FB pixel

Worldcoin security audit shows safe biometrics handling, limited data collection

Worldcoin security audit shows safe biometrics handling, limited data collection
 

A security assessment by Trail of Bits says Worldcoin’s software for biometrics collection with its orb devices is sound from a data protection and privacy perspective.

Trail of Bits also provided the third-party security analysis of biometric digital voting platform Voatz back in 2020.

The Worldcoin security audit report found the orb collects little personally identifiable information, and safely handles the iris biometric code, which is the only piece of PII that leaves the orb.

Tools for Humanity asked Trail of Bits to assess a series of claims about its software. The Worldcoin developer claims that “For the default opt-out signup flow, no personally identifiable information (PII) except the iris code is collected by the orb;” and that “For the non-default opt-in signup flow, PII is handled securely by the orb.” Further, they say “The Orb does not extract any sensitive data from a user’s device” and “The user’s iris code is handled securely.”

The assessment was carried out by three security researchers, who put in a total of six weeks of engineering review, according to a blog post from Worldcoin.

The security researchers identified four possible attack vectors, along with “unconfirmed concerns” that led Worldcoin to update some code.

However, the researchers say their “analysis did not uncover vulnerabilities in the Orb’s code that can be directly exploited in relation to the Project Goals as described.”

Worldcoin’s security audit follows a series of questions from data privacy regulators, with recent examples in Spain and South Korea. Whether they will find the answers it provides satisfy their concerns remains to be seen.

The projects the company refers to as “Wave0” of its Community Grants Program are getting some exposure, meanwhile, in the form of another blog post describing half of the 28 grantees. Several of the projects relate to blockchain voting, in particular for decentralized autonomous organizations (DAOs). Others address monetizing spending data, integrating multi-party computation and visualization of World ID public keys.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Certainty vs flexibility – does the UK need a Biometric Surveillance Act?

By Professor Fraser Sampson, former UK Biometrics & Surveillance Camera Commissioner Last week London became a city of two tales. Two…

 

TestMu AI releases testing tool for agent-produced code

TestMu AI (formerly LambdaTest) has launched Kane CLI, “a new browser automation tool that runs directly from the terminal,” and…

 

Travel biometrics making new connections

Airport biometrics projects and companies are breaking new ground and intersecting with other industry trends, from digital wallets to biometric…

 

Biometric Update Podcast: Teresa Wu on SIA’s Corporate Credential Design Guide

The Security Industry Association (SIA) has published its Corporate Credential Design Guide, and Idema Public Security’s Teresa Wu, who has…

 

AI agents operating continuously at machine speed are breaking human-centric IAM

New research commissioned by Ping Identity and compiled by KuppingerCole Analysts shows that “agents are being deployed into production faster…

 

Criticism follows inclusion of Madras Security Printers in Sri Lanka digital ID bids

Civil society group the People’s Struggle Alliance (PSA) has raised concerns regarding the inclusion of Madras Security Printers (MSP) in…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events