no account recovery system, the average person could easily be denied access to participating in society by a simple mistake on their part, let alone any targeted denial of service style attack. And if there is an account recovery process then that is a vector that can be attacked today.
Putting all the world’s eggs in one basket makes this system a nonstarter. Claiming that they don’t want to do that means the language on their website and rhetoric they use in interviews are lies or misinformation of some kind so why should we trust them?
Blockchains are like virtual computers. It is absolutely possible to imagine ryan air deploying a smart contract to ethereum and giving it sufficient authority to issue bookings but until that happens ethereum is next to useless for booking ryan air flights. This is the oracle problem.
Here I've focused on the write-path but "the oracle problem" usually refers to the read-path. Say you have some prediction market where participants can place bets on who the next US president will be. How do you resolve that market? When Congress certifies the election they do not publish that certification onto any blockchain. Maybe some day they will. But for now blockchains have to make do with various hacks which allow them to imperfectly track what is happening in the outside world.
The Oracle problem isn't the fact that this doesn't happen today, it's that it can never happen in a way that is trustable. When Congress (or anyone else) does decide to publish the election results to a blockchain, every dollar bet on the outcome will be a prize to be won by anyone who can subvert the publication process.
TLS and other measures make me _very_ sure google.com is resolving to a server controlled by Google. A congress who wanted to do so could vote using hardware wallets and publish signatures and we could be just as sure that the blockchain reflected reality. A congress who wanted to do so [1] could declare that henceforth the answer on the blockchain _is_ reality; ryan air could decide that the ethereum smart contract which manages bookings _is_ reality, then there would be no oracle problem even by your definition.
[1] or maybe it would require a constitutional change
I don't follow, one of us is confused about what the other is saying and I'm not sure who. If the Oracle problem were solved tomorrow, one of the first things that would happen is publishing stock prices to ledgers so that derivatives could be implemented in smart contracts, yes?
Anyway, what I'm saying is, whatever real world data you'd like to have on a blockchain ledger, election results or stock prices or sports scores or whatever, the Oracle problem is specifically the fact that you wouldn't be able to trust it if it were there, not the fact that it isn't there yet.
> A congress who wanted to do so [1] could declare that henceforth the answer on the blockchain _is_ reality
This is a workaround - if the value on the ledger is the source of truth, there is no Oracle problem.
Even the Congress example for who is president, we literally had a bunch of people certify fake election results last election and try to overthrow the US goverment. No matter how much you scream that one day the blockchain will be the reality, that goes agaisnt every single judicial and political system we have in the world, and if you disagree with it, I hope someday somebody doesn't hack your house away from you, cause then you will learn why all proper property systems have judicial systems with actual human beings running on human logic with power to do fixes.
the implication here is that those powers of the judicial system will always be used to do fixes in your favour. but if that optimism was shared by everyone, blockchains would have never been invented in the first place.
When you want to interface with the real world, say trigger a smart contract on a stock price move - who do you trust to get that data? You’ve reintroduced a trusted authority.
This is the oracle problem. Now, if like me you don’t give a crap and are happy to trust middlemen in your day to day life because I trust banks over random merchants a million times… big whoop. But if you’re a cryptocurrency fetishist it becomes a big deal.
you're confident they wouldn't use a spoon to take 160 days worth of income? and comparing to non-cripple beggars, it's about a full year of income. that sounds like substantial incentive to me.
You could make things like a "smart contract" returns your money (or triggers an investigation) if after 48 hours you report an issue with your account or transaction. Of course this would mean some change on the blockchains themselves
That was never the goal.
> There's a black market in China for these identities already
It is built such that eventually, Worldcoin identities can be trivially reclaimed by the iris owner, so the market for these identities will drop to zero once people realize they can just sell their same Worldcoin cred over and over again and some sucker is going to buy it.
Their only goal here is to create an identity registration system where..
1. people don't need money to register
2. people don't need to have special friends to register
This is a sybil resistance mechanism, and no other system today does this. Also, the registration is basically fully anonymous. There is no way for anyone to enumerate everyone who has registered, and there is no way to link a registrant with the wallet activity of a credential holder. Say what you will, but IMO these are some pretty useful mechanics, and there are quite a few applications of this technology that can't be done without something like this.
You are uploading your iris scan into a black box, how can that be considered anonymous?
The scale and lack of security design is the cause of them. The mass scams on marketplace, the payment fraud, the harassment, the swatting, etc.
If we forced these companies to meet sane standards (especially visible in fintech) and customer service, oh no, they couldn’t do so many stock buybacks anymore, what a tragedy.
