Worldcoin hit with temporary ban in Spain over privacy concerns
techcrunch.com
techcrunch.com
But let me get this straight. Sam is the CEO of OpenAI. Basically the company that is making it harder and harder to know what was made by a human or a machine.
Out of concern over that, makes Worldcoin as some authentication method? So the problem he helped Shepard in, he has another company that he could make money on to fix said problem?
Am I missing something here or is this... super shady sounding?
That's before getting into the whole scanning our eyes for a few bucks thing.
A lot of people have been trying to point that out for ages, without any real traction.
Either of OpenAI or WorldCoin would be a terrifying nightmare even without Altman and OpenPhilanthropy and the SEC investigation and what-the-hell-ever scared Ilya so bad he 180’d from a single phone call and Yud whipping the public and Congress into a frenzy talking about Terminator in two years.
I don’t care how badly someone wants to be accepted into YC or whatever: this is the wrong side of history.
“We are below them, we are above them, we are around them, we run through everything they do.” - Satya Nadella, Eyes Wide Shut
But make another company defending against an insane danger from the first and people start dreaming.
> Am I missing something here or is this... super shady sounding?
It sounds like inventing the ship and also tools to avoid shipwrecks. I don't think there's inherently anything shady about the pattern.
According to https://worldcoin.org/be-a-worldcoin-operator they'll gladly ship the iris scanning unit to untrusted 3rd party operators, in a similar vein to a bank shipping out PoS card terminals.
I'd love to have a play with one, it wouldn't surprise me if you could get it to mint fresh accounts out of thin air (e.g. by mitming the bus between the iris scanner and the rest of the unit, and making it report fresh unique scans)
Hmm, I wonder if the worldcoin team also thought of that possibility?
(Yes, they did, the iris processing is done inside a hardware enclave so that the obvious attack is not possible)
https://whitepaper.worldcoin.org/technical-implementation
I am broadly anti-Worldcoin but it is reasonably competently executed at a technical level. It would be good to understand what they actually did before declaring it to be impossible.
The SoC they're using, the Jetson Xavier NX, is a cousin of the very thoroughly pwned (secure enclaves and all) TX1.
Further, they don't describe how the busses connecting the sensors to the SoC are encrypted and/or authenticated, which leads me to believe that they are not.
Intel gave up on shipping SGX in consumer devices because (imho) shipping secure enclaves directly to "adversaries" (the consumer being an adversary under the SGX threat model) proved too difficult to maintain.
This is what's wrong with so much of this "security" tech. It's not for our security but for that of the businesses and their business models behind it.
+1 to this. I'm very skeptical of the project (even though I know some of the people working on it), but the problem space is extremely hard and they're giving it an actual shot. If you can think of a potential problem in 5 minutes, I guarantee you that they've thought of it too.
People paid companies like 23andMe actual money for the privilege of mailing their DNA. Getting paid to let a company your eyeball sounds like an improvement.
Which information is more precious overall, which is a call to action rather than a simple joke between friends "oh im 3% Banana".
https://en.wikipedia.org/wiki/There%27s_a_sucker_born_every_...
The money isn't stuck in the app by the way. I've taken out and changed to US$ about $100 and currently have $164 worth in the app and about $10 a week of coins coming in. Which is nice of them. Worldcoin is just another crypto coin like dogecoin or whatever.
Also my id, I think, is just an optimism crypto address 0x93bf030f706e81197856e76c8a3b326640... with no name attached. You'll have a job stealing my identity with that, any more than it's easy to steal Satoshi's because you know his public bitcoin addresses.
I mean if you go to a credit card company and say I'd like to get a card in the name of some guy I don't know the name and address of but here's one of his public keys, I don't think you'll get far. Certainly not compared to getting my real name and address which is fairly exposed on the internet via phone directories and the like.
I don't think if say the photo of my iris's leaked online it would be much of a problem in the same way that the rest of my face is online and it's not much of a problem because no one accepts some photo off the web as proof of id.
