Thank you. Yeah, my name is Steve McCown, and I'm a chief architect at Anonyome Labs. I'm also a steering committee member for the Decentralized Identity Foundation. And so I'm here today to talk about personhood credentials. This is kind of a 101 level intro class, but I entertained as many questions as you'd like. The way I like to do presentations is I don't mind being interrupted, so feel free to just raise your hand and shout them out, and we'll talk about whatever is important to you at that time. All right. So first slide. Is this picture real or fake?
And yes, I do want answers from the audience. So this is actually—I want you to tell me why it's real or fake. Does anything stand out for this picture? The unicorn is the national animal of Scotland, so we can't go based on just that. But when I look at this picture, it looks a little too real. It looks a little too vibrant, which makes me think it's not real. So how I created this is I went into Google Gemini and I said, create a picture of a unicorn near Loch Ness, which is why you've got the little Nessie down there, in Scotland.
And so there's a few tells, and not just that it's a unicorn or that there's a dinosaur in the picture, but there's a few tells related to the picture itself, why this looks fake. And so we look at it and we can kind of get a little sense that it's not exactly real. So let's take a look at this one. How about this one? Does this one look real or does that look fake? That one looks really pretty real, in part because we have people interacting with it. And so there's kind of a sense, other than our kind of inherent, I've never seen a unicorn, so I don't think they exist.
There's this sense that it feels a little more real to us. This also was created with Google Gemini. I asked for a specific, specifically for a unicorn on the streets of Edinburgh, Scotland. And this is what it came back with. And I really was kind of impressed by it. I could have looked up pictures on picture sites, but it created this in about three seconds. And so it was really pretty quick and easy. So now things get a little more serious. This has been talked about a couple of times. I'm sure you've heard this in the news.
So last fall, it came out that a finance worker paid out $25 million. So what happened? The back story is he started getting emails saying, you need to transfer $25 million from this account to that account. And he got suspicious, as he should have, that that was not a real request. And he wanted to verify it. So he verified it by getting everyone on a video call. So he was in a video call, ostensibly with everyone from his team, people he knew. And in fact, he was the only real person on the call. His boss was there, the CFO of the company, saying, please transfer the money, which he did.
And so it starts to get pretty serious, these deepfakes, what AI is able to do. So now it can get actually damaging. So down in Australia, there's a real doctor, that guy. But this is from a deepfake video. So the doctor deals with all sorts of issues, including diabetes. And this video was promoted on Facebook, and everything on Facebook is real. So as people are watching that video, here is a real doctor with a deepfake, telling people to stop taking their diabetes medication and to try this all-natural drug.
And what's alarming about this is that they are coupling the real world with the AI-generated fake world. And this is where it gets to be a real big problem, because people might actually stop taking their regular medication, which may have side effects. And that's the nature of medication. And there's this presumption that all-natural medication is better and safer for us. And so it really played on people and our perceptions of what's real, or good, or harmful, or better, and so forth. So what's going on, as we're finding out, is AI makes fraud easy, fast, and cheap.
And again, this little logo right here, also Google Gemini-generated, because I didn't want to take the time to make something myself. I just had AI make it in a matter of seconds. And this is a real problem for us, because when fraud is so easy, fast, and cheap, what happens is we're going to see more of it. And so the question is, how do we tell? What do we do? So last year, there was a paper that was written by quite a large number of energy industry participants called Personhood Credentials.
So the 100,000-foot view of what this is, is we want to give everyone a digital credential, digitally sign everything, and then make it super easy to verify. So when you hear personhood credentials, that's what's going on. We'll talk in a little bit more detail. But just those three steps right there, they will be very helpful, but there's also some potential harm in there. And so they continued on. These need to be privacy-preserving credentials.
The nature of a digital signature is that it's fingerprintable, and we don't want to create a way to track everybody and everything across the internet. We just want to know whether they're a real person or not, and then we can decide what to do with that.
