Live data from Hacker News

Worldcoin: A solution in search of its problem

newsletter.mollywhite.net

21–30 of 176 posts

Re: Worldcoin: A solution in search of its problem

#22

Earlier quoted context omitted.

If you have centralised signup and identity you may as well run a Postgres DB or a git repo. It could still be a cool idea, but I don’t get how this needs crypto?

How else do you get A16z to invest?

You play League of Legends while on a pitch call with them

Re: Worldcoin: A solution in search of its problem

#23

I do not understand how this is supposed to prevent sibyl attacks? How do they prevent fake virtual iris scanning devices from pretending that they scanned a person that doesn’t actually exist? Or is the idea that sama is will run a centralised private identity system that aims to replace government identity management? Then why do you need crypto? Are they trying to replace proof of stake/proof of work with “proof o…

> sibyl attacks?

This is exactly the same problem as spam detection - nobody has found a good way to prevent people from generating large numbers of fake identities, short of government identity registration. The classic "Why your solution to spam won't work"[1] checklist applies.

[1] https://craphound.com/spamsolutions.txt

Re: Worldcoin: A solution in search of its problem

#24
post #8

Once again it is completely ignored that the whole online identity thing is a solved problem, in the EU. Millions of Europeans use eIDAS apps daily and enjoy single-sign-on across EU websites, can sign docs, make payments etc. etc. And there’s no privacy issues thanks to the GDPR, which it turns out is not just about cookie popups The tech is there, it works today, without crypto bullshit, and it is extremely useful.…

The whole online identity thing was a solved problem well before that. You sign up for a service, you give them your email address and create a password, now they know who you are because you have your password, and if you forget your password they send a reset code to your email. Add 2FA as you like.

That allows you to authenticate with the service you're doing business with, which is all that ever needs to happen because centralized identity systems are just an attack for correlating your activity across services and devices.

Re: Worldcoin: A solution in search of its problem

#25

I have a Sam Altman story... I did a pre-interview to work for one of Sam's first startups, the mobile one that had the date via GPS idea. Turned down going beyond the pre-interview due to concept and funding combination not being compatible with reality. You have to remember at that point in time Mobile OEMs were locking down GPS access through apps and Mobile Operators were attempting to pretend they were VCs. Not…

This is a story about Sam?

Re: Worldcoin: A solution in search of its problem

#26

Earlier quoted context omitted.

The signup module is indeed a centralized system, which then records the new registration on a distributed ledger (which only someone with Worldcoin’s private key can do). From there, payment operations are done distributed on Ethereum / L2. The signup process is always a sensitive part of a cryptosystem, and open network membership is not always expected (for instance, CBDCs, Ripple…). There is certainly a philosoph…

If you have centralised signup and identity you may as well run a Postgres DB or a git repo. It could still be a cool idea, but I don’t get how this needs crypto?

Presumably so that the underlying system can be auditable by 'anyone'?

Re: Worldcoin: A solution in search of its problem

#29

Earlier quoted context omitted.

How else do you get A16z to invest?

You play League of Legends while on a pitch call with them

I believe that was Sequoia? Who just massively downsized that very fund this week. (Tho he did seem to play LoL on a lot of calls…)

Re: Worldcoin: A solution in search of its problem

#30
Lots of good analysis here, with the main flaw (imho) coming in last*. The WC team may be book smart, but not experienced or wise, especially in building complex systems with high integrity and assurance. They cut too many corners, take too many intellectual shortcuts, assume away too many hard problems, minimize important constraints inherent in their chosen architecture, and clearly haven't really thought it all through. Wishful thinking is no substitute for sound engineering. All red flags of a project doomed to fail.

*> A black market for Worldcoin accounts has already emerged [1] in Cambodia, Nigeria, and elsewhere, where people are being paid to sign up for a World ID and then transfer ownership to buyers elsewhere — many of whom are in China, where Worldcoin is restricted. There is no ongoing verification process to ensure that a World ID continues to belong to the person who signed up for it, and no way for the eyeball-haver to recover an account that is under another person’s control. Worldcoin acknowledges that they have no clue how to resolve the issue: “Innovative ideas in mechanism design and the attribution of social relationships will be necessary.“ The lack of ongoing verification also means that there is no mechanism by which people can be removed from the program once they pass away, but perhaps Worldcoin will add survivors’ benefits to its list of use cases and call that a feature.

Relatively speaking, scanning your iris and selling the account is fairly benign. But depending on the popularity of Worldcoin, the eventual price of WLD, and the types of things a World ID can be used to accomplish, the incentives to gain access to others’ accounts could become severe. Coercion at the individual or state level is absolutely within the realm of possibility, and could become dangerous.

[1]:https://web3isgoinggreat.com/?id=sam-altmans-worldcoin-proje...

Post reply on HN