One thing I think may be flawed is if I say hi I'm Tim, send me some money to the above address, then you can see all my other transactions to that address on the blockchain which breaks anonymity/privacy a bit. I'm not sure if they are going to fix that by say issuing disposable addresses but I haven't seen that so far.
I don't know why you're comparing a high definition full iris scan to random photo of you, they aren't the same things. The point is security is made of things you know and things you have, and eyes are hard to pass around, so someone being able to "have" your eyes to fool a scanner is useful for many classes of attacks, we don't need to know the full attack chains yet to know it's inherently a risk because it turns a thing you have into a thing you and Worldcoin and whoever worldcoin sells or gets hacked by - all have.
Even if it's encrypted, if worldcoin gets breached in a particularly bad way (say root to their production servers) then the unencryption mechanism and keys could be leaked along with the encrypted data.
The point being that just because something is encrypted doesn't make it foolproof against everything.
From Wikipedia:
> Worldcoin is an iris biometric cryptocurrency project
From the Worldcoin website:
> World ID 2.0
> A more human passport for the internet.
Eww. I appreciate cryptocurrency, but biometrics + crypto? Heck off.
He undoubtedly owns a considerable amount, and it doesn't matter if it's a long term successful so long in the near term it has a multiplying impact on his OpenAI work. If you look at the 1 year change in WLD you see that he's likely made a pretty sum from it already, especially since whatever amount of WLD he own was acquired at effectively zero cost[0].
The people I was chatting with shared a similar view to dogecoin and Musk. All either needs to do is drive up a little hype and in to time they have access to tremendous amounts of liquidity.
I have always viewed people arguing for or against crypto as equivalent to nerds arguing if batman or superman is better. Utterly irrelevant to me.
The vibe on today's internet when it comes to weird tech bros is 'we made this space, applaud us on it or leave it.'
Many people have chosen option 2.
I was in the room with sergey once 7 years ago and he made a not so unserious joke of “where we’re going we won’t need users.”
It stuck with me forever.
Its really mostly a surprising revelation to outer-circle initiates of the cult of capitalism, who have been indoctrinated in the public propaganda used for recruitment but are ignorant of the inner mysteries.
Instead, institutions attempt to increase transparency and limit gambling with other peoples money.
The availability of terrible high-risk investments and option to buy them is always present. IT is just rarely interesting to talk about.
It fair to say I am very aware, I’ve worked in the largest tech companies in the world and I worked on the largest bank merger in the world. I see how the sausage is made… mostly.
However the value systems that are created anew continue to shock me. Because when the wool gets pulled, and it always fucking does, the damage is shifted to those who “don’t care”
I want to give food or money to 1000 distinct people in some part of the world.
How do I make sure that 1000 distinct people do it and it's not just 100 people getting in the line 10 times each?
What source of identity does everyone have (yes, there are exceptions) and on the more difficult to lose side (industrial accidents are more likely to damage fingers than eyes)?
I mean if your goal is to end fraud there seems to be several options that don’t require a blockchain or some custom eye scanning device.
How does worldcoin solve the issue of a local abusing a position of power to direct everyone to transfer their funds to their account or with holding some other resource to force people to give them their aid?
If the zero knowledge can protect that and the wallet id just can identify that you’ve done an eye scan at some point, the wallet id is still as good as knowing the iris hash. Sure crypto evangelists will use sub wallets and multiple accounts and all that jazz to best preserve their privacy (all things that if possible make sybil attacks possible) but most people will just have the one wallet. Eventually everyone who pays attention will be able to identify them using just the wallet.
So I doubt the effectiveness at preventing sybil attacks, I doubt the effectiveness of how privacy preserving this is, and if used beyond Worldcoin transactions, it just becomes an immutable global id. A social security number that requires an iris to generate.
There's no biometric sensors that are guaranteed to be free from tampering. There's no way to prove that the bits and bytes that say "I scanned person X's iris" actually corresponds to a legitimate iris scan. There's no way to stop someone from going town to town with their own iris scanners and claiming they need to scan eyes for the census or vaccines or any number of other things that people might think are real, only to use those scans to accept the money you mentioned in your comment. There's no way to prevent someone from perturbing those scans slightly to allow them to be re-used for new transactions in the future.
