How do you prove somebody is human? It is a surprisingly hard problem. I think that people are going to start getting accused of being bots.
What we currently see is less than 1% of what it will look like in probably a year or two. The idea that AGI will lead to some very fundamental shift seems obvious.
The AIs are really good at programming humans. Much better than humans are at programming AI.
Absolutely. The AI will be able to have a GitHub account and will be able to post and also attest to five other AIs that these are in fact humans and even though they're not. Honestly, if you don't take it seriously now...
Alex, welcome to the podcast. Great to have you.
Thanks for having me. So, Proof of Human is having a moment right now. Why don't you first give a background for people who are unfamiliar? What is the moment that's happening and how did we get here?
Yeah. And what is proof? Proof of human.
Proof of human, as the name suggests, is, you know, do you know if you interact with a human or like something else on the internet? And I actually think the kinds of questions that we're now asking is are you interacting with a human, an agent on behalf of a human, or just an agent? I think these are roughly the three areas that we want to split apart.
Well, and describe a little bit the difference between just an agent and an agent acting on behalf of a human. How do you see that distinction?
Yeah. So, quickly explaining just the term proof of human and I think what is hard about it and then I will explain how that fits into an agent on behalf of a human. So what proof of human really means is that every individual that interacts on a platform has only one, ideally one account, or a limited number of accounts, and stays the owner of that account. That's kind of the property that you're looking for. You're looking for an initial verification that ideally should be anonymous or extremely privacy preserving, and then ongoing authentication that the same person remains in control of the account. And then there's some secondary properties I think are good to have, but that actually tells you that the really hard thing is uniqueness. What is happening on a platform like Twitter right now is that there's all these bots in the replies, and there's probably one human sitting somewhere sending out tens of thousands or hundreds of thousands of AIs. And there's this catch-up game where Twitter and X are trying to just find them and block probably millions a day of these.
Which is what, like a hundredth of the bots? That's how it feels like.
And then agent on behalf of human, I think how it will look like is, you know, I think all of us will have agents. It's unclear how it will look like, is this going to be one or multiple ones maybe with different tasks and different even types of characters. And I think it will then come down to, I approve a certain action of my agent, I give him certain rights to act on my behalf.
Okay, post to my X account, post to my Instagram.
For example. But it's my Instagram and I'm a unique human that owns it.
That's right. You know, then X or Instagram could decide if that's actually something they want as a platform, right? But that's how you could do it.
That makes sense. And so how do you prove somebody is human?
It is a surprisingly hard problem.
Yeah. So, you know, those agents are very, very clever. It's funny. We started this company a couple years ago before ChatGPT and before all of that. But we kind of took that as an assumption that eventually we will have AIs that both pass the Turing test so they can just claim to be a human, you will not be able to tell them anymore on the internet, and also that they would be highly agentic and just run around doing their own thing. And so that makes it really, really hard because back then when we started the company there were roughly three big ideas that people were interested in. One was this idea of web of trust or related ideas. So this idea that you look at how someone behaves on the internet or did behave in the past. So usually a combination of you have these certain number of accounts that you own since a couple years and then you post regularly or you comment regularly to GitHub, these were the kinds of things that people were using. And then let's say all three of us have them and then I attest that I know you in the real world and I attest to you that I know you in the real world and that's how you would build a certain graph. And that was a very hot idea back then. But we disregarded it basically immediately because we assumed that eventually everything that is just digital an AI will be able to do it as well.
Yeah. Exactly. So an AI will be able to have a GitHub account and will be able to post and own an account and also attest to five other AIs that these are in fact humans and even though they're not. So that was area number one. And area number two was to just use government IDs for everything, which we just all disregarded for a couple reasons. One is, I think it's strictly better if the government would not control such an infrastructure in terms of free speech and actually breaking that apart.
Right, you lose anonymity instantly.
You could hypothetically set up a system that maybe preserves it but it's very hard to do. And then the second thing is also the government identity system is just not built for that. And what is so hard about this problem is it's going to be a global problem and so it doesn't really matter if one government maybe has the perfect infrastructure. For example, Singapore is an example of a government that has perfect infrastructure all around.
But that barely matters because, for example, Meta is a global product with three billion users with a lot of other countries.
Yeah, Singapore is what, like 2 million people or 5 million people.
Yeah, exactly. So do you want to lock everyone else out?
