Trail of Bits completes Worldcoin security audits, finds no vulnerabilities

Share This Post

Cybersecurity firm Trail of Bits has concluded the audit of Worldcoin’s ORB technology and found that it adheres to stringent privacy protocols, particularly in how it processes and stores personally identifiable information (PII).

The full report was released on March 13 and revealed that there are no vulnerabilities in the ORB software and validated many of the claims made by Worldcoin.

The audit was initiated on Aug. 14, 2023, after multiple regulators across the globe raised concerns about Worldcoin’s biometric data collection, with some outright banning its operations.

The audit

Trail of Bits’ audit aimed to meticulously examine the orb’s software, particularly focusing on its handling of personally identifiable information (PII) and the management of users’ iris codes.

During the default opt-out signup flow, the orb collects no PII except for the iris code, which is neither written to persistent storage nor leaves the orb. In scenarios where users opt-in, their PII is encrypted on the orb’s SSD in a manner that even the orb itself cannot decrypt — showcasing a robust approach to data privacy.

Moreover, the audit verified that the orb does not extract additional sensitive data from a user’s device, with the only information collected being from a QR code. This ensures a minimal data collection approach, aligning with privacy best practices.

Importantly, the iris code, a critical piece of biometric data, is handled securely throughout its collection and transmission process, effectively mitigating the risk of unauthorized access or interception.

Recommendations

The audit also highlighted areas for improvement, recommending additional hardening of the orb’s software and hardware configurations to bolster security further.

In response, Worldcoin has implemented changes, including replacing a vulnerable library used for QR code scanning with a more secure alternative.

The Trail of Bits audit represents just one part of Worldcoin’s ongoing efforts to ensure the security and privacy of its technology. With the ORB technology being central to the Worldcoin project’s mission to provide a universal basic income, these rigorous security assessments are crucial for maintaining user trust and project integrity.

Recognizing the importance of transparency and community engagement, Worldcoin has invited public participation in its bug bounty program and plans to share future audit reports as they become available.

The post Trail of Bits completes Worldcoin security audits, finds no vulnerabilities appeared first on CryptoSlate.

Read Entire Article
spot_img

Related Posts

Don’t Get Bitten! France Cracks Down On Unregistered Crypto Platform Bybit

French regulators are sending a strong message to the cryptocurrency industry: play by our rules, or get out The latest target Bybit, a major crypto exchange, which has been blocked by the French

Infamous crypto scam service Pink Drainer shuts down after netting $85 million

Pink Drainer, a notorious crypto wallet-draining service, is winding down its operations, according to a May 16 screenshot shared by blockchain sleuth ZachXBT A Dune analytics dashboard by Web3

Farmsent to enhance smart farming with Nuklai AI tools as peaq raises $35M amid token launch

Nuklai, an on-chain smart data platform, and peaq, a layer-1 blockchain for decentralized physical infrastructure networks (DePINs), have announced an integration aimed at enhancing AI and data

Spot Bitcoin ETFs Record Third Day Of Massive Inflows As Price Tops $66,000

In another remarkable day for cryptocurrency investments, US-based spot Bitcoin Exchange Traded Funds (ETFs) witnessed a substantial influx of capital, totaling $2573 million on Thursday This

US Bitcoin ETFs see fourth consecutive day of inflows, adding $257.3 million

Quick Take US ETFs According to data from Farside, US Bitcoin (BTC) exchange-traded funds (ETFs) saw a $2573 million inflow, marking the fourth consecutive day of inflows The inflows were widespread,

Base to Launch Online Hackathon With 200 ETH in Prizes, Sponsored by Stripe, Shopify, and More

Base, the Ethereum Layer 2 solution incubated by Coinbase, has announced the Onchain Summer Buildathon The event, which runs from May 31st to June 30th, invites builders worldwide to showcase their
- Advertisement -spot_img