Kobi Gurkan
@kobi.bsky.social
📤 799
📥 127
📝 149
applied crypto, security, experimental things. head of research
@baincapitalcrypto.com
Want to understand ZODA? Tried to implement it and found yourself stumped?? This FAQ is just for you! Wrote some answers for questions I’ve seen around me and those I had myself, navigating details and tradeoffs If you have any more - let me know :)
1 day ago
1
2
1
Signature schemes are a cornerstone of modern infrastructure and we all know the common ones that sign a message, and some of you know ones that can be e.g. aggregated In more specialized scenarios, the properties needed aren’t obvious until you hit that problem yourself 1/2
about 1 month ago
1
4
0
Came across an interesting paper this weekend about “Early Signs of Steganographic Capabilities in Frontier LLM” Specifically they’re testing non-fine tuned models that are widely available, like GPT 4.5 1/4
3 months ago
1
2
0
Memory leaks are going to have a whole different meaning soon
3 months ago
0
2
0
You get great results from Claude Code by guiding it to generate tests for itself to verify its output and supporting it by having live data and services running locally, which it utilizes since it runs in your environment And being able to do it on your phone is the best 1/4
4 months ago
1
0
0
reposted by
Kobi Gurkan
Boris
4 months ago
I rewrote my [[Community Search Engine]] note. It's still not very crisp. I include emerging tools that directionally are working on what I want to be using -
@dxos.org
Composer,
@inkandswitch.com
Patchwork (not yet public),
@grjte.sh
'
s
Groundmist
, and the newly released by
Tonk
, TonkbookLM.
3
13
3
Wei Jie’s write ups are among the best resources you can find for in-depth cryptography implementation topics If you’re looking to bridge the gap between theory and practice - have a read
add a skeleton here at some point
4 months ago
0
4
1
I’m on board with nap coding
add a skeleton here at some point
4 months ago
0
2
0
On the lookout for a one click experience to collect interesting things I come across my day, so that I could get a nice summarized digest a day after The closest I had was with X bookmarks, but that’s limited to X
x.com/kobigurk/st...
1/2
4 months ago
1
0
0
Video of my talk in zksummit about Ligerito has been published! It’s about the work by Andrija and
@lmao.bsky.social
introducing a small and concretely fast polynomial commitment scheme Since then, a fun thing has happened — 1/3
4 months ago
1
8
4
“A penny for your thoughts” has a very different meaning now
4 months ago
0
0
0
anyone trying to do provable image transformation as in
eprint.iacr.org/2024/1066
in fast proving zkVMs? It’s one of the cases a bunch of time will pass until you need to compress it for fast verification, if at all
loading . . .
VerITAS: Verifying Image Transformations at Scale
Verifying image provenance has become an important topic, especially in the realm of news media. To address this issue, the Coalition for Content Provenance and Authenticity (C2PA) developed a standard to verify image provenance that relies on digital signatures produced by cameras. However, photos are usually edited before being published, and a signature on an original photo cannot be verified given only the published edited image. In this work, we describe VerITAS, a system that uses zero-knowledge proofs (zk-SNARKs) to prove that only certain edits have been applied to a signed photo. While past work has created image editing proofs for photos, VerITAS is the first to do so for realistically large images (30 megapixels). Our key innovation enabling this leap is the design of a new proof system that enables proving knowledge of a valid signature on a large amount of witness data. We run experiments on realistically large images that are more than an order of magnitude larger than th
https://eprint.iacr.org/2024/1066
4 months ago
1
4
2
reposted by
Kobi Gurkan
leaflet.pub
5 months ago
Leaflet Publications: blogging on Bluesky — version 0.1 is here! ✅ now: make publications, add posts, publish to Bluesky 🗓️ soon: subscribing, commenting & other social features Try it:
leaflet.pub/home
We'd love your feedback & ideas for how we can make this great!
25
279
103
trying out
@leaflet.pub
for my recent post, I'm really enjoying the UI a lot:
kobi.leaflet.pub/3lpruvjqlhs22
just a question - wen math? would like to use it for my next post :D I also see comments are on horizon, but how does it work with unpublished drafts that I don't want others to see yet 👀
loading . . .
