Fun

Worldcoin: Trail of Bits audit shows no vulnerability for Orb software

News Feed - 2024-03-14 11:03:36

Christopher Roark9 hours agoWorldcoin: Trail of Bits audit shows no vulnerability for Orb softwareA third-party project audit reportedly claimed that Orb devices do not record users’ iris codes onto persistent memory and only transmit codes through end-to-end encrypted messaging.11331 Total views2 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksHuman identity project Worldcoin has obtained a third-party audit of its Orb software, according to a draft of a March 14 report from the development team seen by Cointelegraph. The audit was performed by Trail of Bits, which claimed to have found no vulnerabilities that “can be directly exploited in relation to the Project Goals as described,” the report stated. The full Trail of Bits report is expected to be published on March 14, according to an emailed statement from Worldcoin.


Worldcoin allows people to verify their humanity by registering with a phone number or email address or by having their iris scanned by an Orb device. When a user performs this registration, they obtain a “World ID” that can be used to prove they are an actual human. The project was co-founded by Sam Altman, who also co-founded ChatGPT developer OpenAI. Altman claimed that he helped to create Worldcoin out of fear that artificial intelligence (AI) bots may soon be able to pose as humans effectively.Source: Worldcoin on X


Privacy advocates have criticized Worldcoin on the grounds that it risks leaking users’ iris scans to hackers or governments. These iris scans could potentially be used to reveal all of the activity a person performs with their World ID.


Related:Spanish court denies Worldcoin’s injunction request against regulator


According to the report from Worldcoin, Trail of Bits began its assessment on Aug. 14, 2023. The security firm was given version 3.1.10, which was “frozen” for assessment purposes on July 8, 2023. The current version is 4.0.34, the report stated.


The auditors reportedly spent six weeks investigating the code for any potential vulnerabilities. They considered several attack vectors that a hacker could use to obtain a user’s iris scan but ultimately concluded that “our analysis did not uncover vulnerabilities in the Orb’s code that can be directly exploited in relation to the Project Goals as described.” Specifically, the auditors concluded that an attacker could not obtain the user’s iris code unless the attacker has control of one of the trusted certificates. They reportedly stated:“We believe the iris code is not written to persistent storage on the Orb and that it is included only in a single request to the Orb’s back end [...] [W]hile this configuration can be improved to make it more secure (TOB-ORB-10), it should not be possible for typical attackers to extract the iris code from the Orb’s network traffic; the attacker would have to be in control of one of the trusted certificates.”


According to the report, the auditors did make two recommendations to improve the Orb’s security. The first was to “harden” the configuration for the signup flow to ensure that future changes do not introduce security issues. The second was to replace the ZBar library used to scan QR codes during signup with a pure Rust version. The auditors claimed that ZBar might have “memory safety” issues that could leak configuration data, such as the user’s “data custody choice,” if this change was not made. The Worldcoin team implemented both of the suggested changes, the report stated.


The debate over Worldcoin’s privacy practices may continue for some time. On March 6, Spain’s Agency for the Protection of Data issued an injunction against the project, claiming that the agency needed time to investigate claims that Worldcoin violated data protection laws. In response, Worldcoin claimed that it did not violate these laws and that the Spanish government was “circumventing EU law” by issuing the injunction.# Blockchain# Privacy# Identity# AI# Worldcoin# RegulationAdd reactionAdd reactionRead moreLazarus Group moves $12M from HTX, HECO hacks to Tornado CashData privacy and security concerns worry nearly half of tech industry consumers: ReportNigerian crypto community split over govt’s bid for Binance user data

News Feed

While Bitcoin and Ethereum Dominance Slides, Stablecoin Market Caps Reap the Rewards
While Bitcoin and Ethereum Dominance Slides, Stablecoin Market Caps Reap the Rewards During the past 30 days, $285 billion has left the crypto economy and bitcoin’s USD valu
Crypto market crash triggered by ‘aggressive’ selling by Jump Trading: Report
Zoltan Vardai11 hours agoCrypto market crash triggered by ‘aggressive’ selling by Jump Trading: ReportJump Trading significantly contributed to the crypto market sell-off, and it could be looking to sell another $104
Report: UK Gold Dealer Sold Out of Bullion After Pound’s Record Fall Causes Demand to Skyrocket
Report: UK Gold Dealer Sold Out of Bullion After Pound"s Record Fall Causes Demand to Skyrocket The United Kingdom-based gold dealer, Ash Kundra, has claimed that he recently ran o
Joe Hall11 hours agoBitcoin builder climbs Africa’s tallest mountain to raise awarenessAdvocates for the Bitcoin Lightning Network and decentralized protocol Nostr funded Kweks’ Kilimanjaro climb.2912 Total views35 T
US Bank Launches Cryptocurrency Custody Services Amid Strong Demand From Institutional Clients
US Bank Launches Cryptocurrency Custody Services Amid Strong Demand From Institutional Clients US Bank has launched its cryptocurrency custody services. “Investor interest i
Pocketcoin (PKOIN) Is Now Available for Purchase With Visa/Mastercard and 19 Different Cryptos
Pocketcoin (PKOIN) Is Now Available for Purchase With Visa/Mastercard and 19 Different Cryptos sponsored Pocketcoin (PKOIN) is a Proof-of-Stake token that is used decentralized adve
Spot Ethereum ETFs are coming, but ETH derivatives markets are flat
Marcel Pechman3 hours agoSpot Ethereum ETFs are coming, but ETH derivatives markets are flatEther futures show little confidence in the chance of ETH breaking above $4,000 in the near term.1986 Total views121 Total share
Hermi De Ramos13 hours agoMetaverse projects failed on lack of correct business model: MetaMinds CEOAs the metaverse loses its appeal to some global tech leaders, MetaMinds Group CEO Sandra Helou argues that failures in
Ethereum’s quick rebound positions ETH price for 100% rally
Yashu Gola24 minutes agoEthereum’s quick rebound positions ETH price for 100% rallyEther price is mirroring a fractal pattern from October 2023 that preceded a 178% ETH price rally.254 Total views1 Total sharesListen t
AI safety researchers leave OpenAI over prioritization concerns
Amaka Nwaokocha12 hours agoAI safety researchers leave OpenAI over prioritization concernsFollowing the recent resignations, OpenAI has opted to dissolve its “Superalignment” team and integrate its functions into oth
ICO Aftermath: US Rules in Favour of SEC in $100M KIK Case – SALT to Reimburse Claimants From 2017 ICO
ICO Aftermath: US Rules in Favour of SEC in $100M KIK Case – SALT to Reimburse Claimants From 2017 ICOA US court has ruled in favour of the US SEC after the regulator’s fili
Red Alert For Solana: 21% Price Drop Raises Fears Of Further Collapse
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu