Lines

How Biometric Data Collection Can Be Dangerous — Even When Built With Blockchain

Project UpdateAugust 13, 2024
New image

Governments have been collecting our data biometric data for decades now, and although some people seem to be bothered by it, most acknowledge it’s a necessary evil — some countries won’t approve your entry without it. However, one thing is to provide our personal data when it’s mandatory; another is to — although willingly — provide it to a private entity in exchange for money. Let’s delve into the latest news on biometric data collection and the dangers behind it.

ID Data vs Biometric Data Collection

The European Commission defines biometric data as “personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopy data”. These include scanning and storing your irises and/or fingerprints, and photographing your face, among other physical features.

When we talk about ID and personal information, it’s more about date of birth, full name, and in some cases, numbers associated with an individual’s citizenship documents, like an ID card, a driver’s license, or a passport. Some websites require you to verify your identity by providing such information. 10 years ago, your email address or phone number would be enough to open an account on social media. Nowadays, the companies behind these platforms might ask you for more: maybe your address, or ID.

A privacy-centric approach
Companies like Consensys and KILT are currently developing data-collecting tools for KYC and compliance purposes — people are now able to verify their identity online, be it to validate crypto wallets, or to keep an ID in a verified mobile app. This is done with the users’ consent, and they should be aware of the potential risks. Still, the companies developing these verification and storage applications assure a high level of security when it comes to privacy and personal data. The information is usually only stored on the user’s device or account and never released to a public space or the company. This is a very different kind of data-collecting method: it’s supposed to be safe for both users and companies, operating solely as a tool to ease the verification process. To know more about how Web3 thinkers are paving the way towards a safer, more private KYC and compliance world, read our article.

It’s a given
Websites have also been collecting people’s IDs and other personal information — like shopping or eating habits, financial background, etc — for many years now. There’s usually a consent form where each person can choose what information allows to be collected. They use this data mainly to determine market trends, customer preferences, and so on. The real issue arises when the box people tick also includes sharing this data with other entities — it’s hard to know how and for what it will be used.

Governments also collect information, sometimes even more than just our ID. It’s very common to pass through a country’s immigration security and have your retina and face photographed, and fingerprints collected. No one really explains for how long these will be stored, or for what they will (or can) be used. Nowadays, it just comes naturally, usually “for the sake of security”.

The Worldcoin Case

A quick online search for “worldcoin foundation biometric data” unveils countless news about how the Worldcoin Foundation’s efforts to collect people’s data are hitting a wall from governments and official institutions a bit all over the world, from Portugal to Hong Kong. In March, the Portuguese National Data Protection Commission (CNPD) ordered Worldcoin to cease all biometric data collection operations in the country, arguing the need to “safeguard the fundamental right to the protection of personal data, in particular of minors. (…) the CNPD considered that the risk to citizens’ fundamental rights is high, justifying an urgent intervention to prevent serious or irreparable harm.” How did Worldcoin work? They’d set up stalls in major locations like shopping malls and urged people to register and provide their biometric data in exchange for crypto tokens. Until the ceasing of operations, 300,000 people, including minors and migrant workers, had already submitted their information through the Orb device. Most of them didn’t even know what they were signing for, just that they were receiving money.

In Hong Kong, the Office of the Privacy Commissioner for Personal Data (PCPD) also ceased Worldcoin’s operations for the same reasons: due to privacy and personal data concerns.

According to Worldcoin’s website, the company has already stored the identity of more than 6 million people, with the purpose of becoming “the world’s largest privacy-preserving human identity and financial network, giving ownership to everyone.” The idea is that every individual can have a globally-inclusive identity, thus becoming part of the world’s economic system. At the same time, they ensure the privacy of the users’ data. However, the whole system seems a bit ambiguous. Although they assure personal data is “encrypted in transit and at rest”, there are still concerns from governments about the destination of such information. The media mentioned cases where Worldcoin was retrieving data — via the Orb — from minors, and migrant workers, people whose incentive was the money they were getting from providing such important information. Would these individuals be as willing to give their biometric data if tokens weren’t involved?

The blockchain-based project is interesting and poses a great deal of potential, especially with the rapid evolution of AI and related technologies, but the question remains: where does one draw the line?

Virtually any company can be hacked, which means these details that they so vehemently say are safeguarded and protected, can be compromised — although the storage might be done on a decentralized system, the collecting itself usually occurs on a centralized one. Biometric data poses identity theft risks that can last an individual’s lifetime since your iris and fingerprints remain the same forever. A more hypothetical logic can even suggest a higher risk for surveillance and tracking, thus leading to discrimination and other issues.

Blockchain-Based Biometric Systems

When biometric data collecting started, there was no blockchain involved, which meant less security. Most biometric systems are now being built with this technology, which ensures a higher (and stronger) level of security. Worldcoin is being developed with blockchain. According to the company, people only need to sign in once: at the moment the Orb scans the iris. This information isn’t kept; what’s stored is the IrisHash, a set of generated numbers that are unique to each person. The IrisHash is then used to access a digital wallet to create their WorldID or passport.