So yeah, and then there's a long list of other things why we disregarded that basically immediately. And then the last one is biometrics, which actually immediately gives us this ick reaction. And it even went further because what is so hard about this problem as I mentioned in the beginning is uniqueness. And so just in very simple words how you can describe the problem is, well first of all, for example, what does Face ID do? Face ID checks that I'm the same person again using my phone. And so it's a one-to-one authentication. So there's an embedding stored on my phone. It takes a picture of my face, creates a new picture, compares to the previous one, and if that is close enough, I can use my phone. But so that's a one-to-one, one embedding to one new embedding. To solve the proof of human problem, you will need to distinguish one new individual from all previous individuals.
You need to make sure that Ben is trying to sign up and Ben did not sign up before.
Yeah. And then suddenly it goes from one-to-one to one-to-N, and N is the size of your network essentially that you're trying to prove that to. And then you can just do the math and you can calculate how much mathematical entropy, like how much information just information theoretically do you need to prove that. And it turns out that's a pretty high number because it's an exponential problem.
And so then you can just do the math and you find out that things like a face or even fingerprints or something doesn't work. Like that, then you would basically hit a wall after tens of millions of users. And so then you end up with something like iris, which is the muscle of your eye that actually has enough entropy.
That is unique enough. And how do you also then solve the, you know, one thing that biometrics have been subject to historically is just replay attacks.
Where okay, I may not have your eyeball, but I've got enough information that I can run a replay attack on you.
So there's now actually, again it is important I think to split up the problem in verification, which is essentially in old terms it's like you're getting your passport, and then authentication which is you showing your passport constantly for certain kinds of things. And on the verification piece, we've went down the Worldcoin path, we've built this thing called an Orb. It's doing a lot of things to prevent these kinds of attacks. So it's for example it has multiple sensors in the electromagnetic spectrum to just make sure that you cannot show a display to it and it would recognize that. So I think on that side we've got it handled. On the consumer side, to then reauthenticate, it turns out to be much harder because you would need to trust the phone in some sense. Because what we actually do in that moment is when you verify with an Orb, not only do we check your uniqueness in a fully anonymous and privacy preserving way, and we should talk about that, but also we send to your phone a signed face image that you then can later use to reauthenticate against it. And with a new iPhone you can have meaningful amount of trust against that but with old Android phones basically not. And so yeah, because you can just show a deepfake essentially either through a display or just directly injected in the camera stream. So that's a problem. And so it's going to be a mix of, if you have a new enough iPhone or general phone, then you can just reauthenticate against that picture that you took on verification. Otherwise, you would probably have to even go back to an Orb somewhat frequently. Like let's say a couple times a year if you just see you, to reauthenticate.
Interesting. And then, you know, one of the kind of incorrect criticisms of the approach early was, 'Oh my god, they've got my eyeball.' Now they somehow have access to my privacy and they're going to do all these things to me and Worldcoin can impersonate me and all these kinds of things. But that's not the case. And so that was also a non-trivial engineering problem.
That was very much non-trivial. So actually I think one point on iris that I think people don't appreciate enough and that's a bet we took back then but it was essentially that iris will turn out to be supernormal as a modality just because I think we will all wear AR and VR systems that do that. You know Apple already does it, Apple already has iris ID in the Vision Pro. So I think it's going to become something that we will use across many different devices and we'll normalize in that sense. But I think on the privacy piece, that took us a lot of time because when we decided back then, which was 6 years ago, that we will need a custom hardware device for biometrics. It was actually quite scary to come to the conclusion because...
Yeah, that's an expensive conclusion.
It's like very expensive and then just having this idea that you would need to distribute them all over the world, that just assumes that you would be able to somehow bring up billions of dollars and do a massive effort to distribute all over the world. But then also the privacy challenge of how could you build such a system that has all the requirements that we care about. And the two main high-level ideas on how to solve it were multi-party computation and zero knowledge proofs.
And so to again, what is different to Face ID, because Face ID actually can be very private just because the embedding is stored on the phone. It doesn't have to leave the phone ever just because it's just you against you in the past. But to check uniqueness, you need to check against all previous people. So something needs to leave. Something needs to leave something and be compared to someone else. And that's a much harder challenge. And how we approach that is we have multi-party computation. And so that essentially means that in our case when you verify with an Orb, we take all these pictures, they get computed on the device and then they actually get split up in multiple pieces. So for example we take a picture of the iris, we calculate an iris code, then we break that iris code in multiple pieces and send it to multiple computers such that there is no central database in some sort. So no one actually has the information about you.
And then you do some clever tricks of how these different parties need to come together to do a computation that still leaves the pieces apart.
