The Orb FAQs

Jun 11, 2024 2 Minute Read

What is the orb?

The orb is a custom, state-of-the-art hardware device built for the Worldcoin project to verify humanness and uniqueness in a secure and privacy-preserving way. It was developed by Worldcoin contributor Tools for Humanity (TFH).

What does the orb do?

The orb is used to verify a person’s World ID—a private, secure, digital passport that empowers millions of individuals to prove they’re human online. 

It does this by first using highly specialized sensors to ensure the person standing in front of it is a human. It then takes and processes a series of iris images to create an iris code, which is a digital representation of the texture of the iris. The iris code is used to verify that the person is unique and has not verified a World ID before.

All information is always deleted from the orb, including images, once it has been sent to the person’s device.

Does the orb have privacy and security protections?

Yes. Built into the orb’s hardware are diverse privacy and security features designed to ensure that no data can be accessed by anyone unauthorized to do so. 

These include two unique cryptographic keys both permanently burned into the orb’s hardware: one which is provisioned into the main CPU prior to manufacturing and another located in a secure element that cannot be exported. The orb will not operate unless both keys are valid and their environments are intact, and no code can run on it without a cryptographic signature.

Additional orb hardware and backend data security protections include:

  • Asymmetric data encryption at the orb
  • RAM-only data processing
  • Solid-state drive (SSD) encryption “at rest” 
  • Data encryption in transit from the orb to secure servers
  • Use of secure, EU-based AWS and MongoDB servers for data storage of iris codes

This list is not exhaustive. It’s instead intended to demonstrate the seriousness with which privacy and data security are handled at the orb. Security features are continually being evaluated and enhanced by TFH to ensure the integrity of the Worldcoin project.

Is the orb audited to validate its privacy and security claims?

Yes. Regular audits are performed by trusted, third-party auditors to validate the orb’s privacy and security claims.

Most recently, TFH, in conjunction with the Worldcoin Foundation, engaged the respected security experts at Trail of Bits to conduct a specialized audit of the orb’s software.

Is the orb’s hardware and software being open sourced? 

Yes. Many core components of the orb’s hardware and software are already open sourced and freely available on GitHub. More will be open sourced in the future.

Disclaimer

The above content speaks only as of the date indicated. Further, it is subject to risks, uncertainties and assumptions, and so may be incorrect and may change without notice. A full disclaimer can be found in our Terms of Use and Important User Information can be found on our Risks page.