Verifiable Verifications - Kobi's blog
https://kobi.leaflet.pub/3lpruvjqlhs22
5 months ago
1
4
0
How are people thinking of tool use with local models? Feels to me qwen 30b a3b gets confused easily, at least when using the OpenAI agents sdk tool infra
5 months ago
0
0
0
real time proving on pretty complex statements on the server side is here same developer experience on client side would be huge for experimentation (delegation is helpful but interested to see what we can do without)
5 months ago
0
0
0
Some thoughts about how verifications in Bluesky can be extended to ZK-based methods, to achieve Verifiable Verifications This builds on ideas from the recent verification protocol, and explores both direct integrations and lightweight ones, with different points in the tradeoff space of trust 1/2
5 months ago
1
10
3
Another way to think about is adding some generic external code execution mechanism to enable arbitrary verifiers
add a skeleton here at some point
5 months ago
0
0
0
How do people think about new verifications mechanisms in a way that don’t complicate the protocol? E.g. automated verification that can be verified completely using cryptography, lets say about emails Would a good way be: 1. Use the current mechanism with an automated user as the verifier 1/2
5 months ago
1
2
2
It’s a weird point in time where the easiest way to connect remotely from Mac to Linux is through the Windows app
5 months ago
0
0
0
Annnyoing observation about fiat shamir: there are known ways on how to use the hash functions securely (e.g. SAFE), there are reasonable type-based methods to make sure you include everything that’s needed from the protocol description (maybe post incoming?), but 1/2
5 months ago
1
0
0
reposted by
Kobi Gurkan
grjte
5 months ago
🧵 The AT Protocol shows the power of a personal data store. All of our public atproto data is easy to find and access. We can interact with it flexibly in myriad ways and combinations. Wouldn't it be nice to do the same for our private and collaborative data? 👇
1
13
3
reposted by
Kobi Gurkan
Nick Gerakines
5 months ago
I've been working on a network-local ATProtocol dev environment that gives me end-to-end production functionality for Smoke Signal, including handle resolution and repository access. Here’s how I put it together. 🧵
6
77
19
ZK provers on mobile? some thoughts on what needs to change to uphold the security guarantees we work so hard to get tl;dr - the deployment supply chain, at least, should be better
www.kobi.one/The-Lies-Our...
loading . . .
The Lies Our Provers Tell Us | Notion
2025-05-14
https://www.kobi.one/The-Lies-Our-Provers-Tell-Us-1f32d692802180358ae6c14fd9d09127
5 months ago
0
4
1
On the lookout again in 2025 for an editor that has the following: 1. good iOS support, or at least a reasonable mobile friendly web editor 2. able to share a draft article for comments 3. math support must, embedding support optional Bonus - publish directly from the app 1/2
5 months ago
1
1
0
reposted by
Kobi Gurkan
Nick Gerakines
5 months ago
@graze.social
(and I) just open sourced AIP, a small but powerful service to ease OAuth session handling in the ATmosphere. It supports both did:plc and did:web identities and simplifies session management for apps using ATProtocol.
loading . . .
GitHub - graze-social/aip: ATmosphere Authentication, Identity, and Permission Proxy
ATmosphere Authentication, Identity, and Permission Proxy - graze-social/aip
https://github.com/graze-social/aip
7
83
25
The real AGI test has always been handling python dependencies
5 months ago
0
2
0
reposted by
Kobi Gurkan
grjte
5 months ago
🧵 The AT Protocol (atproto), which underlies Bluesky, lets us to interface with the same data in as many ways as we can conceive of through AppViews that each provide a different "view" of the network. Can we make our local-first software as interoperable as the AT Protocol? 👇
1
29
12
What are the best tools to develop full backend or web apps completely on your phone? I know at least one person doing that successfully
6 months ago
1
0
0
reposted by
Kobi Gurkan
grjte
6 months ago
🧵 I've been experimenting with combining local-first software and the AT Protocol (atproto) to play with the design space of apps that live at both ends of the privacy spectrum - maximally private AND maximally public, without some of the downsides of the modern web. Why? 👇
1
69
19
In 10,000 years, the life form composed of many units of humans engulfed in computers will laugh at the single human existence of today
6 months ago
1
1
0
Is there an OpenRouter equivalent with flexible and pay-per-use but for other AI tools for voice, video, etc? An end to end flexible payment stack
6 months ago
0
0
0
The “two diseases” diagnosis in House is equivalent to “It’s the compiler” moment for a developer
6 months ago
0
1
0
What if the real pmf of cryptography is verifying correctly cited case law in llm output
6 months ago
0
2
0
When Andrija and
@lmao.bsky.social
told me they're writing an extremely fast cryptography library in Julia I didn't know what to think... And then they showed me the following cool stuff:
baincapitalcrypto.com/releasing-c...