We should care whether the peer has some "skin in the game". For example a Bitcoin wallet with some Satoshis locked in a multi-signature smart contract would probably insure that. This approach would automatically ensure a free and robust digital identity and secure communication via secret/public key of that wallet.
If some rules need to be imposed - they could be managed through the smart contract plus some type of an oracle - here I second your thought. Though in this approach (with bitcoin wallet as identity) it is easy to fund the proper process in a transparent and balanced way because the funds are there already.
- VCs dump money in (SBF, a16z, etc)
- 25% of the coins are kept for the founders + investors
How many times do people have to get burned on these scams?
Obviously Sam has some street cred with the govt else they would have pulled him infront of congress like when zuck tried to launch Libre.
He got around US regulations by not making it available in the US. No street cred required.
I.e. the fine print says “the key is the only proof of ownership” but the buzz says “digital wallet secured by spy movie tech”.
The point is A) buy low (at zero) and B) sell high.
Everything else is just a marketing ploy to get to B.
We'll introduce this idea that sounds really tech, and hype. Maybe imply its so difficult that computers could never compete with humans.
We'll say its about improving security, and most humans will get a vague comforting feeling from the idea that there's some security feature, even if they find it kind of annoying to interact with.
Five years later, we say "surprise, it was really about training an eyeball recognition database that we can sell. Just like the image recognition datasets."
I do not even kind of believe these people are dumb.
Whether it will continue to have value is a very different question. I suspect that it won't.
This is absolutely a traditional shitcoin.
Quite the opposite. Congress usually doesn’t give a shit until something is actually relevant to politics. They don’t care about weird VC grifts
https://worldcoin.org/cofounder-letter
There are a few words about economic opportunity but little explanation, so you can discount that part. They don't seem to believe it beyond UBI distribution, which has the same problems as any distribution today[1]
Their main sell:
> scale a reliable solution for distinguishing humans from AI online while preserving privacy
> Worldcoin consists of a privacy-preserving digital identity (World ID)
> You can now download World App... After visiting an Orb ... you will receive a World ID. This lets you prove you are a real and unique person online while remaining completely private.
This seems to be the sole feature but "distinguish" and "privacy" are fundamentally at odds. Always! If you can identify a person, in any way, they are no longer private. They may be private for a little while, but as soon as User12345 is outed to be Taylor Swift, there's no going back. There's no worldcoin re-roll. Twitter accounts are more anonymous than that - at least if your anon twitter account is unveiled, you can make a new one! In that way uniqueness is anti-privacy. It has to be.
[1] For example worldcoin has a plan to confirm that people exist. It does not have a plan to confirm that people are dead. https://japantoday.com/category/crime/man-says-he-kept-paren...
Especially since UBI distribution aren't built in any meaningful way on this blockchain. They have some vague notion of one day wanting to use it to provide UBI, but they don't have any idea of what that actually looks like, or when, etc.
They are vaguely gesturing towards the concept of UBI.
Literally everything about this is a huge nope for me.
Credit cards, Dungeons and Dragons, Pokemon, "new world orders", the United Nations. All of these things were tools of the devil, marking your soul for eternal damnation.
I get the sense they would have had a field day with Worldcoin.
I can hear it now. "The Antichrist is taking control of the global finance system. When you choose to scan your eyes and participate in his world instead of the kingdom of heaven, you surrender your soul to the devil. And that's a place where even Jesus Christ himself cannot save you. Choosing to scan your eyes - that God himself gave you - is swearing allegiance to Lucifer and his armies on this earth. Choosing Worldcoin is making a personal choice of eternal damnation."
Worse, acknowledging even an accidental good tends to encourage lazy thinking and reinforce a very harmful system.
And calling them out every time someone tries to throw them a bone doesn't take away from the bad elsewhere -- such as VC grifting shit coins and their panopticon dreams.
Worldcoin seems like the peak of a top-down push to have perfect digital control over every human being.
This is not necessarily applicable. There's cryptography from 20 years ago (e.g. the work of Stefan Brands) that can show that someone has a World ID without revealing which ID it is. If no "username" is ever revealed then it can't be linked to anything.
Maybe you can find a few thousand on the black market, but that's going to add up fast.
https://en.m.wikipedia.org/wiki/Accelerationism
A lot of his actions, investments and marketing strategy seem to point in that direction.
I personally have a very dim view of him, mostly because of Worldcoin (which is how he came onto my radar). His work with OpenAI confirms my unease with his efforts and makes me wonder what his goals actually are.