Extremely advanced credit card skimmers exist, and those subvert the security of little tiny computers embedded in the credit cards. If you think a picture of an iris is any better, I've got an NFT of a bridge to sell you.
Even if the food/money is perfectly evenly distributed via Worldcoin, a gang boss can have his muscle go around and threaten violence if people don't give him their share of the food/money. That's the problem, right?
The kind of injustice that spurs people to build Worldcoin can't be solved by Worldcoin.
The problem is a real one, lookup "sybil attacks", which is what I think Worldcoin is trying to defend against.
Government-issued ID card?
> How do I make sure that 1000 distinct people do it and it's not just 100 people getting in the line 10 times each?
Find people to do the distribution whom you trust to be able to recognize people who are cutting multiple times? I mean, you already have to trust them to do things like actually disburse the food to the people, and not skim off 30% to sell for their own profit or whatnot. And if you look into where aid distribution goes awry, it's largely not "100 people getting in the line 10 times each" but the distributors absconding with the aid instead of giving it to the intended recipients.
It's easy to think of reasons that wouldn't work particularly well in some parts of the world. That doesn't mean I'm actually onboard with scanning biometrics, especially those of people who haven't read enough dystopian science fiction to be skeptical of that plan.
Government issued ID cards are forgeable and states not too difficult to get officially (the classic example of a spy with four different identities). For that matter, multiple different forms of identification can complicate the matter. Consider https://www.tsa.gov/travel/security-screening/identification - I have a passport, I have a drivers license. There are individuals who have both of those identifications and a Tribal Nation identity card and a Veteran Health Identification Card too. Four different forms of ID for the same person - can those each be used once?
I believe that Worldcoin is/was an attempt to solve some great societal issues with crypto currency tooling ... and is going to end up with many other ideas of how to solve social problems with technology in a "nope, that doesn't work" pile. Scanning eyeballs is an attempt to have one person to one identity - which may work, but it doesn't solve the related practical problems of distributing aid.
The point of government ID is that you have a complete government registry of allowed people, and ID cards are used to prove your association to that registry. For example, when I go to vote, there is a master list of everyone who is eligible to vote, and my name gets checked off the list. If I tried to vote again, well, my name is already checked off the list and I don't get to vote again because of that.
Or put differently, proof of identity isn't the same of proof authorization. ID cards prove identity; some other mechanism needs to prove authority to access the resource, and if necessary, it's that mechanism that prevents repeat access.
A list of voters, and when someone comes in you cross their name off the list. If it turns out they were lying, you'll find out when the actual voter turns up.
How much drift from the original does this allow? And if it can be updates, can that be abused or can people be coerced into handing over their accounts?
Is blockchain technology involved? Then it's worth a look.
I have no interest in tying my ability to conduct transactions and hold wealth to an ID that is designed to be immutable. But that's just me. I also lack faith in any system founded on biometrics, as it's a technology that's implicitly sold as something that is nearly impossible to exploit, which I simply have no reason to believe.
If there are people out there who are turned away by cryptocurrency being involved, well, I can't say I entirely blame them. The nerdy advocates and developers of cryptocurrencies and the countless "gurus" have failed to adequately onboard the public or counter the bad PR from the media. When setting up a custodial cryptocurrency account takes more steps than signing up for a credit card, the fees are relatively high, and stories pile up of clueless people falling for scams involving cryptocurrency, as well as the barrage of FUD from folks who are usually ignorant, it's no wonder everyday people would run in the other direction as soon as "cryptocurrency" is mentioned.
Neither of these two is fulfilled here, so yeah - it's bad.
On the one hand "Proof of humanity" is an important problem and is surely only going to get more important as time passes. Bots are already better than humans at solving captchas.[1]
On the other hand I cannot conceive of giving someone my biometric data so they can mint some blockchain thing from it, and although I admit I wasn't interested enough to look into it beyond reading a couple of articles, I really don't see how this specific solution makes the situation better. Eg how do they know someone hasn't pwned me and then hijacked my special proof of humanity token to using it for their bots to "prove humanity"?