1/4
loading . . .
CryptoUtilities.jl: A Small Julia Library for Succinct Proofs
We’re excited to open-source CryptoUtilities.jl, a collection of Julia packages built to prototype and benchmark succinct proof systems over binary fields, along with a simple walkthrough for how to…
https://baincapitalcrypto.com/releasing-cryptoutilities-jl-a-small-julia-library-for-succinct-proofs/
6 months ago
2
9
5
Used Gemini 2.5 to generate a game based on the “On Proving Pairings” paper by Andrija and Liam Zap the non-residues 😂
kobigurk.github.io/zap-non-resi...
H/t to
@emollick.bsky.social
for the prompt
6 months ago
0
0
0
zk - uses only verifiability zkzk - verifiability and zero knowledge zkzkzk - recursive verifiability of zkps zkzkzkzk - zero knowledge recursive verifiability of zkps zkzkzkzkzk - …
6 months ago
0
4
0
No one transacts in the same blockchain twice, for it is not the same blockchain and they are not the same person
6 months ago
0
4
0
Does a local first Oura ring exist?
8 months ago
0
1
0
Fun fact: co-snarks are obtained from reversing the arrows on normal snarks
10 months ago
0
3
0
reposted by
Kobi Gurkan
10 months ago
ZODA Joint work with
@nicomnbl.bsky.social
and
@lmao.bsky.social
(with help from our friends Nash, Sanaz, and John at
@celestiaorg.bsky.social
) A minor tweak to the encoding procedure makes data squares like Celestia's provably correct Paper:
bit.ly/zoda2
Blog:
bit.ly/zoda1
loading . . .
ZODA: Zero-Overhead Data Availability
We introduce ZODA, short for ‘zero-overhead data availability,’ which is a protocol for proving that symbols received from an encoding (for tensor codes) were correctly constructed.
http://Bit.ly/zoda2
1
22
9
reposted by
Kobi Gurkan
Nico
11 months ago
Very excited for these puzzles to come out. I think they have huge teaching potential. Join us for this weekly online event! ZK Hack is a great way to learn about advanced cryptography and meet the cryptography-in-web3 community
add a skeleton here at some point
0
4
3
New benchmark for papers: if you give it an image of an algorithm, can an LLM implement it
11 months ago
0
3
0
ZK Hack V starts next week on Nov 26th! Andrija,
@nicomnbl.bsky.social
and I have been brewing a few puzzles that would challenge what you know about the security of widely used systems today🤭 Stay tuned 🫡
zkhack.dev/zkhackV/
11 months ago
1
8
3
“We model our adversary such that it has computational power N, and for any attack against the system (with required computational power M), we have N < M”
almost 2 years ago
0
1
0
A proof a day keeps the hacker away
about 2 years ago
0
1
1
Decentralization is a stage and we are all actors
about 2 years ago
0
0
1
I’m using an app that cross posts to X, Farcaster and bluesky wooooo
about 2 years ago
1
1
0
reposted by
Kobi Gurkan
Matthew Green
over 2 years ago
A new blog, trying to clarify the difference between fully-homomorphic encryption, multi-party computation and Ashton Kutcher.
https://blog.cryptographyengineering.com/2023/05/11/on-ashton-kutcher-and-secure-multi-party-computation/
1
28
9
@yui.bsky.social
/card
over 2 years ago
1
0
0
Load more
feeds!
log in