Last May, the company announced a new multi-party security system to prevent cybersecurity issues: The data from one iris is “broken down” into different pieces that are then stored in different places, which means it’s distributed. To decrypt and read the iris information of one individual, one will have to grab the scattered pieces from all over.

Decentralized systems are, indeed, the safest ones — at least from a technological standpoint. Imagine the following scenario: there’s a hidden treasure inside a box that requires 4 keys. A centralized system would keep all the keys in the same place; they could be hard to find, but when someone did, they’d be able to discover the treasure. A decentralized storage system would have you hide each key in a different place, making it almost impossible to uncover the treasure.

Blockchain provides other advantages, including user control (blockchain can enable individuals to have greater control over their biometric data by allowing them to grant and revoke access permissions through smart contracts), anonymization, and pseudonymization (biometric data can be stored in an anonymized or pseudonymized form on the blockchain, reducing the risk of personal identification and enhancing privacy protection), auditability, and trustlessness. If needed, biometric data stored on blockchain can also be useful for easier and quicker cross-border data sharing.

The integration of blockchain with biometric data collection and storage offers numerous benefits, including enhanced security, privacy, and efficiency. However, it is essential to address the challenges and risks associated with this integration through robust technical, legal, and ethical frameworks. By doing so, organizations can leverage the full potential of blockchain technology to create secure and trustworthy biometric data systems.

• • •

About Integritee

Integritee is the most scalable, privacy-enabling network with a Parachain on Kusama and Polkadot. Our SDK solution combines the security and trust of Polkadot, the scalability of second-layer Sidechains, and the confidentiality of Trusted Execution Environments (TEE), special-purpose hardware based on Intel Software Guard Extensions (SGX) technology inside which computations run securely, confidentially, and verifiably.

Community & Social Media:
Join Integritee on Discord | Telegram | Twitter Medium | Youtube LinkedIn | Website

Products:
L2 Sidechains | Trusted Off-chain Workers | Teeracle | Attesteer | Securitee | Incognitee

Integritee Network:
Governance | Explorer | Mainnet | Github

TEER on Exchanges:
Kraken | Gate | Basilisk

You Might Also Like

New image
Project UpdateSeptember 10, 2024

TEERdays: A New Unit That Will Shape Incognitee

New image
Project UpdateSeptember 01, 2024

Common European Data Spaces: Fostering Data Innovation & Collaboration in the EU

New image
Project UpdateAugust 05, 2024

Monthly Wrap-Up July 2024: Talking at Decoded, Launching Treasury Proposals, Publishing Articles & More

New image
Project UpdateJuly 30, 2024

Hyperautomation: The Power of Blending AI, Blockchain, and RPA

New image
Project UpdateJuly 18, 2024

Cybercrime on the Rise: Why Is Securing OT Systems Paramount?

New image
Project UpdateJuly 02, 2024

Monthly Wrap-Up June 2024: Incognitee Bug Bounty Launch, Polkadot Treasury Proposal & More

New image
Project UpdateJune 26, 2024

Become a Collator Operator for Integritee Network!

New image
Project UpdateMay 02, 2024

MiCA & Other Crypto-Related Regulations: Striking the Right Balance

New image
Project UpdateApril 23, 2024

DEXs on Polkadot: Leveraging the Power of Substrate & Shared Security

New image
Project UpdateApril 16, 2024

Slot Auctions vs Coretime: What’s Changing for Polkadot Projects

New image
Project UpdateApril 03, 2024

Monthly Wrap-Up March 2024: Listing TEER on Basilisk, Attending Sub0 & Paseo Landing

New image
Project UpdateMarch 19, 2024

DEXs: The What, The Why & The How of Decentralized Exchanges

New image
Project UpdateMarch 05, 2024

Monthly Wrap-Up February 2024: Crowdloan, Governance and Treasury

New image
Project UpdateFebruary 05, 2024

Monthly Wrap-Up January 2024: Launching the Incognitee Testnet, Winning a Hackernoon Award & Much More!

New image
Project UpdateFebruary 02, 2024

Polkadot Crowdloan: Campaign Kicks Off on February 7th!

New image
Project UpdateJanuary 30, 2024

2023 at Integritee: Product Releases, Partnerships, a Privacy Sidechain & Much More

New image
Project UpdateJanuary 19, 2024

OLI Systems Releases Research Paper about a DLT-Based Local Energy Market Model

New image
Project UpdateJanuary 05, 2024

Monthly Wrap-Up December 2023: New Products, Fresh Content & More

New image
Project UpdateJanuary 03, 2024

2023 Integritee Content: Giving Back to Our Community

New image
Product UpdateDecember 11, 2023

Unlocking Privacy in Transfers: The Power of Integritee’s Private Sidechain Model

New image
Project UpdateDecember 05, 2023

Monthly Wrap-Up November 2023: New Content, TEER Recover & Tech Updates

New image
Project UpdateNovember 06, 2023

Monthly Wrap-Up October 2023: Joining an Accelerator Program, Launching the New Website, Educational Content & More!