Where nobody has the whole thing.
Yeah. So no one has the whole thing and also during the computation no one has the whole thing, but they do some clever interactions to come to the conclusion.
A little like a zero knowledge proof kind of technique. It's very different but I think in terms of the properties it achieves it's somewhat similar where no one knows anything about you but you can actually together make a statement about you.
And so you send it to this multi-party computation and what comes back is yes that individual is unique. And then the second thing we do is we separate all of this from you with a zero knowledge proof. So meaning you have that secret on your phone but no one else has it. No server has it. We don't have it. And then you can later go back to this multi-party computation and say like hey I have a secret that is part of that computation and I am in fact unique. And you can prove that to a platform. You could go to the social network and prove that you're a unique user to the social platform without us knowing anything about you or the social network knowing anything about you. And so it's this very counterintuitive property that even though it uses biometrics you preserve anonymity and extreme levels of privacy which I think is super cool.
You know, social media is one kind of vector of things that were annoying and are now becoming overwhelming in terms of just bots, particularly with SCOPs, propaganda, all these kinds of things. What are some of the other uses of bots that are going to be kind of impossible to live with if we don't get to proof of human in the future?
Yeah. Actually, I think the simple model I have for it is every moment on the internet that is primarily about humans interacting with each other, or even indirectly interacting with each other. So you can start with simple ones like dating, you know, that it really matters.
What is the other side is in fact the person.
Got bad news for listeners.
Well and the person who you expect it to be.
Yeah. Exactly. We had the problems even before, catfish thing.
Yeah. So that's an obvious one. And so for example, Tinder is already using it for that reason. I think...
And what's the Tinder use case? So...
So we started in Japan as a test market and it's essentially exactly what we just discussed. It is if you verify with an Orb, you get a little badge that signals to other people that you are in fact a human. So it has a high level of verification. And then also, I don't think that's live yet, but what will come next is that you're actually the person you claim to be. So meaning you have a World ID that is associated to the kind of profile pictures that you use. So you just run a quick check that this is all correct. And so you then know you're not interacting with a bot, but also you interact with a fully authentic profile.
Yeah. Another fun one because I think it's somewhat counterintuitive but I think it will be video conferencing because you already have deepfakes.
Yeah, just I don't feel like going to this video conference, just put my deepfake up.
Yeah. And actually you raised it to me first and that's why we started building a product for it because it will actually start with very high value users, like for example people like yourself that maybe manage a fund and sometimes calls actually could be very high value if it's about borrowing money or...
Oh yeah, yeah, yeah. Well so somebody can be me and say Eric can you please wire this Nigerian prince $400 million.
Right, yeah, exactly. Be good to know. Yeah.
Yeah. Like that's still slightly hypothetical because these things are not fully real time and you can somewhat...
But we're very close and so I think in a year from now it's just going to be a full commodity and it's going to be super photorealistic and absolutely real time and you will just not know anything anymore on these vehicles. And so I think that's another one. I think another one then will be, which I think is fun but it's going to be gaming. Because...
Because the gamers really care.
Oh, yeah. That they're not playing an AI. Holy cow, that's frustrating.
Especially if we bet money.
Exactly. And you lose money. You train multiple hours a day to get really good at this thing and then suddenly you get destroyed by an AI that is just superhuman in every dimension.
Um, funny enough, I was like, I wonder what you think about this bit because I don't have a good mental model about it, but even the whole model for video platforms, I think, is about to break because there's a couple dimensions to their problem. But one, if the creation of content is becoming super scalable, like for example, I heard about this one guy that created I think like on the order of a hundred videos a day on YouTube and made...
Tens of thousands of dollars a month. All of them were fully AI generated.
Yeah. And people just fell for it. So now the question is, is that actually something that YouTube wants to monetize that way? Like is that...
Yeah. Well, it's interesting, right? They fell for it. But maybe they liked it. Like that could be, but it would sure be nice to know like, okay, this is a human video or this is an AI video.
Um, actually, my thesis about this is something along the lines of I think there's categories of content that are clearly just fictional.
Like movies are that, you know, it's like you don't care that there's any connection to reality. It's just a fully fictional story. But now if you think about something like TikTok or all these kind of things like people actually really care about them mostly because there is some connection to reality.
Yeah. Well, there's reality and there's connection to human, right? So, you can create a pretty good, like you can take a scientific paper and give it to Gemini and say, 'Make this into a podcast' and, you know, it'll be like a pretty entertaining podcast and it will be reality in that it came from some real thing.