Worldcoin releases audit reports showing resolved security issues

1 year ago

The impervious of humanness protocol released information audit reports claiming that astir issues were fixed oregon mitigated.

Worldcoin releases audit reports showing resolved information    issues

Proof of humanity protocol Worldcoin released its audit reports connected July 28 arsenic disapproval of its information postulation practices continues to mount. The caller reports were conducted by information consulting firms Nethermind and Least Authority. 

According to an accompanying announcement from Worldcoin, Nethermind recovered 26 information issues with the protocol, of which 24 were “identified arsenic fixed” during the verification signifier portion 1 was mitigated and different was acknowledged.

Least Authority discovered three issues and made six suggestions, each of which “have been resolved oregon person planned resolutions,” the announcement stated.

Learn much astir the results of 2 abstracted information audits of the Worldcoin protocol, performed by @NethermindEth & @LeastAuthority.https://t.co/fXa50wNBYE

— Worldcoin (@worldcoin) July 28, 2023

Worldcoin archetypal roseate to prominence successful 2021 erstwhile it announced that it would springiness distant escaped tokens to immoderate users who verify their humanness, which they could bash by having their iris scanned by a instrumentality called an “Orb.” The task was co-founded by Sam Altman, the co-founder of AI developer OpenAI.

At the time, Altman and different squad members argued that AI bots would go an expanding occupation connected the net if radical didn’t find a mode to verify their humanness without giving up their privacy. According to the protocol’s documentation, The Orb produces a hash of the user’s iris scan but does not support a transcript of the iris scan.

Related: Worldcoin confirms it is the origin of mysterious Safe deployments

Nethermind’s Worldcoin audit report. Source: Github

Worldcoin initiated its nationalist launch connected July 25, aft astir 2 years of improvement and beta testing. But disapproval of it erupted astir immediately. The United Kingdom's Information Commissioner's Office (ICO) reportedly said the authorities assemblage was deciding whether to investigate the task for violating the country’s information extortion laws. French information extortion bureau CNIL besides questioned Worldcoin’s legality.

The crypto assemblage was divided implicit the project’s launch, with immoderate participants seeing it arsenic the commencement of a dystopian aboriginal wherever privateness would beryllium eliminated. In contrast, others saw it arsenic a indispensable measurement towards protecting humans against malicious AIs.

The caller audit reports screen a wide assortment of information topics, including absorption to DDoS attacks, case-specific implementation errors, cardinal retention and due absorption of encryption and signing of keys, information leaking and accusation integrity, and others. Some issues recovered were the effect of dependencies connected Semaphore and Ethereum, including “elliptic curve precompile enactment oregon Poseidon hash relation configuration,” the announcement stated.

All issues but 1 were fixed, mitigated, oregon person planned fixes. The 1 information contented that was not fixed by the clip of verification has a severity of "undetermined" and is listed arsenic "acknowledged."

View source