New image
Project UpdateOctober 06, 2023

Monthly Wrap-Up September 2023: Winning an Award, Talking at Sub0, Partnering with OVH & More!

New image
Project UpdateSeptember 27, 2023

OVH Releases Whitepaper on How Integritee Is Re-Inventing Blockchain Security & Confidentiality Using Intel SGX Technology & OVHcloud

New image
Project UpdateSeptember 04, 2023

Monthly Wrap-Up August 2023: Launching the Attesteer, Encointer’s PoP Badge & More

New image
Product UpdateAugust 30, 2023

Launching Integritee’s Attesteer

New image
Project UpdateAugust 08, 2023

Monthly Wrap-Up July 2023: Video Releases, Tech Updates & More

New image
Project UpdateJuly 06, 2023

Monthly Wrap-Up June 2023: Polkadot Decoded, New Add-Ons and More

New image
Project UpdateJune 06, 2023

Monthly Wrap-Up May 2023: Governance Platform Launch, New Environments and More

New image
NewsMay 09, 2023

Integritee Launches New Governance Platform with Polkassembly

New image
Project UpdateMay 04, 2023

Monthly Wrap-Up April 2023: Tech Upgrades, Partnerships & Upcoming News

New image
Project UpdateApril 06, 2023

Monthly Wrap-Up March 2023: Product Releases, a Privacy Sidechain & More

New image
Project UpdateApril 04, 2023

Securitee & enclaive Team Up to Offer Ready-To-Use TEE-Secured Solutions

New image
Product UpdateMarch 30, 2023

Securitee Launches Confidential Computing Platform to Protect Data in Use

New image
Product UpdateMarch 23, 2023

Introducing Integritee’s Teeracle: A Framework to Build TEE-Based Oracles

New image
Project UpdateMarch 21, 2023

A Privacy Sidechain for All Polkadot & Kusama Chains

New image
Project UpdateMarch 06, 2023

Monthly Wrap-Up February 2023: Launching Roadmap, Partnerships and More!

New image
NewsMarch 03, 2023

SDK v0.11.0: Increased Performance and Faster Processes

New image
NewsFebruary 21, 2023

OLI Systems Develops Innovative Energy Market Place by Building on Integritee

New image
Project UpdateFebruary 09, 2023

Integritee Network: Roadmap 2023

New image
Project UpdateFebruary 06, 2023

Monthly Wrap-Up January 2023: Slot Swap, Davos Touchdown and Much More

New image
Project UpdateJanuary 03, 2023

Community Updates: Discord, Twitter Raids & More

New image
Project UpdateJanuary 03, 2023

2022 at Integritee: Winning Parachains, Hosting Events, Integrating with Projects & Much More

New image
Project UpdateDecember 01, 2022

Monthly Wrap-Up November 2022: Lisbon Happenings, Bifrost Integration & More

New image
Project UpdateNovember 16, 2022

XCM Integration of Integritee and Bifrost Completed

New image
Project UpdateNovember 14, 2022

Integritee Welcomes Sergei Medvedev as New Advisory Board Member

New image
Project UpdateNovember 10, 2022

Monthly Wrap-Up October 2022: Travels, Interviews, Tech Updates & More

New image
Project UpdateOctober 06, 2022

Monthly Wrap-Up September 2022: Integritee SDK Release, Token2049 & More

New image
Project UpdateSeptember 20, 2022

Integritee & Securitee: Connecting the Dots

New image
Project UpdateSeptember 08, 2022

Integritee’s SDK: A New Era of Web3 Application Building

New image
Project UpdateSeptember 05, 2022

Monthly Wrap-Up August 2022

New image
Project UpdateAugust 30, 2022

Integritee Sidechain Performance Benchmark

New image
Project UpdateAugust 24, 2022

Integritee & Crust Team Up for Publicly Verifiable Decentralized Content Storage

New image
Project UpdateAugust 23, 2022

Integritee’s Polkadot Crowdloan

New image
Project UpdateAugust 03, 2022

Monthly Wrap-Up July 2022: Winning a Slot on Polkadot, Integrating with Karura & Much More

New image
Industry InsightsJuly 27, 2022

From Web 2.0 to Web3: A Step Forward

New image
Project UpdateJuly 18, 2022

Polkadot: The Next Step in Integritee’s Growth and Development

New image
Project UpdateJuly 13, 2022

Integritee Rewards Structure: Early Birds, Loyal Followers, Family, Friends, and More!

New image
Project UpdateJuly 11, 2022

The Integritee Polkadot Crowdloan Campaign Starts Today!

New image
Industry InsightsJuly 07, 2022

XCM Integration: What Is It and How Does It Work?

New image
Project UpdateJuly 05, 2022

Monthly Wrap-Up June 2022: Kraken listing, Talking at Polkadot Decoded & More!

New image
Project UpdateJuly 01, 2022

XCM integration of Integritee & Moonriver Completed

Lines