I'm not sure... but I'm also convinced that 'private corporation issued id' isn't fundamentally superior to 'government issued id' and has some challenges in terms of accountability.
Is it? I use my eyes a helluva lot more than I use my government issued SSN. In fact, I've only taken my physical SSN card out of storage once, but I stare at random (potentially camera equipped) stuff all day. Of course you can still steal it from me by pretending to ask for ID, but that's true of my eye-print as well.
This may be a dumb question, buy why could someone not simply create an AI-generated iris image and fool the orb into thinking that is a unique human?
Secondly, I believe that the protocol is based around the idea that the operator is trusted, i.e., they won't allow such uses of the orb. If an operator isn't trustworthy, I guess there needs to be a way to revoke the validity of all their scans.
The main purpose of the scan it to check for uniqueness so you can't keep going up and get 50 accounts.
https://whitepaper.worldcoin.org/technical-implementation#wh...
Governments have been doing this for centuries (see passports, identity documents, birth and death certificates). Witnessing attempts by private entities repeated attempts to "solve" this problem and make a profit has shown me the limitations of free markets. Despite the complexity and sophistication of the implementation, it boils down to a record that's looked up by a trusted entity who attests the validity of the subjects identity, or not.
The actual problem - which is waiting for a solution - is undeniable. (This isn't often the case with cryptocurrency projects.)
That's about the least-private implementation one could think of; I wouldn't want to send scans of my iris to random Internet services either! This would be the equivalent raw-data implementation for Worldcoin.
> The actual problem - which is waiting for a solution - is undeniable
The solution is the government providing an oauth-like service. Internet services would only get a token and only a limited set of PII you were shown and agreed to while authenticating (e.g. your name, email address, and/or whether you're a minor/adult).
No one can attest your identity without keeping a record of it - public service or not. IMO, having private enterprise do this merely increases the attack surface.
You don’t. You generate some secure keys using iris data. You send the internet service a copy of your public key. They can use that to verify that you are human, but not who you are.
I'm sure they must have thought about this but I don't understand the solution.
https://whitepaper.worldcoin.org/technical-implementation
https://whitepaper.worldcoin.org/advancing-decentralization#...
This sounds great as long as you live in a strong democracy with trustworthy institutions. A lot of people don't.
The only exception being meta a decade ago, to which I obviously answered by deleting anything meta related bar Whatsapp.
If you're hiring, or looking for a new job, the odds of you being tricked/phished are getting worse by the day. I've read stories of employees get interviewed for fake jobs as a long-con to get banking details, and employers interviewing a persona that's fronting an offshore dev team, or people who don't have work skills and aim to pick up paychecks until their dismissal is processed.
It's obvious that captchas will need to be replaced by something else, no?
In essence: good luck trying to exit/enter a country/location with access to the iris database that already mapped your identity after KYC for your bank account.
You are now living inside "Minority Report": https://www.youtube.com/watch?v=PPDYh9EpbmA
There was a whole load of these zombies lining up here in the local shopping centre to give Altman their irises.
They're free to do so of course but they're lowering the barrier for privacy significantly by presenting the world with the reality of a significant proportion of the population with their irises scanned. Thus it will be harder for us to keep our privacy just like privacy on internet is gone as a fait accompli. People are already using this as a debate argument against privacy: "Your privacy is already gone anyway so why do you care about this new issue?". That's how bad things have become.
The same way as that, having a significant portion of society do this, will mean I'll be unable to prove I'm not a bot without getting my own eyes scanned in the future.
https://www.aepd.es/en/press-and-communication/press-release...
The only news afaik is that Worldcoin failed to get injunction against Spain’s privacy suspension https://techcrunch.com/2024/03/11/worldcoin-fails-to-get-inj...
"Lets just take their <eye/finger/hand/head> with us to get into the <base/facility/lab>".
And I speculated on the possibility of Iris generation a while ago, the research is fairly solid - you just need to fool the device into thinking it’s scanning a human eye instead of a display.
When all is said and done, none of this changes that. Humans will push back against non-human things ... with regulations and eventually violence.
