Welcome to Noirland
ETHBerlin·Thu, Jun 19, 2025, 02:30 PM · 21:59
A brief overview of what Noir the ZK language is, followed by a curated glimpse into cutting edge explorations, researches, and applications using Noir. Previewing the future of privacy: right here at Protocol Berg v2.
Transcript
Thank you. Thank you for the lovely intro. GM, GM, everyone. It is the true GM here in Berlin. Lovely being here with you all.
Given the lack of laughter, can we get a raise of how many people here speak just a bit of German, German the language. Lovely. And how many of you also program a bit of Noir the language. Yes, that is a very hard pivot to the topic that I want to share on. Okay.
That's actually a decent crowd. Lovely. But yeah, I'm not afraid of hard pivots. So thank you all for going through that. But yeah, I'm Savio from Aztec.
Lovely here sharing a bit more about programmable privacy, but also particularly with Noir with you all. A brief rundown of what we'll be going through today with the update on what is CK. So don't worry if you didn't raise your hand just now, because we also have a very brief what is Noir session as well. And then we will take a very lovely glimpse into the Noir land on what's happening with the language, what have people been building with it. Hopefully an exciting journey for you all.
But starting off, what is CK to begin with? If you are getting back home after today, just remember, a bottle of beautiful CK proof is actually in my hand right now. We'll go through how. But by formal definition, CK, what we would normally refer to it as pure knowledge proof. It's basically computation plus proving plus hidden inputs.
We'll go through them one by one, so don't worry too much about it. But what we are usually used to would be pure computation. This is what you do on running your programs, written in Python, written in Rust. You're simply computing, for example, one plus one equals two. And then serial knowledge proof, the proof part is that you don't only just compute, but you're also proving what you want to compute as well.
And the serial knowledge part is that you can prove about it without reviewing all the information that you feed into the program to begin with. And that makes a serial knowledge proof. Basically proving things without reviewing everything. You might still be thinking at this point, what on earth does that mean? For the lovely German-speaking community, what is happening here?
But back to the example of a bottle of beautiful serial knowledge proof, this is a basic typical workflow of how a serial knowledge proof goes through things. First you have an input, you have an input towards your program, and then there's the prover person and the verifier person that interact between the proof. The prover basically takes the input, bring it into some computation, and then brings it to some proving operation, which outputs a proof that then gets passed to the verifier, which does the verification. And in this case, the bottle of Coca-Cola is the serial knowledge proof itself. And what it actually proves is that Coca-Cola has a recipe behind it.
A secret Coca-Cola recipe of the beautiful bottle of drinks that you get every day. Well, hopefully not every day. But that is basically the serial knowledge proof pipeline. It's a proof of a recipe that you don't want to review to the world, but once you get the chance to taste a bottle of Coca-Cola, or maybe many bottles of Coca-Cola, you kind of know that Coca-Cola has a recipe to consistently produce that proof to you. And what does that relate to NOIR?
What is NOIR to begin with, to have anything to do with serial knowledge? Before NOIR existed, the way that people code and program serial knowledge proofs is through, unfortunately, C++ libraries, or maybe if you are familiar with Circom, you are building basically circuits, tying things like literally electronic circuits, where you tie inputs, signals into logic gates, then output values, which is still computation, but it's not what we are all familiar with, and it makes me cry. I'm not sure about you, but I don't like coding in C++, to begin with. And then it brought the birth of NOIR itself from five years ago, the first commit, which then flourished into the beautiful CK language that we have today, that works on chain, on different chains, off-chain, on different devices, web browsers, mobile proofing systems, or mobile phones, I mean, even across different proofing technologies, with 100-plus contributors these days, working on the language itself, as well as the ecosystem around it. And what NOIR brings to the table is simply three things.
First of all, simplicity, that is in syntax, that is in developer tooling, that is in the entire developer experience to make it as simple as possible to build a serial knowledge proof, to build a CK app to begin with. The second part is open source. It means permissive access to building serial knowledge proofs. You don't need to pay a price, you don't need to get permission, get whitelisted to start building. It also means credibly neutral.
We try our best to decentralize as well, to make it as neutral as possible as a public good for people to use to build CK proofs. If you don't like it, you can always fork it as well. That's the beauty of open source. And the third value that NOIR brings to the table is universal. As I mentioned, working across different chains, even off-chain, and also web-friendly to begin with for everyone to build the CK app that they are imagining for.
So the language itself evolves into a beautiful one with unsigned integers, with signed integers, but also with, it's behind the screenshot itself, but with a lot of different language features that you are used to in a general purpose programming language, trace, control flows, etc. It also comes with a great suite of libraries, not just by us, the moderately sized contributing team, but also the much bigger NOIR community that we have today, all the way from data types to even Libyan storage-proof libraries if you want to do something fancy. And it also comes with great tooling, VS Code support, debugger, NOIR.js packages for you to deploy on a web app to begin with. So a lot of beautiful tooling as well.
