Worldcoin: A solution in search of its problem
newsletter.mollywhite.net
newsletter.mollywhite.net
This is a really key problem. The main application of biometrics today is in cell phones, and for those we operate on the assumption that we're trying to distinguish between the authorized user and a quite small pool of non-authorized people who will have physical access to the device: family members, friends, co-workers, and the occasional thief. This threat profile allows the biometric algorithm to err on the side of usability—it's more important that the algorithm consistently open the phone when shown the user's fingerprint or face than it is that there be no other human being on the planet who could open it.
Worldcoin has a very different threat profile, and it's not obvious to me that is possible to have a usable biometrics system (with an acceptably low false negative rate) that also has absolutely zero risk of hash collisions when the pool of unique people you need to distinguish is the size of the entire planet.
Not merely the size of the entire planet. If they hope that this scheme lasts in perpetuity, it will need to distinguish between all individuals who will ever be born.
So even with the birthday paradox you'd need 10^37 people before having a good chance of a collision, which is rather more than we are likely to have in the next few centuries.
Of course, it's possible that there are some subpopulations who don't have this amount of entropy in their irises, most obviously the small number of people who have a birth defect such that they are born without eyes.
If the goal of this is really as ambitious as they claim, with every single person on the planet getting UBI through it, their biometric system needs to be strict enough to not conflate two people and flexible enough to match the same iris when scanned a second time for verification. I don't believe the tech is there.
https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_pr...
That the photo represents a real event in real reality is absurd o_O
EDIT: The while premise of needing a nin-centralized wax of confirming ones identity is, at its core, deeply un-demicratic. As of bow, government issued documentation confirms anyones identiy. These governments can be democratic, and are. Puting a different system in place, controlled by some tech-billionaire-liberitarian, is as dytopian as it gets. So of course VCs are investing like hell in it.
Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale
Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus
I deeply hate this line of logic. This exact argument was presented against the Signal messaging app in an Op-Ed in the NYT (https://archive.is/tJoem), to quote from it:
> They are a small group of people who govern these powerful tools, and they are not accountable in the way that, say, a democratically elected government is. Whether law enforcement should tap our phones on the condition that a warrant is obtained is, at the very least, worthy of public discussion. Signal has unilaterally decided for us all.
Boo hoo, math makes it so that governments (yes, even democratic ones) can't tap phones, therefore math (and the technologists who code up this math) are evil and anti-democratic.
For all WorldCoin's faults, merely attempting to offer a decentralized alternative (even if it's not a very good one!) to government proof-of-person solutions is not one of them.
Outsourcing some, or all of that to some VC backed companies, facilitating access for the various intelligence agencies, is what I have a problem with. And a crypto start-up setting out to build a global database of peoples retinas is exactly that.
So you're against encryption then. Simple as that.
> Outsourcing some, or all of that to some VC backed companies, facilitating access for the various intelligence agencies, is what I have a problem with.
I also have a problem with that. We should aim to build systems that are resistant to all attackers, even intelligence agencies. And like Signal, it should be impossible for companies to facilitate access for anyone, including intelligence/law enforcement.
> And a crypto start-up setting out to build a global database of peoples retinas
Perhaps you should familiarize yourself with real criticisms of WorldCoin (Vitalik has a nice critique here: https://vitalik.ca/general/2023/07/24/biometric.html), because they don't store biometric data, they only store hashes.
What's the worry here? If WorldCoin surpasses their wildly ambitious long term goals, governments won't be able to revoke someones passport for being a dissident anymore? What specific issues do you see with a successful decentralized proof of personhood system?
EDIT: Specifically, what issues does _decentralization_ bring to proof-of-personhood over government run proof of personhood, other than removing the government's ability to un-person someone.
You wont solve social issues with technical solutions. But just like the DAO hack you can solve technical issues using social solutions quite easily.
it's usually much more than that. A lot of those projects founders, including Signal's, are pursuing deeply ideological projects, "it's just math" doesn't really cut it. Many aren't just after providing services that are largely in line with existing values of privacy or what have you. Hell, Moxie wrote an actual anti-democratic treatise whose central premise was:
>"[..]Our critique is of democracy in all its various forms, whether representative or direct. We are not echoing confused cries for more democracy, we are calling for its entire abolition."
