Back

Proof of personhood: four approaches compared

Iris, palm vein, social graph, and document plus device. What each one assumes, what it filters, and what breaks it. Including the one this project uses.

The question they are all answering

Every proof of personhood system is trying to establish one thing: that the holder is a distinct human, and that this system has not already granted the same standing to them. Not who they are. That difference is covered in another post; here the interest is in how the uniqueness part is actually attempted, because the four available answers fail in different places.

A note on what follows: this project uses the fourth approach, so treat the assessment of it with the scepticism that deserves. The weaknesses listed for it are the ones that keep me up, not a token concession.

Iris

World ID is the largest deployment. A dedicated device photographs both irises with near-infrared cameras and derives a code used to check whether this person has enrolled before. The uniqueness claim is strong, because iris patterns are stable and highly distinguishing, and the privacy story is better than it sounds: what is retained is a derived code, not a photograph, and presentations can be made without revealing which enrolment they came from.

What it assumes is hardware. Someone has to build, distribute and operate the devices, and you have to travel to one. That makes the operator the trust anchor for the whole system, not by design but by consequence: you are trusting that the thing pointed at your eye did what it claims. It also draws regulatory attention, since iris patterns are biometric data in essentially every privacy regime and processing them at scale is a hard thing to do quietly.

Palm vein

Humanity Protocol took the same shape with different hardware, capturing the vein pattern inside the palm. There is a real argument for it over face or iris: veins are internal, so they cannot be captured covertly from a photograph or across a room, which removes an entire class of passive collection.

It inherits the hardware problem, though. Palm vein readers need specialised near-infrared sensors, which means the same dependency on a manufacturer and a distribution network. Worth noting that in February 2026 the project stepped away from proof of personhood as its framing and kept the palm biometrics for verifiable credentials, which is a reasonable read of where the difficulty actually is.

Social graph

BrightID and Proof of Humanity avoid hardware entirely by using people. Existing verified members vouch for new ones, sometimes with a stake behind the vouch, and uniqueness comes from the structure of the graph rather than from a measurement of a body.

The cost lands somewhere unexpected. These systems are often described as the privacy-preserving option, and in one sense they are, since nobody takes a biometric. But joining Proof of Humanity has meant publishing your face, and a verification party exposes who you are to everyone in it. Against that, the biometric systems are the more private choice, which is the opposite of the intuition.

The structural failure is collusion. A graph resists sybils only while the vouching is honest, and a coordinated group can manufacture standing for accounts that correspond to nobody. Exclusion is the quieter problem: if you have no path into the graph, there is no process to appeal to, and from inside the graph that population is invisible.

Document plus device

The fourth approach checks an identity document and binds the result to a key held in the device's secure element, through WebAuthn or the equivalent. No specialised hardware, no biometric retained, and the document check can be done and discarded: this project keeps nothing, and the credential that comes out carries a score reflecting how many attestations of what kind were completed rather than a single yes.

Now the weaknesses, which are real. Uniqueness is weaker than biometric deduplication, and not marginally. Nothing inherent stops one person enrolling with two documents, or across two devices, unless the system deduplicates on something stable, and anything stable enough to deduplicate on starts to look like the identifier the approach was meant to avoid. That tension does not have a clean resolution.

It also excludes people without documents, which is a different population from the one excluded by hardware but not a smaller one. And it moves the trust question to document authentication, which is a mature field with a known false-accept rate rather than a solved problem.

What none of them do

None of these establishes who you are, and none produces an attestation with legal effect. A personhood credential is not a qualified attestation whatever the issuing process looks like, for reasons that are institutional rather than technical and are set out separately.

And all four trade inclusion against strength along the same axis. Every mechanism that makes the uniqueness claim harder to forge also makes it harder for someone to obtain: a device to travel to, a graph to be part of, a document to hold. There is no configuration that removes the trade, which means the honest question for anyone choosing between them is not which is strongest but which exclusion they can live with.

Get your personhood credential

Verify through the Gateway and receive a DID, a verifiable credential and a personhood token. No personal data is retained.

Stay updated.