And, of course, at the end of the day, the beautiful community that we both have here, but also joining us online or perhaps joining us async online as well, that works on NOIR, curious about NOIR, and always building with NOIR. So talking a lot about the things behind NOIR or what NOIR is, let's dive into what people have been building with NOIR. Kicking off with CK Passport, amazing team working on amazing technology that a lot of CK, if you are from the CK space, you are probably very used to the analogy or the explanation of we can do a proof that you are an adult without reviewing your data first to begin with. Turns out it's a very challenging problem, but when you factor in the many different countries with the many different identification and passport technology that they each choose to adopt, but the CK Passport team is doing an amazing job to support a lot of different countries at this point to actually generate a proof of your passport, a proof of your age, a proof of your country, for example, a proof of even your name. Hopefully one day we will be starting a Savio DAO to begin with.
But fun fact on CK Passport, by the way, if you are buying your Deaf Connect tickets these days or looking at options, and if you happen to be from Latin America, you can actually generate a zero knowledge proof of your passport and get 50% off. So something that has been in development and has been in deployment for a while now. And there's also the amazing team behind CK Email working on the technology that proves your email. So this could be email from your, let's say, employer. This could be an email of your Twitter account.
This could be an email from even Trading View. This then unlocks a lot of interesting use cases where you can cryptographically prove, for example, Trading View data as an oracle. You can prove your employment details or employment what you are a professional in. And the CK Email team has been building this amazing technology as the founding stone to unlock a lot of those email-based applications, basically bridging email data that you have today into the Web3 world or in whatever world that we want to throw a CK proof in. There's also the Taseo team that is working on beautiful technologies, marrying MPC, which does very good at private computation over private data that no one needs to know.
We will go through a bit on some of the applications later. But marrying that MPC technology with zero knowledge proof to cryptographically attest to those operations and to cryptographically compose those beautiful private computations with all the other CK apps or with all the other even normal apps if you throw a verify in to tie those two technologies together. There's a Bo team that works on zero knowledge proving open banking API. So open banking is a standard that traditional commercial banks that we are all using today are kind of gradually adopting to share information in a kind of secret manner or a tested manner of your bank account. So you can, for example, request your bank balance, you can request your transaction history, et cetera, through the open banking API from your own banks.
And what the Bo team is trying to do is to do a zero knowledge proof of those specific requests without reviewing all the information behind. That means, for example, if I am able to prove my transaction to a certain, let's say, on-ramper that is available on-chain, with that proof alone, I can already claim, for example, the USDC that I'm trading for through an off-chain channel. And that builds a pretty minimally trusted on-ramping, off-ramping system through the Bo's initiative itself. And then there's the OpenBank team that is working on CK Glassdoor. So it brings the beauty of CK JWT that is locking credentials from your Google account, for example, Apple account, et cetera.
And it also brings together CK emails that we mentioned just now. And you can cryptographically prove that you work for a particular company, at what salary, if you want to review that. And at the same time, you don't necessarily need to review who you are within the company while you get a very, very, very, very trustable or very, very viable proof that attests to your range, that attests to your role in the company. And you can review the company itself without, well, a big problem for Glassdoor itself is people can either post very, very permissionlessly, but then there's very little verification about the actual role and what they are actually doing in the company. If they stricken things up, then the hurdles or the verifications that users have to go through to actually make a post on Glassdoor would be immense.
And with cryptography, that kind of minimizes that barrier without trading off the trusted assumption or trading off the reliability of the information that people post on the platform itself. And speaking of posting things, Stealthnode is a project that works on true knowledge proving your email or your login credentials so that you can post a message without revealing who you are from that particular organization. That was definitely not me trashing about Linux two minutes before capturing the screenshot itself, but basically you can privately post certain thoughts or certain things without revealing who you are. This could be for fun, trash poses, but also perhaps if you think about journalism, this could be a very good way to whistleblow as well without necessarily reviewing who you are within the company. And the mobile proving team is actually working on mobile proving with Noir, and they have recently come together with the proof of concept of mobile proving Stealthnode that we mentioned just now fully on mobile.
So it's amazing that we're now not only able to do Noir proofs on web browsers, but also can do it on mobile phones where most, if not all, people hopefully love. And posting things is not only limited to organizations as well. Anonworld is working on a social platform where you can post things based on your token ownership. So for example, this particular forum that they have is a forum that you can only post if you own a certain amount of Ethereum. So it attests to if you look closely, you can see some of the posts actually shows like this person owns two plus ETH, the next person actually owns four plus ETH, but not necessarily reviewing how many ETH they own, and definitely not like which address does that tie to.
And this gives you the flexibility to post with skin in the game, but not necessarily revealing who you are. And then there's also the beautiful team at TK Polk that works on social with Noir through signaling the intention that you want to connect with some person. It could be evolving into a dating app, it could be evolving into a business application, but basically what it does is that you can share some information about yourself before actually connecting with the person. So for example, you can share your first name, not your last name, you can share about your hobbies, for example, maybe your religion, you can share about which country you are based in, but not necessarily the city, and only until the other person accepts kind of your signal intent and is willing to connect, share the information with you. At that point, you will be sharing more information with that person, so you kind of get a two-level or maybe even building this multi-level of trust based on personal information when it comes to social.
