Sign in

Kobi Gurkan

@kobi.bsky.social
945 followers 211 following 186 posts

applied crypto, security, experimental things | zkSecurity

PostsRepliesMedia
Kobi Gurkan @kobi.bsky.social · 16/01/2026
One cool thing about designing your vibe coding workflow for verifiability and testability is that you can switch out models and only impact performance, including switching to local models
020
Reposted by Kobi Gurkan
Filippo Valsorda @filippo.abyssdomain.expert · 05/01/2026
PSA: go.sum is not a lockfile. You never need to look at go.sum. go.mod has everything you need.
words.filippo.io
go.sum Is Not a Lockfile
In Go, go.mod acts as both manifest and lockfile. There is never a reason to look at go.sum.
513325
Kobi Gurkan @kobi.bsky.social · 30/12/2025
One fun simile of AI producing a lot of math/code and produced proofs of correctness using formal verification is that it’s like we’re moving to an NP feeling era where the statements are math/code and witnesses are these proofs
130
Kobi Gurkan @kobi.bsky.social · 29/12/2025
Submitted to present in #ATmosphereConf! Thoughts on what tools and protocols we have at our disposal for expressive end to end verifiability using trusted execution environments and/or cryptography
1193
Kobi Gurkan @kobi.bsky.social · 27/12/2025
How well it would work to paint PLA with acrylic with only sanding and without priming? Or otherwise do you know an in-office friendly and convenient priming method?
010
Reposted by Kobi Gurkan
grjte @grjte.sh · 23/12/2025
7/ Check out the details, including a deeper discussion of challenges, a prototype of Bitchat over Wi-Fi Aware, and general notes on cross-platform Wi-Fi Aware implementation 👉 grjte.sh/bitchat-wifi...
0144
Kobi Gurkan @kobi.bsky.social · 24/12/2025
@grjte.sh’s exploration into using Wi-Fi aware for local-first chat on bitchat Wi-Fi aware has large range, simpler authentication and is becoming cross-platform supported @grjte.sh integrated it as an alternative to Bluetooth 1/2
120
Reposted by Kobi Gurkan
grjte @grjte.sh · 23/12/2025
🧵 Could Bitchat have 5x the range and 100x the throughput for the same power expenditure? I explored how Wi-Fi Aware could improve the reliability and throughput of Bitchat and mobile ad-hoc networks in the absence of internet connectivity. #bitchat 👇
14112
Reposted by Kobi Gurkan
Nick Gerakines @ngerakines.me · 21/12/2025
@brittanyellich.com and I have been talking about community modeling on ATProtocol lately and I wrote a follow-up piece to her recent post "Representing groups in ATProto".
ngerakines.leaflet.pub
The Community Manager Pattern - Nick's Blog
This post looks more closely at Brittany Ellich's work on representing groups in ATProtocol. It builds on earlier conversations and explores how these ideas might work in practice.
3364
Reposted by Kobi Gurkan
Chad Fowler @chadfowler.com · 21/12/2025
aicoding.leaflet.pub
Regenerative Software
5236
Reposted by Kobi Gurkan
Martin Kleppmann @martin.kleppmann.com · 08/12/2025
New blog post! ✨ I argue that AI will make formal verification go mainstream. martin.kleppmann.com/2025/12/08/a... Three reasons for this: 1. LLMs are getting increasingly good at writing proofs using proof assistants. This will make formal verification vastly cheaper than it's been to date.
martin.kleppmann.com
Prediction: AI will make formal verification go mainstream — Martin Kleppmann’s blog
1416929
Kobi Gurkan @kobi.bsky.social · 16/12/2025
Being unique can make you strong ❤️ In unique signature schemes, existential unforgeability implies strong unforgeability
010
Kobi Gurkan @kobi.bsky.social · 04/11/2025
The word of the week is vandermonde
020
Kobi Gurkan @kobi.bsky.social · 21/10/2025
doing my favorite thing of composing stuff together, and toying around with x402 and Privacy Pass to see how they can play together to introduce a sort of a blinding layer to x402 an intro to both, how they're used and a possible way to integrate them! kobi.leaflet.pub/3m3pyyctda22i
kobi.leaflet.pub
Privacy Pass + x402 = blinding for x402 - Kobi's blog
0152
Kobi Gurkan @kobi.bsky.social · 11/10/2025
The word of the week is malleability
000
Kobi Gurkan @kobi.bsky.social · 03/10/2025
Want to understand ZODA? Tried to implement it and found yourself stumped?? This FAQ is just for you! Wrote some answers for questions I’ve seen around me and those I had myself, navigating details and tradeoffs If you have any more - let me know :)
141
Kobi Gurkan @kobi.bsky.social · 27/08/2025
Signature schemes are a cornerstone of modern infrastructure and we all know the common ones that sign a message, and some of you know ones that can be e.g. aggregated In more specialized scenarios, the properties needed aren’t obvious until you hit that problem yourself 1/2
140
Kobi Gurkan @kobi.bsky.social · 06/07/2025
Came across an interesting paper this weekend about “Early Signs of Steganographic Capabilities in Frontier LLM” Specifically they’re testing non-fine tuned models that are widely available, like GPT 4.5 1/4
120
Kobi Gurkan @kobi.bsky.social · 22/06/2025
Memory leaks are going to have a whole different meaning soon
020
Kobi Gurkan @kobi.bsky.social · 18/06/2025
You get great results from Claude Code by guiding it to generate tests for itself to verify its output and supporting it by having live data and services running locally, which it utilizes since it runs in your environment And being able to do it on your phone is the best 1/4
120
Reposted by Kobi Gurkan
Boris @bmann.ca · 13/06/2025
I rewrote my [[Community Search Engine]] note. It's still not very crisp. I include emerging tools that directionally are working on what I want to be using - @dxos.org Composer, @inkandswitch.com Patchwork (not yet public), @grjte.sh's Groundmist, and the newly released by Tonk, TonkbookLM.