But the sense of urgency cause by the supposed incoming terror, destitution, and despair seem to indicate these people would almost enjoy seeing it happen. Notice how their marketing doesnt focus as much on the benefits as it does on the drawbacks. It’s as if they _want_ the negatives to come to fruition and some sort of radical change to happen as a result of it.
Maybe i am reading too much into it and giving sam and the other folks at openai too much credit, but the idea that they might be accelerationists is so crazy that it might actually be fact.
Why else would you go above and beyond to build products that you yourself claim can be extremely harmful, they require radical change, other than you wanting for that negative outcome to happen so that you can achieve said change?
Didnt the person say or write somewhere that he wants to solve inequality? And since ai would drastically increase inequality by extracting work from the masses and selling it for the profits of the few at massive scale doesnt it is logical to believe that he’a aiming to prove a point. Speeding things up, cause social upheaval, that leads to social change. The definition of that ideology.
I think that if you've put a ton of time, money, and effort into preparing for a thing to happen, you begin to want that thing to happen (even if unconsciously). If it doesn't, then all that time, money, and effort was wasted.
These are the type of people building and running OpenAI? We're in a fun ride, seems they're more out of touch than I could have imagined.
Quotes like "it is easier to imagine an end to the world than an end to capitalism" and Mark Fisher's (CCNU and Nick Land, etc)ideas around capitalism realism sort of sum it up.
Capitalism is a system (much more than just an economic system) that allows for selection like this. In a sense a type of market driven Darwinism which chooses how energy is spent developing the tools that allow humans to evolve rapidly into the next thing. That it's natural that Capitalism started with the industrial revolution which marks the beginning of humans evolving tech rapidly. It's almost as if it was inevitable once we reached that stage. To be against it is futile as it's as natural as gravity. And we just keep getting better at it.
And I don’t think doom is the right word. I mean yeah, Homosapien as we know it being wiped out but in a way similar to Neanderthal.
But it’s just one theory on it all. :)
Capitalism can be effectively regulated and often is, and as a system it only works effectively due to the presence of regulated markets.
But I posit that it doesn’t really matter. Technology will ultimately prevail. I’m not sure I would call it a dystopia but rather the next step in the evolution of life.
There’s nothing inevitable about it.
You just described capitalism as a kind of suicide pact.
I don't entirely disagree, but limit this critique to unrestricted capitalism. Unrestricted capitalism is a monster that would, if never restrained, basically destroy everything.
How can we stop a force of nature?
And pg was his enthusiastic Palpatine. Egging on and fawning over sama was already uncomfortable back in 2010.
Second, they weren't subject to much public scrutiny as they weren't yet household names until maybe the mid '10s when tech companies took over the market.
It does have its beginnings as a concept in Marxist writings. In a way, Marx himself was the first accelerationist (but he seems to have mostly abandoned that thinking towards the end of his life).
I have a simple theory that tech billionaires are at least partly influenced by the sci-fi of their youth. While some of the older tech billionaires were brought up on utopian sci-fi like Star Trek, with wonderful ideas like the post-scarcity economy, some of the younger tech billionaires were brought up on the dystopian sci-fi of the 1980s. Unfortunately what seems to be happening is that they may have mistaken dystopia as a blueprint for what to build rather as a warning of what to avoid.
Also known as the Torment Nexus.
I'm very much into the crypto world and I'm so tired of all of these dumb scams. Even worse that it is backed by yet another scammer named 'Sam'.
I really wish we could focus on things that actually provided value to people. What a waste of time/money/effort. I hope this one dies a quick death. So far, it looks like it will, which is great.
I just fail to see crypto as anything but a scam - period. It's like physical gold and silver but worse at everything they do. How can one even derive value from a coin like bitcoin where the swings are often worse than the bolivar.
If you want to go back a bit further in time, I'd like to point out someone else's comment that I thought was pretty spot on as well: https://news.ycombinator.com/item?id=26238410
Hopefully that opens some discussion/thought points that we can focus on.
Update: thinking a bit further on your points. My personal concern isn't privacy, my concern is more with decentralization. I don't agree with other people telling me what I can and cannot do with my own funds. It is relatively simple things... If I travel to another country, being limited to carrying $10k cash on a plane, is absurd (why would I need to carry cash anyway?). If I'm in another country, getting access to my funds is often extremely difficult. These are the things that I'd like to see people work on.
Not trying to be glib, but have you tried an internationally recognized ATM card?
I travel extensively since 30+ years and never ever had a problem to get access to cash (and thus my funds).
That also goes for "exotic" places like Vietnam, Peru, Laos or Cambodia.
It is absurd to have to get some special card or bank account. It is absurd to be limited to a tiny amount of money, I certainly wouldn't have been able to pay rent that way.