There's a CK coverage team that is working on CK GPS that proves your GPS location and attests it against known hurricane paths, for example, or known natural disaster paths. And that then gives you a cryptographic proof of if you are, for example, affected by a certain natural disaster, and then cryptographically unlocks, for example, your insurance claim or maybe governmental aid for what you might be eligible for given the unfortunate event you are going through. And there's also Terry Escape, this is a beautiful team working on, when we think about privacy, we often think about the harsh part of security, the harsh part of how do we make the society work, the harsh part of how we make private money work, but there is also the beautiful part of privacy is fun to begin with. All fun games to a certain extent involve privacy. When you think about if you play League of Legends, if you play Dota, if you play CSGO, if you play Hearthstone, if you play even poker to begin with, there's always a certain amount of hidden information from your players to actually make the gameplay experience engaging.
Terry Escape is one of the little gaming team that works on Noir with gaming. Basically, two players control two batches of agents to fight against each other in the darkness. Very interesting experiment that they are working on. And there's also the CK Among Us team where they are working particularly on Fork of War within cryptography using Hazeo technology, if I recall correctly, where one person, your player, only sees the other player if they are close enough, but not if they are far apart. This might be very easy to do if you are working in traditional gaming because you simply have a server hosting all the information and the server does not reveal anything.
But with this case, everything is actually cryptographically proven, which you don't even need a server to begin with. You can have a P2P game with Fork of War, which is amazing to begin with. And with all those innovations, there are also kind of traditional, boring things that Noir can do good as well. The Eragon CK research team has been working on the private voting initiative for the noun style, which you can do fully private on-chain voting based on your noun's NFT ownership. There's also 1KX that built the CK safe implementation where you can do private multi-fix on-chain rather than fully transparent and public ones.
There's also the Noire team that is working on a lending market that gives you privacy as well. So think Aave compound, but rather than fully public positions, rather than fully public ownerships, you can actually lend money and borrow money in a private manner. Amazing stuff. But yeah, I've gone through just a bit of what people have been building in the Noire ecosystem. Some of the project teams that I mentioned just now, and some that weren't even included in the slides, will be talking more about their projects doing deeper dives at NoireCon next week.
So if you are interested, definitely sign up, blue.mar at NoireCon too. We'd love to see you there and chat more. But yeah, a few takeaways if we are going back home from this talk. It's quite a long one.
So remember, zero noise proof equals Coca-Cola. A bottle of Coca-Cola is a good proof. And Noire is basically the language, the way that you can brew your own Coca-Cola. And it's time for privacy. So hopefully that's a very nice glimpse into the future that we can all build together.
And lovely to take some questions if you have any. But thank you all. Thank you very much, Fabio. We got a couple of questions. So yeah, let me kick this off here.
First, what are the current limits of the Noire language? For example, the size of inputs, expected latency, and so on. Thank you. So when we think about zero noise proof, usually the limitations would come from the overhead versus normal computation. And it, of course, depends on what you want to do particularly.
But if you are wanting to, for example, port an entire wrist-size architecture into CK, that's what most CK PM teams are doing. You can see a very immense computation overhead. But for a lot of simpler use cases, for example, the ones that are highlighted just now, like CK password, CK email, et cetera, those are fully provable, for example, within seconds on your mobile phone. So it took a lot of impressive work from the teams. But we are already there if you want to ship something meaningful in production in terms of performance.
And in terms of limitations specifically, the limitation is simply your hardware. If you have better hardware, then you can run more things. If you have less hardware, you can run less things. But with the tech stack itself, there is no hard limitation of what you can do. Perfect.
Okay, we got another one here. Are you planning to support more backends than Barettenberg soon in terms of docs and tooling and so on? Yeah, that's a very good question. As I mentioned, Noir is meant to be universal in the beginning. So from the day one of designing Noir, we have been working towards a generalized language that works across different proving backends.
In fact, today, it works with Barettenberg, yes, from Aztec Labs, but it also works with multiple different backends. Like World has been building the ProverKit backend based on Spartan, if I recall correctly. Solana has been working on Gnog backend. There are two funky implementations that work with Noir as well. Check out awesome Noir on GitHub, and you can find a proving backend session which shows which backend already works with Noir.
And if you are building one, definitely get in touch as well. And somewhat related here, does Noir support Halo 2? Is there complexity overhead when using libs like Halo 2? That's also a very good question. There was a Halo 2 proving backend implementation that works with Noir.
I think it's outdated right now, given the lack of interest in continuing the development itself. But yes, it works. Short answer is it works. The long answer is it needs more work to get it working. And so far, the last question.
You can still ask one while this one is being answered, but when enums? Oh, that's from a good Noirian here. Follow the GitHub issue, is what I would recommend, and stay tuned from there. If you want to PR, we welcome PRs as well. It's an open source project, we can all contribute.
Automatic transcript — names and jargon may be misspelled.