3133
Kobi Gurkan @kobi.bsky.social · 11/06/2025
Wei Jie’s write ups are among the best resources you can find for in-depth cryptography implementation topics If you’re looking to bridge the gap between theory and practice - have a read
041
Kobi Gurkan @kobi.bsky.social · 09/06/2025
I’m on board with nap coding
010
Kobi Gurkan @kobi.bsky.social · 01/06/2025
On the lookout for a one click experience to collect interesting things I come across my day, so that I could get a nice summarized digest a day after The closest I had was with X bookmarks, but that’s limited to X x.com/kobigurk/st... 1/2
100
Kobi Gurkan @kobi.bsky.social · 28/05/2025
Video of my talk in zksummit about Ligerito has been published! It’s about the work by Andrija and @lmao.bsky.social introducing a small and concretely fast polynomial commitment scheme Since then, a fun thing has happened — 1/3
184
Kobi Gurkan @kobi.bsky.social · 24/05/2025
“A penny for your thoughts” has a very different meaning now
000
Kobi Gurkan @kobi.bsky.social · 23/05/2025
anyone trying to do provable image transformation as in eprint.iacr.org/2024/1066 in fast proving zkVMs? It’s one of the cases a bunch of time will pass until you need to compress it for fast verification, if at all
eprint.iacr.org
VerITAS: Verifying Image Transformations at Scale
Verifying image provenance has become an important topic, especially in the realm of news media. To address this issue, the Coalition for Content Provenance and Authenticity (C2PA) developed a standard to verify image provenance that relies on digital signatures produced by cameras. However, photos are usually edited before being published, and a signature on an original photo cannot be verified given only the published edited image. In this work, we describe VerITAS, a system that uses zero-knowledge proofs (zk-SNARKs) to prove that only certain edits have been applied to a signed photo. While past work has created image editing proofs for photos, VerITAS is the first to do so for realistically large images (30 megapixels). Our key innovation enabling this leap is the design of a new proof system that enables proving knowledge of a valid signature on a large amount of witness data. We run experiments on realistically large images that are more than an order of magnitude larger than th
142
Reposted by Kobi Gurkan
Leaflet @leaflet.pub · 22/05/2025
Leaflet Publications: blogging on Bluesky — version 0.1 is here! ✅ now: make publications, add posts, publish to Bluesky 🗓️ soon: subscribing, commenting & other social features Try it: leaflet.pub/home We'd love your feedback & ideas for how we can make this great!