These kind of attitudes are often baked into the projects themselves, hence why there's a worldcoin and MobileCoin in Signal. Don't really need your own currency for either of those projects right?
https://theanarchistlibrary.org/library/moxie-marlinspike-an...
Libertarians want to live in a world where they are accountable to no-one. It's the ultimate conclusion of capitalism: wealth makes right. Serfdom and (sexual) exploitation for those of us who are not rich.
How do they prevent fake virtual iris scanning devices from pretending that they scanned a person that doesn’t actually exist?
Or is the idea that sama is will run a centralised private identity system that aims to replace government identity management? Then why do you need crypto?
Are they trying to replace proof of stake/proof of work with “proof of being a human being”? I don’t see how the iris scanning achieves this?
I think it’s fundamentally impossible.
If you don’t have a centralised authority verifying identity, the best thing you can get is peer-to-peer federated identity verification like PGP. But with this, identity is relative, as in “I trust a guy who trusts a gal who says this person is real”.
The signup process is always a sensitive part of a cryptosystem, and open network membership is not always expected (for instance, CBDCs, Ripple…). There is certainly a philosophical argument to be made against closed membership, since it can disadvantage people that struggle for access, and lets the company discriminate in the future once they get a stronghold, which can be especially problematic considering the primary value of human-uniqueness is to restrict voting to an in-group whose bounds historically have been heavily argued even in non-repressive regimes.
But it seems unlikely to become predominant. Some people have prosthetic eyes; I would be hard-pressed to imagine, say, Apple releasing an iPhone that is inaccessible to a population in such a significant way.
It could still be a cool idea, but I don’t get how this needs crypto?
This is exactly the same problem as spam detection - nobody has found a good way to prevent people from generating large numbers of fake identities, short of government identity registration. The classic "Why your solution to spam won't work"[1] checklist applies.
I expect Europeans to shun this.
I fear though that once they hit "1bn people" they will invoke the FOMO into the rest.
Over a billion humans have intestinal parasites, but that doesn't mean people are queuing up for worm eggs.
"Increase your resistance gut to parasites with our revolutionary cure!"
Or some such...
And then you realize what complete sleezy snakes most of these tech bros are.
Otherwise it wouldn't Make Money Fast.
This came up a few weeks ago on HN, with someone from a small country writing that they quit a crypto startup because they realized it was a scam. The startup was starting up an exchange, which doesn't really need a "coin". But they had to have one, so they could play games with the financial structure and Make Money Fast.
This is why there are very few real DeFi crypto exchanges. A trustless exchange, where the exchange never has custody of the money, is the way a crypto exchange ought to work. The exchange is then just a matching service - people put limit orders on a blockchain, the exchange finds ones that match, and tells both parties "go". Like the NYSE, which never owns a stock.
But there's no Make Money Fast in that. It's getting your hands on the customer assets that pays off.
But why do you need a coin for that? If you have centralised accounts you may as well have a centralised ledger.
On the other hand, if you decentralise account creation - let me tell about my friend, the virtual iris scanner powered by /dev/random
There is a lot of room for systems that are the silver standard and the math enables a great deal of reliability for those outside of the traditional financial systems (many people). It doesn’t have to be perfect, it just has to be good enough.
Each scanner is registered, authorised, tracked etc. Presumably with a private key but also I think they have the location, operator details and so on for every one.
*> A black market for Worldcoin accounts has already emerged [1] in Cambodia, Nigeria, and elsewhere, where people are being paid to sign up for a World ID and then transfer ownership to buyers elsewhere — many of whom are in China, where Worldcoin is restricted. There is no ongoing verification process to ensure that a World ID continues to belong to the person who signed up for it, and no way for the eyeball-haver to recover an account that is under another person’s control. Worldcoin acknowledges that they have no clue how to resolve the issue: “Innovative ideas in mechanism design and the attribution of social relationships will be necessary.“ The lack of ongoing verification also means that there is no mechanism by which people can be removed from the program once they pass away, but perhaps Worldcoin will add survivors’ benefits to its list of use cases and call that a feature.
