• Home
  • Cryptocurrency
  • Blockchain
  • Analysis
  • News
    • Regulations Security
    • Getting Started
  • Insights
    • Opinion
    • Expert Interview
  • All Posts
Facebook X (Twitter) Instagram
Trending
  • KiloEx Exchange Exploiter Restores All Stolen Funds Following $7.5 Million Hack
  • Hashkey Targets XRP ETF in Asia with New Fund Supported by Ripple
  • Sygnum Predicts Potential Altcoin Rally in Q2 2025 Due to Enhanced Regulations
  • Media Tycoon Files Counterclaim Against Justin Sun in $78 Million Sculpture Dispute
  • Yemenis are embracing DeFi in response to US sanctions on the Houthi group
  • Saylor and ETF Investors’ ‘Stronger Hands’ Contribute to Bitcoin Stabilization — Analyst
  • Bitcoin Dip Buyers Show Interest at BTC Range Lows, Yet Remain Risk-Averse Until $90K Establishes Support
  • Kyrgyzstan’s President Enacts CBDC Legislation Granting Legal Status to ‘Digital Som’
Facebook X (Twitter) Instagram
CoinovelCoinovel
  • Home
  • Cryptocurrency
  • Blockchain
  • Analysis
  • News
    • Regulations Security
    • Getting Started
  • Insights
    • Opinion
    • Expert Interview
  • All Posts
CoinovelCoinovel
Home » Orb software found to be free from direct vulnerabilities in Worldcoin: Trail of Bits audit
Orb software found to be free from direct vulnerabilities in Worldcoin: Trail of Bits audit
Orb software found to be free from direct vulnerabilities in Worldcoin: Trail of Bits audit

Orb software found to be free from direct vulnerabilities in Worldcoin: Trail of Bits audit

0
By admin on 2024-03-14 Blockchain, Regulations Security

Worldcoin, the Human Identity Project, has received a third-party audit of its Orb software, as stated in a draft report from the development team seen by Cointelegraph. The audit, conducted by Trail of Bits, found no vulnerabilities in the Orb software that could be exploited to undermine the project’s goals. The full report from Trail of Bits is expected to be published on March 14, according to an email statement from Worldcoin.

Worldcoin allows individuals to verify their humanity by registering with a phone number, email address, or by scanning their iris using an Orb device. Upon registration, users receive a “World ID” that serves as proof of their human identity. The project was co-founded by Sam Altman, who also co-founded OpenAI, the developer of ChatGPT. Altman expressed concerns about the potential for artificial intelligence (AI) bots to convincingly impersonate humans, which motivated him to create Worldcoin.

Privacy advocates have raised concerns about Worldcoin, arguing that it exposes users’ iris scans to the risk of being accessed by hackers or governments. These scans could potentially reveal all of the activities associated with a person’s World ID.

According to the report from Worldcoin, Trail of Bits commenced its assessment on August 14, 2023. The security firm was provided with version 3.1.10, which was frozen for assessment purposes on July 8, 2023. The current version is 4.0.34, according to the report.

The auditors reportedly spent six weeks examining the code for potential vulnerabilities. They considered various attack vectors that could be exploited by hackers to obtain a user’s iris scan. However, they concluded that no vulnerabilities were found in the Orb’s code that could be directly exploited to undermine the project’s goals. Specifically, the auditors stated that an attacker would require control of one of the trusted certificates to obtain a user’s iris code.

The report also mentioned two recommendations made by the auditors to enhance the Orb’s security. The first recommendation was to strengthen the configuration of the signup process to prevent the introduction of security issues in the future. The Worldcoin team implemented this recommendation. The second recommendation was to address a bug in the ZBar library used for scanning QR codes during signup. The auditors identified “memory safety” issues in ZBar that could potentially leak configuration data, such as the user’s “data custody choice.” In response, the Worldcoin team replaced the ZBar library with a pure Rust version.

The debate surrounding Worldcoin’s privacy practices is likely to continue. On March 6, Spain’s Agency for the Protection of Data issued an injunction against the project, citing the need to investigate claims of data protection law violations. Worldcoin maintained that it did not breach these laws and accused the Spanish government of bypassing EU law by issuing the injunction.