screenshot of our "Leaflet Lab Notes" publication homepage, with one post listed, at https://lab.leaflet.pub/screenshot of a record from @leaflet.pub's PDS, showing the data for the Leaflet Lab Notes publication, at https://pdsls.dev/at://did:plc:btxrwcaeyodrap5mnjw2fvmz/pub.leaflet.publication
3234680
Kobi Gurkan @kobi.bsky.social · 22/05/2025
trying out @leaflet.pub for my recent post, I'm really enjoying the UI a lot: kobi.leaflet.pub/3lpruvjqlhs22 just a question - wen math? would like to use it for my next post :D I also see comments are on horizon, but how does it work with unpublished drafts that I don't want others to see yet 👀
kobi.leaflet.pub
Verifiable Verifications - Kobi's blog
140
Kobi Gurkan @kobi.bsky.social · 22/05/2025
How are people thinking of tool use with local models? Feels to me qwen 30b a3b gets confused easily, at least when using the OpenAI agents sdk tool infra
000
Kobi Gurkan @kobi.bsky.social · 21/05/2025
real time proving on pretty complex statements on the server side is here same developer experience on client side would be huge for experimentation (delegation is helpful but interested to see what we can do without)
000
Kobi Gurkan @kobi.bsky.social · 19/05/2025
Some thoughts about how verifications in Bluesky can be extended to ZK-based methods, to achieve Verifiable Verifications This builds on ideas from the recent verification protocol, and explores both direct integrations and lightweight ones, with different points in the tradeoff space of trust 1/2
1103
Kobi Gurkan @kobi.bsky.social · 17/05/2025
Another way to think about is adding some generic external code execution mechanism to enable arbitrary verifiers
000
Kobi Gurkan @kobi.bsky.social · 17/05/2025
How do people think about new verifications mechanisms in a way that don’t complicate the protocol? E.g. automated verification that can be verified completely using cryptography, lets say about emails Would a good way be: 1. Use the current mechanism with an automated user as the verifier 1/2
121
Kobi Gurkan @kobi.bsky.social · 15/05/2025
It’s a weird point in time where the easiest way to connect remotely from Mac to Linux is through the Windows app
000
Kobi Gurkan @kobi.bsky.social · 15/05/2025
Annnyoing observation about fiat shamir: there are known ways on how to use the hash functions securely (e.g. SAFE), there are reasonable type-based methods to make sure you include everything that’s needed from the protocol description (maybe post incoming?), but 1/2
100
Reposted by Kobi Gurkan
grjte @grjte.sh · 14/05/2025
🧵 The AT Protocol shows the power of a personal data store. All of our public atproto data is easy to find and access. We can interact with it flexibly in myriad ways and combinations. Wouldn't it be nice to do the same for our private and collaborative data? 👇
1133
Reposted by Kobi Gurkan
Nick Gerakines @ngerakines.me · 14/05/2025
I've been working on a network-local ATProtocol dev environment that gives me end-to-end production functionality for Smoke Signal, including handle resolution and repository access. Here’s how I put it together. 🧵
67916
Kobi Gurkan @kobi.bsky.social · 14/05/2025
ZK provers on mobile? some thoughts on what needs to change to uphold the security guarantees we work so hard to get tl;dr - the deployment supply chain, at least, should be better www.kobi.one/The-Lies-Our...
kobi.one
The Lies Our Provers Tell Us | Notion
2025-05-14
041
Kobi Gurkan @kobi.bsky.social · 11/05/2025
On the lookout again in 2025 for an editor that has the following: 1. good iOS support, or at least a reasonable mobile friendly web editor 2. able to share a draft article for comments 3. math support must, embedding support optional Bonus - publish directly from the app 1/2
110
Reposted by Kobi Gurkan
Nick Gerakines @ngerakines.me · 01/05/2025
@graze.social (and I) just open sourced AIP, a small but powerful service to ease OAuth session handling in the ATmosphere. It supports both did:plc and did:web identities and simplifies session management for apps using ATProtocol.
github.com
GitHub - graze-social/aip: ATmosphere Authentication, Identity, and Permission Proxy
ATmosphere Authentication, Identity, and Permission Proxy - graze-social/aip
78119
Kobi Gurkan @kobi.bsky.social · 26/04/2025
The real AGI test has always been handling python dependencies
020
Reposted by Kobi Gurkan
grjte @grjte.sh · 23/04/2025
🧵 The AT Protocol (atproto), which underlies Bluesky, lets us to interface with the same data in as many ways as we can conceive of through AppViews that each provide a different "view" of the network. Can we make our local-first software as interoperable as the AT Protocol? 👇
1288
Kobi Gurkan @kobi.bsky.social · 23/04/2025
What are the best tools to develop full backend or web apps completely on your phone? I know at least one person doing that successfully
100
Reposted by Kobi Gurkan
grjte @grjte.sh · 22/04/2025
🧵 I've been experimenting with combining local-first software and the AT Protocol (atproto) to play with the design space of apps that live at both ends of the privacy spectrum - maximally private AND maximally public, without some of the downsides of the modern web.  Why? 👇
16718
Kobi Gurkan @kobi.bsky.social · 19/04/2025
In 10,000 years, the life form composed of many units of humans engulfed in computers will laugh at the single human existence of today
110
Kobi Gurkan @kobi.bsky.social · 19/04/2025
Is there an OpenRouter equivalent with flexible and pay-per-use but for other AI tools for voice, video, etc? An end to end flexible payment stack
000
Kobi Gurkan @kobi.bsky.social · 19/04/2025
The “two diseases” diagnosis in House is equivalent to “It’s the compiler” moment for a developer
010
Kobi Gurkan @kobi.bsky.social · 18/04/2025
What if the real pmf of cryptography is verifying correctly cited case law in llm output
020
Kobi Gurkan @kobi.bsky.social · 17/04/2025
When Andrija and @lmao.bsky.social told me they're writing an extremely fast cryptography library in Julia I didn't know what to think... And then they showed me the following cool stuff: baincapitalcrypto.com/releasing-c... 1/4
baincapitalcrypto.com
CryptoUtilities.jl: A Small Julia Library for Succinct Proofs
We’re excited to open-source CryptoUtilities.jl, a collection of Julia packages built to prototype and benchmark succinct proof systems over binary fields, along with a simple walkthrough for how to…
294