Relatively speaking, scanning your iris and selling the account is fairly benign. But depending on the popularity of Worldcoin, the eventual price of WLD, and the types of things a World ID can be used to accomplish, the incentives to gain access to others’ accounts could become severe. Coercion at the individual or state level is absolutely within the realm of possibility, and could become dangerous.
[1]:https://web3isgoinggreat.com/?id=sam-altmans-worldcoin-proje...
Sure, yeah, maybe that's all it is, a scam that's totally transparent and obvious to every random internet commenter but totally non-obvious to the simple and gullible marks on Sand Hill Road.
Or maybe, just possibly, there might be more to it.
Perhaps it takes a little more effort to understand than just piling on to the reflexive groupthink cynicism which passes for conventional wisdom around here.
(Disclaimer: I have no association with this project, haven't gotten my irises scanned, don't own the token, haven't invested any effort to understand it. But I've been around long enough to recognize the smell of reflexive groupthink cynicism, and to profit by betting against it.)
Maybe I'll spend the 20 minutes to read the 5000 words in Molly White's article, and then another couple hours to read the whitepaper, then another who knows how many hours researching the claims and counterclaims to make my own judgment.
But probably I'll never do any of those things, and I'll still have high confidence that the project probably isn't simply a scam for sweet, sweet VC money, or unimaginably naive, or full of fatal flaws that every rando can identify instantly.
Because in the past, when anonymous internet commenters are of one mind that a new thing is a scam or fatally flawed, while the team behind the new thing are highly capable, with good reputations for not being scammers or unimaginably naive, usually the anonymous internet commenters don't understand what's really happening.
And then I'll ctrl-f the whitepaper to search for 'sybil' and discover that the arguments in this thread are already discussed in the whitepaper, which gives me even more confidence that the hivemind conclusions of scamminess or naivete are most likely uninformed.
You write this like it's an absurd notion, but we've already been through Juicero, WeWork, Theranos, Nikola, and FTX among others.
You mean the ones who also invested in Theranos, WeWork, and FTX? They don’t always make the wisest investment decisions. They’re not complete idiots, but they’re sucsceptible to same biases and misjudgements as the rest of us. And I’m sure they‘re aware of some or all of WC’s flaws, and are just investing b/c Sam Altman, or because they invested back in the 2018-2021 crypto bubble. There’s also some time pressure, they’ve gotta put that money somewhere within a year (standard VC LP contract), or give it back.
> Perhaps it takes a little more effort to understand than just piling on to the reflexive groupthink cynicism which passes for conventional wisdom around here.
Molly already put extensive effort into just that in the OP, as did several other folks she references and links to. If you have any critiques of her critiques and why she may be wrong, love to hear it. But without that, it’s not her or us that’s being reflexive here.
If that's the case, then isn't it on WorldCoin to educate us? Their communications so far have apparently been insufficient, if people are rejecting the scheme merely because they don't understand it.
If you are tech savvy you can sign up and convert the worldcoins to money yourself, via Kucoin or similar brokerages. Which is allowed and intended.
(1) Pick your 80's Sci-Fi movie dystopia that fits here.
Plenty of evidence... of which still none is being presented neutrally.
Still waiting for such evidence...
I would be less suspicious of someone working on a selfish project that might benefit people as a side effect.
Why on earth would the CEO not get a stock grant when the entry level SWEs do?
This is the most critical part, I think. If my Iris scan is leaked (which is not hard to do, from modified Orbs, similar to credit card skimmers, to mobsters scanning people's irises under threat of death), my identity will be stolen and I can't do anything about it. Do they have at least some sort of 2FA?
What is it with founders named Sam who are scammers?