This is why nations spend so much time hiding the non-human factors acting against them.
Will AI prevent me from feeling human feelings? No. To Altman and many others this seems like world changing stuff, but is it?
I am afraid that they may not have an equally compelling explanation for the same problem in the rest of the world.
- You can’t change them if they’re compromised
- They’re unreliable, they can change with age, depends on the environment that they’re measured in
- It’s not really “proof of humanity” just “proof of biology”
Worldcoin is an interesting attempt though
- Not provided enough information about how the data is stored/used
- Collected data from minors
- Not offered individuals to withdraw their consent
So the data protection agency of Spain is temporary halting any data processing/transfers, in order to protect people from the unlawful collection.
Is this the first time "Urgency procedure"/Article 66 (https://gdpr-info.eu/art-66-gdpr/) of the GDPR is being used in the wild?
Edit: If my memory is correct, Worldcoin claims to have a “key” that was generated using your retina, but the key is not associated with your identity. You can then present the key to a third party who can verify with Worldcoin that you are human, but not a specific person.
[1] Imagine a bot that could impersonate you and drain your bank account, for example.
Altman (for some reason) needs a ton of biometric data, so go around the world and especially to poorer places, offer folks funny money in exchange for their biometrics and run off.
Set aside the moral and ethical questions and it's quite frankly a very good way to get your hands on this type of data.
It's a bit like the outlandish COVID vaccine conspiracy theories: Step 1: Vaccinate people and deploy 5G wireless networks. Step 2: ??? Step 3: Total power over people; world domination.
But that's kind of beside the point. I wouldn't be at all confident that you or I thinking about this problem for a few minutes are going to uncover every possible abuse vector that a motivated nefarious actor will in the future.
Collecting this kind of private data for no clear benefit looks sketchy as hell.
#1: AGI is coming soon.
#1.a: Because of #1, there will be a flood of unverifiable bot activity on the internet, easily outnumbering real human interaction by 100x+. The only way to identify other humans is some sort of biometric verification process.
#1.b: Because of #1, the vast majority of people will become an economic net-negative. They can't outproduce an easily replicable AGI more than they consume. Thus we need a Universal Basic Income (without the messy fraud) and a way to evenly distribute it, so that people can still enjoy a decent quality of life.
Sama has written about these concerns on his blog about a decade ago. Or just believe it's "because money $"
If he's also working under the assumption that AGI is inevitable, it would make sense to want to be first at it so it aligns with his values more, while also preparing for a post-AGI world.
If I thought that AGI was anywhere close to imminent (which I don't), then this perspective seems to me like it has a great risk of being a self-fulfilling prophecy. Why risk being the one to bring the bad thing into existence? Wouldn't it make more sense to let someone else be the bad guy and instead focus on defense?
Maybe an analogy is more like an unsafe building collapsing randomly versus a controlled demolition after getting everyone out? The thing is going to happen, but if you're the one to make it happen, you can prevent it from being as much of a disaster. Not all possible AGIs are equal, he sees it as making it so when there is an AGI, it's aligned to his values.
It's being defensive against bad-AGI by developing good-AGI first. It's not clear if it will work, but it's better than just hoping setting up a good framework for UBI will keep your from being turned into paperclips.
The intrinsic problem is that over the internet, you're basically getting an "id=<hash of biometric data>" field, and how do you know that biometric data actually came from a scanner rather than a hacker who stole the master biometric database? This is the intrinsic problem with any e-verification: there is no way to distinguish between a human initiated something on their computer and a program on the computer imitated a human initiated something on their computer, and if you have a problem that requires you to distinguish the two, well, you're out of luck.
Of course, 20 years from now if this is actually true well then we HAD to sell the biometric data at some point because a project of this size needs the funding.
We really had no choice in the matter at Worldcoin. We didn't want to sell the biometric data but we couldn't see any other way to get to UBI.
Is this depiction of basic income as (inherently) fraudulent yours? Or Altman’s?
This AGI is supposed to be super intelligent right?