Monero has a 24h buy/sell volume of only $110m. What do you think the global volume is for drug/nefarious trade?
Using crypto for "bad things" is a rounding error in the grand scheme of things.
Given that Mastercard just stopped allowing debit card usage at Cannabis stores (which makes sense, it is a source of fraud with cashbacks), it seems like there should be a way that people can buy things without having to take on risk by carrying cash into a store.
I never said drugs were "bad things". Some of them are, but some of them aren't. I was genuinely pointing out that getting access to certain unfairly prohibited drugs was a positive benefit that some people get from cryptocurrency.
> Given that Mastercard just stopped allowing debit card usage at Cannabis stores (which makes sense, it is a source of fraud with cashbacks), it seems like there should be a way that people can buy things without having to take on risk by carrying cash into a store.
See, there's another illegal drug you might be able to buy with cryptocurrency! My point exactly.
It allows people to bypass laws and regulations around currency exchange. This can be a good thing -- bypassing repressive regimes, making it easier to send funds over national borders, etc. It can also be a bad thing -- evading consumer protections, reducing the ability of nations to manage their economies, etc.
My understanding is Monero is private. So you could also just buy it from a regular exchange. Maybe it has replaced the whole mail people cash thing. Never looked in to it or used it though.
Anyway, you're welcome to your beliefs - but it's fucking obnoxious to take a stance like that and just deflect when someone asks you to defend it.
They won’t, in one side you have those “state sponsored” scams that will milk people’s money and trust, and on the other side you have a happy government because those at very least will keep people from trusting anything than the traditional centralized banks.
I am in the bitcoin world since mid 2010, it was that concept that any freedom and open source enthusiast will love, and it kept going that way until around 2016, gradually getting worse till 2020, then going downhill from there with these scams and Ponzi schemes, dozens of fraudulent coins and business models built around the fact how to scam people and cash out, or used for other means like this meme worldcoin one. Still, I like that you can have a truly decentralized way of funding other than traditional banks, and with some coins providing anonymity is a plus too respecting the user’s privacy.
It essentially boils down to:
- Get a bunch of people you know who can verify that you are indeed who you claim to be
- Have them sign legally binding documents that attest that, yes, you are you
- Start building your paper documents all over again
We never really talk about any of this given that it's pretty rare for this to happen to someone but I think it's interesting to point out that it eventually boils down to your IRL social network.
https://news.google.com/search?q=Worldcoin%20ai&hl=en-US&gl=...
> Investors are recognizing the opportunities presented by AI-based projects that leverage blockchain technology.
...Of course, this is total nonsense. But perception is everything for crypto IPOs.
Biometrics are like a username NOT like a password.
When a piece of wolrdcoin is inevitably compromised, people have no means of rolling a new iris. The whole thing will come crashing down.
There are so many stupid decisions this team is making. Like, users can opt into the orbs retaining their iris scan for network quality assurance purposes. Would any sane person ever opt into an ATM storing their PIN number for quality assurance? It is an implicit bounty for hacking the orb. And the fact that they seem to need further quality assurance points to the fact that they aren't confident people will have continuous access to their accounts. Best case, I'd imagine anyone who has a catastrophic eye injury would also permanently lose access to their accounts - but I suspect the reality is much worse.
Yet there’s already a black market where you can buy multiple accounts with real iris.
That some people might use their Worldcoin account to do things on behalf of someone else is a different problem from the one OP was referring to.
If the system has value inside of it, inevitably people will figure out how to make synthetic irises that fool the orb, nullifying the sybil attack prevention benefit. Surely someone could get a handful of real iris scans (using the same open source hardware) and generate a huge number of plausible synthetic iris datas.
Is the idea that in the current moment of the tech arms race, if someone steals an iris scan, the capability to synthesize an artificial iris that encodes that scan has not yet been developed?
Have they published a 'solution' to what happens if you are holding worldcoin in an iris-associated account and then:
- your scan data is stolen, ex. fake orb scans you and publishes your iris data on the internet for anyone to use
- someone throws acid in your face, your irises don't scan the same anymore. how does this affect the user's ability to access their wallet?
(is there additional private key management needed to use worldcoin securely? is the iris scanning thing really nothing more than a temporary sybil countermeasure..?)
It’s kind like how the terrible grammar/spelling in email scams has the side effect of pre-selecting desperate or out of it enough people that ignore red flags.
Then, I realized he was serious.
The only idea I see is for some certificates handed out by government to citizens and I absolutely hate it even in a democracy.
