{"id":56910,"date":"2023-07-29T09:43:21","date_gmt":"2023-07-29T09:43:21","guid":{"rendered":"https:\/\/egrowonline.com\/?p=56910"},"modified":"2023-07-29T09:43:21","modified_gmt":"2023-07-29T09:43:21","slug":"worldcoin-releases-audit-reports-showing-resolved-security-issues","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=56910","title":{"rendered":"Worldcoin releases audit reports showing resolved security issues"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-2649fa34=\"\">\n<p>Proof of humanity protocol Worldcoin released its audit reports on July 28 as criticism of its data collection practices continues to mount. The new reports were <a target=\"_blank\" href=\"https:\/\/worldcoin.org\/blog\/worldcoin\/worldcoin-protocol-security-audit-reports\" rel=\"noopener nofollow\">conducted<\/a> by security consulting firms Nethermind and Least Authority.\u00a0<\/p>\n<p>According to an accompanying announcement from Worldcoin, Nethermind found 26 security issues with the protocol, of which 24 were \u201cidentified as fixed\u201d during the verification phase, while one was mitigated and another was acknowledged.<\/p>\n<p>Least Authority discovered\u00a0three issues and made six suggestions, all of which \u201chave been resolved or have planned resolutions,\u201d the announcement stated.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Learn more about the results of two separate security audits of the Worldcoin protocol, performed by <a target=\"_blank\" href=\"https:\/\/twitter.com\/NethermindEth?ref_src=twsrc%5Etfw\" rel=\"noopener\">@NethermindEth<\/a> &amp; <a target=\"_blank\" href=\"https:\/\/twitter.com\/LeastAuthority?ref_src=twsrc%5Etfw\" rel=\"noopener\">@LeastAuthority<\/a>.<a target=\"_blank\" href=\"https:\/\/t.co\/fXa50wNBYE\" rel=\"noopener\">https:\/\/t.co\/fXa50wNBYE<\/a><\/p>\n<p>\u2014 Worldcoin (@worldcoin) <a target=\"_blank\" href=\"https:\/\/twitter.com\/worldcoin\/status\/1685017542484541441?ref_src=twsrc%5Etfw\" rel=\"noopener\">July 28, 2023<\/a><\/p><\/blockquote>\n<p>Worldcoin first rose to prominence in 2021 when it announced that\u00a0<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/free-coin-to-everyone-project-aims-to-make-1b-crypto-owners-in-2-years\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/free-coin-to-everyone-project-aims-to-make-1b-crypto-owners-in-2-years\/amp\" rel=\"noopener\">it would give away free tokens<\/a> to any users who verify their humanity by having their iris scanned by a device called an \u201cOrb.\u201d The project was co-founded by Sam Altman, the co-founder of AI developer OpenAI. <\/p>\n<p>At the time, Altman and other team members argued that AI bots would become an increasing problem on the internet if people didn\u2019t find a way to verify their humanness without giving up their privacy. According to the protocol\u2019s documentation, The Orb produces a hash of the user\u2019s iris scan but does not keep a copy of the iris scan.<\/p>\n<p><em><strong>Related: <\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/worldcoin-confirms-it-is-the-cause-of-mysterious-safe-deployments\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/worldcoin-confirms-it-is-the-cause-of-mysterious-safe-deployments\/amp\" rel=\"noopener\"><strong>Worldcoin confirms it is the cause of mysterious Safe deployments<\/strong><\/a><\/em><\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-07\/b36272ea-756a-4077-a9cd-e96f6ecb83c6.png\" alt=\"\" title=\"\" \/><figcaption style=\"text-align: center\"><em>Nethermind\u2019s Worldcoin audit report. Source: GitHub<\/em><\/figcaption><\/figure>\n<p>Worldcoin <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/openai-creator-launches-worldcoin\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/openai-creator-launches-worldcoin\/amp\" rel=\"noopener\">initiated its public launch<\/a> on July 25 after nearly two years of development and beta testing. But criticism of it erupted almost immediately. The United Kingdom\u2019s Information Commissioner\u2019s Office (ICO) reportedly said the government body was <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/worldcoin-may-face-uk-data-regulators-enquiry-days-after-launch-report\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/worldcoin-may-face-uk-data-regulators-enquiry-days-after-launch-report\/amp\" rel=\"noopener\">deciding whether to investigate<\/a> the project for violating the country\u2019s data protection laws. French data protection agency \u2014 the National Commission on Informatics and Liberty \u2014 also <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/french-privacy-watchdog-questions-worldcoin-s-data-collection-method-report\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/french-privacy-watchdog-questions-worldcoin-s-data-collection-method-report\/amp\" rel=\"noopener\">questioned Worldcoin\u2019s legality<\/a>. <\/p>\n<p>The crypto community <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/worldcoin-launch-divides-crypto-community\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/worldcoin-launch-divides-crypto-community\/amp\" rel=\"noopener\">was divided over the project\u2019s launch<\/a>, with some participants seeing it as the start of a dystopian future where privacy would be eliminated. In contrast, others saw it as a necessary step toward protecting humans against malicious artificial intelligence.<\/p>\n<p>The new audit reports cover various security topics, including resistance to distributed denial of service attacks, case-specific implementation errors, key storage and proper management of encryption and signing of keys, data leaking and information integrity, and others. Some issues found resulted from dependencies on Semaphore and Ethereum, including \u201celliptic curve precompile support or Poseidon hash function configuration,\u201d the announcement stated.<\/p>\n<p> All issues except one were fixed, mitigated or have planned fixes. The one security issue that was not fixed by the time of verification has a severity of \u201cundetermined\u201d and is listed as \u201cacknowledged.\u201c<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/worldcoin-releases-audit-reports-showing-resolved-security-issues\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Proof of humanity protocol Worldcoin released its audit reports on July 28 as criticism of its data collection practices continues to mount. The new reports were conducted by security consulting firms Nethermind and Least Authority.\u00a0 According to an accompanying announcement from Worldcoin, Nethermind found 26 security issues with the protocol, of which 24 were \u201cidentified [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":56911,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[41],"tags":[4965,1824,160,3882,16717,1349,2033,15470],"class_list":["post-56910","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-audit","tag-issues","tag-releases","tag-reports","tag-resolved","tag-security","tag-showing","tag-worldcoin"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/07\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDcvMjlmZjViM2ItMTNlNS00Y2UyLWIzMTYtMTkyZmRmNTA2NmEyLmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/56910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=56910"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/56910\/revisions"}],"predecessor-version":[{"id":56912,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/56910\/revisions\/56912"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/56911"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=56910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=56910"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=56910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}