I wonder if it can figure out 'Nice browsing history you have there Pete, would be a shame if your wife saw it. Now scan your eye for me please'.
I don't think this will help anything against a real AGI.
I still haven't really figured out why they want to scan eyeballs. Biometrics might be part of a secure solution to account access but I would hate to lose access to my account because I got in a accident and lost an eye.
I do not believe the conspiracy theories about gathering biometric data, if only because what would be the point? But the stated reasons are so silly that it is easy to believe in an ulterior motive.
There is a huge problem in the cryptocurrency space where you don't know if 10 accounts belong to 10 individuals, or one individual. So a bunch of projects are trying to figure out a solution to this, to prevent sybil attacks.
Gitcoin Passport is one of those solutions, where you can connect various accounts to a "Passport", which you can then hand over to services who can see you have a certain score, but not exactly what that Passport is connected to, so you still preserve your privacy.
I think Worldcoin is another attempt at this, with the idea that the iris scans they do are unique in the world. So basically like a normal cryptocurrency wallet, except these ones also have a ID/hash or something that indicates their "iris value" or something.
Then Worldcoin can guarantee/prove that one individual only has one wallet.
At least that's my understand of it, happy to be corrected.
(Guess I should add that I personally don't use or support Worldcoin at all, but I have read about it a couple of times at this point)
One of the only (dubious) advantages of crypto is that nothing ties a wallet to a person, or a wallet to another wallet unless they interact. How is WorldCoin better than just having a bank account that you have to go into a bank in person to set up?
The point is that application developers can limit access to their $whatever by real humans, and force uniqueness.
> One of the only (dubious) advantages of crypto is that nothing ties a wallet to a person, or a wallet to another wallet unless they interact. How is WorldCoin better than just having a bank account that you have to go into a bank in person to set up?
This seems to be generally about cryptocurrencies at large, doesn't seem specific to Worldcoin as far as I understand.
I think the assumption is that "Someone wants to use a cryptocurrency and someone built a platform, now the builder wants to make sure the user is unique", and without that, then there isn't really anything to discuss.
I think the idea is both about being able to use it for ID (specifically, ID that you are a unique human being), while also making it accessible in places where there's large "unbanked" populations. If it was BankAccountCoin, there would be over a billion people left out. I'm not a fan of it, and I don't think it will ever work as well at this as it will at making Sam a bit more cash, but the concept isn't entirely flawed.
Which only works if you have somehow created a completely secure method proving the provenance of iris scan data. Given the intent is to lock a bunch of money behind this, I highly doubt that this is remotely possible.
If worldcoin has real value, someone will find a way to obtain and replay iris scans to make money.
Biometrics is simply not a good security mechanism.
Not trying to defend worldcoin. It's just that this problem of differentiating people and AI online matters a lot to me and I haven't thought of a reliable way yet, even theoretically.
Make everybody play Where's Waldo? with a grid of 9 blurry pics.
Except sometimes Waldo is a bus, bridge, or traffic light.
I don't think that there is a way to do this without an unacceptable level of sacrifice in terms of privacy/security. I hope my opinion is very wrong, but so far I haven't seen any sign that it is.
Blockchain attestations seem interesting but I'm not yet convinced by them. I'm glad there are people working on this problem though.
If you want to generate fake humans, having a shit load of real raw biometric data at hand is probably going to be useful.
Offended the wrong person? Stood in the way of their plans? Black box back room deals get you a criminal record with arrest warrant. It doesn't even matter then if they are tied to your real identity. The government asks the private identity provider who you are at say an airport border control and private entity says: oh they're this fugitive, arrest on sight. Then what?
> banned in a country
We don’t need the irises. We just need brand loyalty.
>“Our efforts to engage with the AEPD and provide them with an accurate view of Worldcoin and World ID have gone unanswered for months,” he added. (FT article)
Personally I go with the free market idea that if a company wants to provide a service and users want to take advantage of it, 4 million+ so far including myself, then governments provide limited value by blocking that unless they can show it's actually harming people.
* or whatever motive one wishes to ascribe to the mix of for- and non-profit entities involved in muddying the waters OpenAI-style