The least-harm solution, as far as I can see right now, is to just accept that the internet cannot be made trustworthy in this way. The only way to know for sure the nature of who you're dealing with will be to deal with them in person. Much like it has always been.
I don't think that really works, you need some kind of trust system. I hope it doesn't turn out that worldcoin is the best solution.
I think a web that is half identified and half anonymous would work well.
Then you can't be sure.
> you need some kind of trust system.
I agree. I just haven't heard of one that doesn't cause more problems than it solves. Just because we want it doesn't mean we can have it.
I think it is based on that in some countries there is less trust in the government than in other countries.
Where I live, Sweden, it is very hard to live without an ID card/passport and starting to get hard without a digital ID.
However, the privacy laws and prevention against abuse is fairly good. Not perfect I am sure but pretty good, compared with the US or even the UK (both places I have lived).
Trusting a safe isn't like trusting a person.
Captchas have solved a real problem. They did work.
I'm not asserting that the compromise they present is a bad one (or a good one). Just that they're a compromise.
How can we _reduce_ the problem once captchas are obsolete?
I think we'll see two "tiers" of internet.
One tier will be for day to day usage for "normal" users - banking, social media, news, etc. A tier that you digital ID will be used to verify you are who you are, and others can be assured that they're talking to the person they say they are - though there are flaws in that system if someone can get a hold of another persons' certificate.
The other tier would be the unverified internet - things like boilerplate/startup communities, activities you don't want your digital ID tied to, something to still allow people to remain semi-anonymous on the internet if choosing to.
Not sure if this will be what actually happens or if governments just slowly decide to force people to use only the verified internet while trying to access the "outernet" (or whatever buzzword they'd use) would be met with scrutiny and potentially criminal charges.
Of course there is a lot of space for abuse. And it would unfairly lock many/most people out, because services can only accept certificates from the governments they trusts.
Verifying identity is necessarily completely different if you're sending someone an item in exchange for money, or looking to date them for a while, or going into long-term business with them, or maybe just having a discussion where you want to validate that they work where they claim.
We don't need blanket verification of people's identities online. If a bot is posting on a service and is indistinguishable from an interesting human, why shouldn't it stay? "On the internet, nobody knows you're a dog" used to be the Web 1.0 motto.
I think this is the answer. Governments already have the infrastructure to verify identities in person, and no other organization is going to build it.
IMO, you can end that sentence after "internet".
But yes, as I said, I hate the idea. Was asking for other solutions.
> Your biometric data is first processed locally on the Orb and then permanently deleted. The only data that remains is your IrisCode. This IrisCode is a set of numbers generated by the Orb and is not linked to your wallet or any of your personal information. As a result, it really tells us — and everyone else — nothing about you. All it does is stop you from being able to sign up again.
> Since you are not required to provide personal information like your name, email address, physical address or phone number, this means that you can easily sign up without us ever knowing anything about you.
If Worldcoin is building a biometric database, that must be the most useless database in the world.
there's tremendous leeway in "eventual deletion" and it looks like the full device won't be open
Yeah, no.
https://en.wikipedia.org/wiki/Kinetoscope#/media/File:Kineto...
https://en.wikipedia.org/wiki/Kinetoscope#/media/File:Kineto...
E.g. we protect our social security numbers against identity theft because the economic benefits of having one outweigh selling it. But when there isn't a benefit, then the identity can just be sold.
Solving the identity problem and solving the "good governance" problem are likely the same problem.
It's the age-old rule of thumb: never trust anyone who says "trust me".
That alone is enough to make me lose any interest in hearing more.
It would be easier to accept him as someone who is genuinely altruistic. Instead, he turns out to be just another self-serving 'tech' bro.
I write 'tech' because clearly this guy does not actually care about pushing technology forwards for human good -- which is the cause, in my view, of all real technologists. It's about himself, just as it is with the great Technoking.
[0]: https://vitalik.eth.limo/general/2023/07/24/biometric.html
I've been scrolling this thread for ten minutes and also read through the worldcoin website. Nobody seems to have asked this. If they want this to be a true proof of personhood it needs to work for every person.
In addition, the USA needs to create a single Civilian Social Platform just like we did the highway system. We need to validate people based upon their citizenship, and label people based upon their relative status to actual stakeholders in the nation.
I will add Monero to that list
https://rollup.id/blog/rollup-id-the-open-source-privacy-fir...
use a crypto token to exploit poor people. a real web3 VC douchebag move there
wasn't that VC who was recently murdered in SF also involved in this project (unrelated murder).
in any case mr altman can kiss my hairy yellow a$$ before getting my retina data