Yes, sir. Go ahead. If that model you had just walked over was a real walkout from that video, would the video have been used in practice to give confidence that it was a real video? Yes. And so if the video played saying, this is a real doctor, what you, the user, the consumer need, is a way to verify that. So the provider of a legitimate video would have signed that with one of these personhood credentials, and then presumably the player would have a quick and easy way to verify that.
In the old days, before Chrome got wise and decided we didn't need to know if things were HTTPS encrypted, there was a little yellow lock on the bar. And when you saw that lock, it would tell you that at least a secure socket layer was in place. And so it was a quick and easy way to verify that.
This, we're moving into a world where we need something like that. We just want to know, is this real? Is it fake? I don't want to verify anything. I don't want to see the crypto that went into it. I just want some simple icon to tell me I'm OK. All right. So what is a personhood credential? It's very simple. All we want is a credential that empowers holders to prove that they're a real person and nothing more. So we've heard about verifiable credentials all week long and how they can prove this and that. You're over 21 and you're from this country or that country.
That's not what a personhood credential is, although in theory it could contain that. Really, this is geared towards answering one question. Is the person I'm dealing with on the Internet or the artifact that's been created, was it created by a real person or not? And that's it. So some of the foundational requirements in the paper are you're supposed to get one credential that proves you're a person and only one. You only need one. And it needs to be unlinkable and synonymous. So we want to have anonymous interaction. We're not trying to track you. We're not trying to identify you.
If you say, I like this president, I don't like that president. We're not trying to track that. All this is intended to do is prove that you're a real person so that the other person can know that they're talking to a human and not a bot. The other number three is really important. We need these to not be forgeable by AI, which is getting good at doing such things. All right. So now we start to get into a few technical details that are outlined in the paper.
Basically, it's kind of what you're accustomed to. There's a user, and on the left side here, they put out a credential request, and then they provide evidence of some sort. Maybe they get this through their motor vehicle department or their university or the hospital, wherever they get this. There's some evidence provided that allows the issuer to verify that they're, in fact, a human. And then they will issue this credential subject to any validity checks that they give, and then the user has that credential.
Very simple, very similar to the verifiable credential formats that we've seen talked about and we've used for years. Now, here on the right, when we use that, we want to submit that to a service provider of some sort and assert that we're a human. We want to do that with some type of zero-knowledge proof.
Again, the idea is not to track that you went to this site or you consumed this service, but to enable the service provider to know that you're a human and not a bot. Yes?
So, excellent question. Holder binding is really important. If I get a personhood credential, and you pick up my phone because I've left it unlocked, and you go to your favorite site and assert that you're a human, is that acceptable? Not really. We want the people, and in a minute we'll talk about services that employ these personhood credentials, to be able to use them and not have any other person or entity use those credentials. And there's a lot of reasons for that. We'll talk about a couple here in just a second. All right.
So, some of the benefits of these is we want to reduce the impact of fake actors online. Also, mitigate bot attacks. One of the big things we see in a lot of ways is this doesn't preclude denial of service, but we see that kind of thing where there's a bot army that comes and corrupts databases by inputting too much data or whatever's going on. We want to make sure that if proof of humanity is a check, that that gets done. And so then a bot would presumably not have one of these credentials and therefore not be able to assert their personhood, and then that request could simply be rejected.
Now, the last thing almost seems a little bit counterintuitive. We want to verify the delegation to AI agents.
Now, okay, that's really kind of funny because we're wanting to discriminate between a real human and differentiate that between an AI. But as we've seen this week, we do want AIs to work on our behalf.
I, for example, might want to book a flight this evening from here to Paris on a nice airline at a good price. That's all I care about. Don't really care which particular airplane, don't care which seat, I just need to get there. And so I might delegate that to an assistive AI that'll work on my behalf and take care of that for me so I don't have to do all that on my phone. So those types of AIs are coming and we're going to want them.
