InfoBedingungenDatenschutzKontakt
 
Wird aktualisiert
The Web3 Security Podcast

The Web3 Security Podcast

Veröffentlicht: 2026-01-27
© TheWeb3SecurityPodcast
The Web3 Security Podcast - QR Code
12 Folgen
Audio
Anhören auf Apple Podcasts
12 Folgen
Audio
Anhören auf Apple Podcasts
Veröffentlicht: 2026-01-27
© TheWeb3SecurityPodcast
Aktuelle Folge
Web3 Security Podcast: DC Builder, Research Engineer at World Foundation

Web3 Security Podcast: DC Builder, Research Engineer at World Foundation

World Foundation's proof of personhood system defended against an iris spoofing attack where users verified multiple times by pairing their left eye with someone else's right eye—exploiting uniqueness checks that operated on eye pairs rather than indi
Länge: 1:09:21
World Foundation's proof of personhood system defended against an iris spoofing attack where users verified multiple times by pairing their left eye with someone else's right eye—exploiting uniqueness checks that operated on eye pairs rather than individuals. DC Builder, Research Engineer at World Foundation, explains the multimodal defense they deployed: continuous 3D heat mapping, time-of-flight sensors, anomaly detection models trained on contact lens datasets across manufacturers, and checks for glasses that alter iris patterns.
This represents one attack surface in a system protecting 38 million verified humans. World became Nvidia's largest security partner for Jetson NX embedded chips, filing more CVSS reports than any other customer after discovering edge cases from production deployment that Nvidia's internal teams hadn't encountered. DC's current focus: building Proofkit, a Noir backend optimized for client-side ZK proving on constrained mobile devices, because the 99th percentile of World's users operate phones with minimal memory and CPU headroom.
The technical architecture spans layers most Web3 teams never touch. Trusted execution environments and secure enclaves depend on vendor supply chains. Private keys etched into Orbs during manufacturing get destroyed after provisioning. Groth16 proofs require trusted setups from both PSE and World's own ceremony. Multiparty computation encrypts iris codes, but compromise would expose biometric-derived data. Open-source firmware on ejectable SD cards enables independent verification against GitHub repos—an auditability model DC walks through in detail.
Topics discussed:
Iris spoofing via eye permutation attacks: left-eye/right-eye combinations bypassing uniqueness checks
Multimodal biometric defense: 3D heat mapping, time-of-flight sensors, contact lens detection across manufacturers
Filing majority of Nvidia Jetson NX CVSS reports through production edge cases undiscovered internally
Building Proofkit: Noir backend optimized for ZK proving on memory-constrained Android devices at 99th percentile
Formal verification pipeline: automatic GNARC-to-Lean circuit extraction developed with RayLabs
Groth16 trusted setup dependencies: PSE ceremony plus World's own setup and associated compromise risks
MPC protocol security: encrypted iris codes and what exposure means for biometric-derived sensitive data
Hardware auditability: ejectable SD cards enabling firmware verification against open-source repositories
Supply chain trust model: secure enclave vendors, TEE implementations, manufacturing key provisioning
Attack surface inventory: hardware TEEs, Linux-based custom OS, biometric ML pipelines, MPC protocols, ZK circuits
Folgen-ID: 1000746925009
GUID: ff2e4e58-75a4-4cc1-9194-5bd3b67c6f52
Erscheinungs­datum: 27.1.2026, 23:18:41

Beschreibung

The Web3 Security Podcast explores the discipline of Web3 security through conversations with leaders at prominent crypto and Web3 companies.
Each episode delivers practical insights into security philosophies, strategic approaches, and vendor evaluation processes. Our guests share hard-earned lessons from the field, without revealing sensitive implementation details or vulnerabilities.
We dive deep into the thinking behind security decisions, the challenges of protecting decentralized systems, and the strategies that actually work. Whether you're a CTO, security leader, or technical decision-maker, you'll walk away with concrete insights to strengthen your security posture.

Apple Podcasts: Kundenrezensionen

Kein Eintrag