[0] https://vitalik.eth.limo/general/2023/07/24/biometric.html
I find it difficult that this kind of project is attached to Altman — it’s not a good look for someone playing around with controversial human replacement technologies capable of insane global control and manipulation.
Let’s invent a crypto that tracks every human on the planet using their immutable characteristics.
It’ll be fine. What can go wrong? This information won’t be used inappropriately I’m sure.
Never trust a rich person who wraps themselves in the cloak of human interest or says they are “of the people.” The establishment isn’t in the business of teaching you to disrupt it.
The tech is there, it works today, without crypto bullshit, and it is extremely useful. But since nobody became a billionaire out of it, nobody talks about it
You can do the same thing in the US. The problem is that businesses can't easily do this without collecting bank routing information from customers, which is effectively "secret" because it allows anyone to debit money directly from their bank account, so they're reluctant to provide it.
What's needed is a low- or no-fee system for requesting payments from someone without collecting any secrets from them. The technology to do this is not hard -- use public key cryptography, or just require the customer to approve merchants before they can make debits. But the customer's bank has little incentive to implement this because the customer won't choose a different bank over it and meanwhile the banks own the credit processing networks charging the high fees.
Which is why people are looking for an external solution.
How does it work in the US?
But with the same information someone can also make a withdrawal, which is problematic.
You seem to be talking about authorising businesses to take money from my account without needing further approval. A direct debit.
Parent is talking about transferring money to someone else's account, which is easy and requires no secrets or authorisation.
What problem needs to be solved?
This would be essentially solved with a standardized system for customers to give each merchant a separate bank account number (or equivalent) which really refers to the same bank account but could be revoked individually if that number is compromised or you want to remove the merchant's access, or could be set to automatically expire for non-recurring payments. But the banks don't have the incentive to provide this when they're the ones getting the credit card fees.
Supposedly FedNow is the solution to this, but it will be a while before this functionality is exposed to end users.
That allows you to authenticate with the service you're doing business with, which is all that ever needs to happen because centralized identity systems are just an attack for correlating your activity across services and devices.
Soon it will impose savings limits, expiration dates to incentivise spending [0] all tied up to your digital identity.
When governments propose extremely unpopular policies on its people, it will be certainly used against their own people to quell and discourage protests much easily than before.
You will then realise that all these digital identity solutions such as eIDAS, digital euro and wallets are essentially no better than Worldcoin. Governments around the world would love to do exactly what Worldcoin is doing for onboarding to a future CBDC.
No thanks and absolutely no deal to both of that.
[0] https://reclaimthenet.org/digital-euro-spending-saving-limit...
> But since nobody became a billionaire out of it, nobody talks about it
Here in CZ, the law was setup in a way that gives advantage to banks compared to other identity providers, these banks created one consortium, which is essentially monopolistic provider, with ~80 % market share, asking private services providers significant money for identity services.
The irony.
Just like 90% of startups fail, it is the same with 90% of crypto startups, and AI startups will fail. The 10% remaining will continue to exist.
Just stop this absolutist nonsense.
It is already known that the majority of unprofitable startups take tons of VC money and have regularly played the Silicon Valley playbook of 'faking it' until they are caught out in the open [0] [1] [2]. It has gotten so common to the extent where their favourite bank (SVB) went under with all these unprofitable startups crying over payroll when generating little to no revenue with inflated valuations.
We were supposed to learn from that VC pyramid scheme that has caused SVB to collapse which was so seismic that all those unprofitable startups would all have gone bust had capitalism just run its course without government intervention.
There really is no defence for continuing the constant dependence on raising VC money in unprofitable startups for years anymore after over-leveraging and injecting more cash at unjustified valuations in these startups. For this scam to be revealed so late shows how long many startups were able to get away from 'faking it'.
[0] https://www.theguardian.com/media/2023/feb/23/ozy-media-foun...
[1] https://abcnews.go.com/US/startup-founders-alleged-175-milli...
[2] https://www.cnbc.com/2022/10/14/nikola-nkla-founder-trevor-m...