And so there needs to be some way for that AI operating on my legitimate behalf to prove that they're working on my behalf and what does that mean in terms of these credentials. All right. Some of the challenges is we also need to make sure that personhood credentials, can they affect your access to digital services? Will this block you from using some services? Will they be so required and if you don't have one, you really need one and can't operate? Will some of the ways that these are implemented prioritize some users over the next?
Those are some of the challenges that we need to vet those out as these start to come online. Will people feel safe using them? If I have to assert a credential issued specifically to me, will I as the average non-technical customer feel that my comments are non-attributable? Maybe I do want to speak anonymously. I want to give my input into a political process without fear of retribution of some sort. And so will users feel comfortable actually putting these into practice? Will this affect tech providers?
Right now, if you log in with a federated identity to another site, right now the provider of that federated identity is in a really neat spot because they control all those identities, they get insight into the access. How will that affect those tech providers? Will it start to distribute that a little more evenly and take away from that vantage point? And how will we be able to detect any errors or subversions to this process? Those are things that we need to kind of think through and just kind of model those as those come online. So there's some technical cautions.
So as we've been talking about verifiable credentials, most of those carry some flavor of cryptography such as ED25519. We're moving into a world where in 2030 or thereabouts, depending on your segment of the industry, post-quantum cryptography will be required. And so these credentials and others need to migrate to a quantum-safe cryptography. And they need to be implemented in such a way that this is a zero-knowledge proof implementation so that we don't unintentionally create a very deterministic tracking mechanism. Because that's not the point.
The point is not to track people, but just to be able to prove whether they're a person or an AI. To do that, we need to make sure we prioritize privacy and security above interoperability.
Right now, we see systems that prioritize interoperability so high that they're almost compromising some of the privacy and security aspects in order to be interoperable. That is just a balance that we need to keep in balance so that we don't sacrifice privacy and security. And then make sure that these credentials can be proven and vetted without any kind of phone home to the issuer process. If your credential requires correlation with the issuer, the issuer becomes in this vantage point of they know when and where every person used that credential.
And that can create a very large surveillance network, which I don't think any of us want. And so, we need to make sure that the technologies used to implement these types of credentials avoid the surveillance and not build it in from the get-go.
Now, going forward, agentic AI, as I mentioned, we want these AIs to work on our behalf. We want them to do things for us. We are trying to block and differentiate between human activity and AI activity, but we're going to want them.
And so, that is kind of a whole new follow-on. For further reading, there's the original paper. Feel free to take a picture of that, type it in, or it's in the slides. And that's freely available. You can read that paper as well.
Thank you, and there's my contact information. Any questions?
Yes, sir, go ahead. I work in the civil resistance space. Thanks.
So, I was interested in your comment on bot resistance. And one thing that we find is that proof-of-personhood credentials are being farmed by bots. Credentials are being farmed by huge thousands of people who just basically donate their biometrics to obtain these credentials and then send them to a central actor. What's the best way to add a uniqueness level on top of this proof-of-personhood? What do you mean by uniqueness? Sorry. It's partly linked with hold-aligned inputs.
So, if you're using credentials later, you have to still be in the version of the biometrics. You don't want to have the same code, and you don't want the same actor being able to generate several credentials.
Okay, excellent point. One of the things that's happening right now is, take, for example, the iPhone. There's a secure enclave. There's biometric verification to get into your phone. On the surface, that accomplishes what you're talking about because My Fingerprint or FacePrint authorizes me to use the credential that's stored in the, at least partially stored in the secure enclave.
So, as I say that, as a father, when I set up iPhones for my children, I actually put My Fingerprint in their phones so that I could get in their phones. So, the implication of that is that I can exercise their credentials because My Fingerprint unlocks the service protecting the credentials.
So, we're back to your original question. I think we can talk afterwards. There's a number of paths forward, but that is super important, and you've identified something that the industry needs to solve that completely as we move into this trust, especially in a non-issuer contact kind of trust situation.