Ajay

2K posts

Ajay banner
Ajay

Ajay

@patelmtl

Dreamer of ice cream, cookies, and candy --- Head of World ID @tfh_technology @worldnetwork --- McGill | Northeastern | MIT | Xoogler

Mountain View, CA Katılım Kasım 2010
1.8K Takip Edilen421 Takipçiler
Sabitlenmiş Tweet
Ajay retweetledi
World
World@worldnetwork·
Coming soon to the US. 5 extra boosts for humans. @worldnetwork + @Tinder
English
48
54
617
103.5K
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
652
6.1K
24.3K
3.2M
Ajay retweetledi
DL Research
DL Research@dl_research·
Agents are the new interface to the internet. But who's actually behind them? We sat down with @dcbuilder, Research Engineer at @worldnetwork, to discuss how x402 cracked agent payments, and how AgentKit layers proof-of-human on top to solve uniqueness: dlnews.com/research/inter…
English
2
4
21
719
Ajay retweetledi
World
World@worldnetwork·
Join us for Lift Off on April 17 at 10am PT on X and YouTube.
English
35
55
306
39K
Ajay retweetledi
Ajay retweetledi
Tawanda Michael Mahere
Tawanda Michael Mahere@tawandamahere·
Every platform, every payment rail, every app is converging toward the same question for online interactions in the age of AI: is this a real human? Proof of Human limits scaled deception, protects against deepfake impersonation and protects public discourse on social media. It facilitates agents acting on behalf of humans and empowers humans to capture the benefits of AI advances while maintaining trust in online interactions. Looking forward to this conversation!
Michelle O’Connor@Mq2Oco

Not to be missed Proof of Human Salon Series by @tfh_technology & @thehousesf, April 10th 🔜luma.com/jwziweok Conversations include - Rodrigo Coelho, @tawandamahere, Colin Luce, Andy Wang, and more. @basistheory @worldnetwork @edgeandnode

English
1
1
6
508
sunny madra
sunny madra@sundeep·
Just saying…
sunny madra tweet media
English
17
11
97
11.7K
Ajay
Ajay@patelmtl·
You miss the point of where proof of human must land for it to really accelerate humanity. Proof of human is not idv or kyc. Your disagreement is valid if you view the world based on use cases that the internet struggles with today - but that’s a point in time view and not how one should build for scale. TLDR: GovIDs are credentials. They are not inclusive nor are they trusted equally or appropriate for all but a small subset of use cases. Happy to discuss live.
English
0
1
10
98
Rene ◘
Rene ◘@RegenRene·
Aligned with @alexblania on importance of Proof of Human! However, I disagree on the assessment of biometric-chip IDs. They are such an amazing infrastructure to leverage for this. 3B people already have them (and many more can get them). There is also no surveillance risk if you build it the right way, using zero knowledge proofs (ZKPs). That's what we are doing at Self self.xyz 😄
Alex Blania@alexblania

Agentic capability is improving fast. We believe Proof of Human is becoming critical for the internet and many of the platforms we use (like X). This paper explains why FaceID, face biometrics & government IDs won’t solve the problem, and what properties are most important.

English
4
3
27
3.1K
Ajay retweetledi
Sandro Herbig
Sandro Herbig@sandroherbig·
1/ Proof of Human is becoming increasingly critical. In the limit democracy and human agency depend on it. But building Proof of Human is unexpectedly challenging. FaceID doesn't prevent one person to fabricate human presence for thousands of AI agents. Government ID based Proof of Human is a surveillance risk and only 1b out of 8 billion people have verifiable IDs. An anti-surveillance and effective Proof of Human that actually empowers people requires new technology [paper linked in thread] 🧵
Sandro Herbig tweet media
English
16
42
150
23.6K
Alex Blania
Alex Blania@alexblania·
Agentic capability is improving fast. We believe Proof of Human is becoming critical for the internet and many of the platforms we use (like X). This paper explains why FaceID, face biometrics & government IDs won’t solve the problem, and what properties are most important.
Alex Blania tweet media
English
122
158
846
502K
Ajay retweetledi
World
World@worldnetwork·
Join us on April 17th for Lift Off, a live World ID launch event in San Francisco. Hosted by Alex and Sam. With special guests.
World tweet media
English
72
111
525
206.9K
Ajay
Ajay@patelmtl·
Developers have been using World ID to differentiate unique humans and bots. Now, with AgentKit, they can differentiate bots from agents that are acting on behalf of the unique humans that control them. We believe explicit and certain agent delegation is critical to scale. If you're building an agentic service or protocol, please reach out! We'd love to work with you.
World@worldnetwork

As millions of agents start to come online, the internet needs to distinguish bot armies from the agents acting on behalf of humans. Introducing AgentKit, the human layer for agentic automation. Built on World ID, the AgentKit beta unlocks human-verified automation, a new primitive for the agent economy.

English
4
4
31
7K
Ajay retweetledi
Andy
Andy@wangandy·
AWS WAF + World ID User hits rate limit: > Challenged to verify with World ID > Server verifies ZK proof > User issued a temporary session cookie Repo in thread, built by @macdonald_4176 from AWS!
English
6
9
54
12.3K