[0] https://thefintechtimes.com/stellar-aid-assist-creates-new-r...
The whole thing is designed to exclude the disadvantaged and disconnect the formerly advantaged from thier funds when they face an unexpected change in ocular health.
As a comparison, Vitalik wrote a great, even handed analysis:
Seems like there is no reason why the iris picture needs to be stored. But I’m not sure of the whole use case
Can’t do any searches on people based on the iris.
I did a pre-interview to work for one of Sam's first startups, the mobile one that had the date via GPS idea. Turned down going beyond the pre-interview due to concept and funding combination not being compatible with reality. You have to remember at that point in time Mobile OEMs were locking down GPS access through apps and Mobile Operators were attempting to pretend they were VCs.
Not every slide deck that gets money is a good slide deck!!
If I had a pre-interview for a job at Amazon, does that mean I have a Jeff Bezos story?
"I have a pre-interview story..."
Let's be real here, this was a rather poor attempt at name dropping Sam. It also had nothing to do with Sam.
It also had nothing to do with how the company was run, which they'd really know very little about, given that it was a pre-interview. They turned the offer to continue down due to the concept, not how it was run.
If the person had described sitting down at an interview with Sam and discussing the way the company was run, then I'd call that a Sam story about how the company was run.
Did I walk through this slowly enough for you?
Reports it back to us as Sam Altman launches another fly-by-night operation.
Sorry, but it's a Sam Altman story.
It is a story about a pre-interview, not a story about Sam.
And no, not by own bias, just an accurate reading of OP's story about his operation.
It doesn't store biometric data. It doesn't store any information that is useful to anyone for any purpose. The only thing it can do is tell if your iris has been scanned before. That's it. It can't reproduce what your iris looks like and can't sell any useful data about it to anyone.
It does in fact allow online activity with privacy and while remaining anonymous. There is no way to link accounts between sites unless you do so yourself.
Yes, people will sell accounts. This is fine because it still solves the problem of people being able to make infinite accounts online at present. It still creates a barrier of entry for spam where there currently is often very little or none. Inauthentic behavior online will continue but not at the rampant pace it currently has.
There's lots more I could say but I'm not going to change minds that aren't open to rational discussion and instead engage in the perpetual outrage machine that is social media and corporate news. If you have genuine curious questions that aren't easily answered by their website, feel free to ask and I will answer as best I can.
I have no affiliation other than I'm working on a personal project with their API.
> It doesn't store biometric data.
She addresses this: they do in fact store the biometric scans if you opt in, and they strongly encourage you to opt in because if you don't you'll have to periodically reverify as they tweak the algorithm.
> It doesn't store any information that is useful to anyone for any purpose. The only thing it can do is tell if your iris has been scanned before. That's it. It can't reproduce what your iris looks like and can't sell any useful data about it to anyone.
As Molly points out, you're making a huge assumption that this number that uniquely identifies your iris isn't useful information to sell to someone (or for someone to hack).
> Yes, people will sell accounts. This is fine because it still solves the problem of people being able to make infinite accounts online at present. It still creates a barrier of entry for spam where there currently is often very little or none. Inauthentic behavior online will continue but not at the rampant pace it currently has.
This is where the project really needs to figure out what it's actually trying to do. If the goal is simply to reduce inauthentic behavior on the ETH chain, then it's possible that you are right that sale of accounts doesn't matter. But if the goal is to provide some sort of UBI system, the fact that it has no way to verify who is using the account after its initial creation is a huge huge problem that will lead to massive amounts of corruption and harm if they succeed at implementing the kind of worldwide UBI they're talking about. Just look at what happens to humanitarian aid that goes into territory controlled by warlords: that's what we're talking about.
Again, Molly addresses this, so it feels like you didn't read her article.
> As Molly points out, you're making a huge assumption that this number that uniquely identifies your iris isn't useful information to sell to someone (or for someone to hack).
How would someone possibly use the information that you've already scanned your iris to your detriment? How does that benefit anyone?