Update 4:18 pm UTC on March 18: This article has been updated to provide clarification regarding the vulnerability in the ZBar library.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

KiloEx Exchange Exploiter Restores All Stolen Funds Following $7.5 Million Hack

Media Tycoon Files Counterclaim Against Justin Sun in $78 Million Sculpture Dispute

Yemenis are embracing DeFi in response to US sanctions on the Houthi group

  • Popular
  • Latest
  • Hot comments
2022-02-23 Getting Started

Cryptopedia: Unveiling the Metaverse’s Potential to Revolutionize the Internet

2022-03-07 Getting Started

Unveiling Cryptopedia: Grasp the fundamentals of DAOs and their operational mechanisms

2022-03-25 Getting Started

Cryptopedia: Explore Web3 and its goal to revolutionize internet services

2025-04-18 Regulations Security

KiloEx Exchange Exploiter Restores All Stolen Funds Following $7.5 Million Hack

2025-04-18 Cryptocurrency

Hashkey Targets XRP ETF in Asia with New Fund Supported by Ripple

2025-04-18 Cryptocurrency

Sygnum Predicts Potential Altcoin Rally in Q2 2025 Due to Enhanced Regulations

Latest Gallery

Latest Recommendations
2025-04-18 Regulations Security

KiloEx Exchange Exploiter Restores All Stolen Funds Following $7.5 Million Hack

2025-04-18 Cryptocurrency

Hashkey Targets XRP ETF in Asia with New Fund Supported by Ripple

2025-04-18 Cryptocurrency

Sygnum Predicts Potential Altcoin Rally in Q2 2025 Due to Enhanced Regulations

2025-04-18 Regulations Security

Media Tycoon Files Counterclaim Against Justin Sun in $78 Million Sculpture Dispute

2025-04-18 Blockchain

Yemenis are embracing DeFi in response to US sanctions on the Houthi group

2025-04-18 Regulations Security

Saylor and ETF Investors’ ‘Stronger Hands’ Contribute to Bitcoin Stabilization — Analyst

2025-04-18 Cryptocurrency

Bitcoin Dip Buyers Show Interest at BTC Range Lows, Yet Remain Risk-Averse Until $90K Establishes Support

2025-04-18 News

Kyrgyzstan’s President Enacts CBDC Legislation Granting Legal Status to ‘Digital Som’

2025-04-17 Blockchain

Polygon’s Nailwal: The Jio Partnership Will Propel Real-World Web3 Adoption for 450 Million Users

2025-04-17 Blockchain

Babylon’s Total Value Locked Decreases by 32% as Wallets Unstake $1.2B in Bitcoin

2025-04-17 Regulations Security

OpenAI pursued a deal with Anysphere prior to shifting its focus to WindSurf

2025-04-17 Analysis

Bitcoin Gold’s Imitation Strategy Could Surpass $150K as BTC Remains ‘Remarkable’

2025-04-17 Cryptocurrency

AI Tokens and Memecoins Dominate Cryptocurrency Narratives in Q1 2025: CoinGecko

2025-04-17 Cryptocurrency

Four Reasons Why the Price of Bitcoin Could Surge to $90,000 in April

2025-04-17 News

Trump Criticizes Powell for Delaying Interest Rate Cuts, Calling It ‘Too Late’

2025-04-17 News

Wyoming Commission Considers Whether Stablecoin Falls Under SEC Regulations

About
About

Coinovel is an enthralling novel of cryptocurrencies. Engage with narratives, delve into stories, and journey through the captivating world of digital currencies.

X (Twitter) Telegram
Popular posts
2022-02-23 Getting Started

Cryptopedia: Unveiling the Metaverse’s Potential to Revolutionize the Internet

2022-03-07 Getting Started

Unveiling Cryptopedia: Grasp the fundamentals of DAOs and their operational mechanisms

2022-03-25 Getting Started

Cryptopedia: Explore Web3 and its goal to revolutionize internet services

Copyright © 2025 coinovel. All rights reserved.
  • Home
  • Cryptocurrency
  • Blockchain
  • Regulations Security
  • Analysis
  • Insights
  • News
  • Getting Started

Type above and press Enter to search. Press Esc to cancel.