# Aztec Workshop | Jose Pedro Sousa | Painless Zero-Knowledge Circuitry with Noir | ETHDam 2023

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 20:30
- Watch: https://streameth.org/watch/yt-5KLTroMcldg
- YouTube: https://www.youtube.com/watch?v=5KLTroMcldg

## Description

Jose Pedro Sousa is a Developer Relations Engineer at Aztec. 
https://twitter.com/zpedro_eth

Aztec
https://aztec.network/

ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷
Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

foreign [Music] okay so we're on so how's it going everything cool yeah it's been great I mean yeah um so I'm gonna talk a little bit about zero knowledge so I'm assuming people have heard about it um but first i'm gonna present myself I'm I'm the Pedro people call me um I used to be a music teacher then I kind of stopped I stopped teaching people to start teaching machines because they do what I tell them but then I mean teaching is still more interesting because machines is what I tell them and yeah that doesn't work too well sometimes now I'm just the real engineer at Aztec labs and so I work mostly with this kind of zero knowledge things uh and namely Noir so today uh let's just go through our rundown we're gonna talk just a little bit about DK what what it is I think that's not going to be a surprise for anyone then I'm going to talk about Noir and our specific zkdsl that we're building at stack then our build plan um basically I'm gonna demo something let's hope it works and so I'm just going to present what I what's going to be happening and then yeah then finally we're gonna try to hack something just very quick uh just to show how Noir works and in the context of ZK so we know that GK proofs are powerful they allow for secret Roll-Ups they allow for a bunch of privacy stuff that we care about but again with creates power uh usually comes Universe programmable commitments so I'm I'm personally I don't understand much of this I try but it's it's kind of hard and the problem with GK is exactly that is that your I mean in order to develop very good position if you understand the math behind it but if you don't then you're gonna have some trouble and so this is very important for us because as you see ZK works with there is a lot of use cases for ZK from privacy that's basically why we are here uh from corporate because you can basically prove that you know something without disclosing what for gaming as well because you can have a lot of chain gaming of chain gaming compiles identity like we know with sismo they were just talking just here this morning it was very interesting they were using ZK and then we know a lot about blockchain defy gaming I put crypto twice it's intentional because yeah crypto will crypto so yeah and we kind of try to have Noir in these two places so in the intersection and in ZK and that's going to be the Aztec L2 chain that I can talk about it later not today not now okay today but not now about Aztec but what we're trying to do and why do we need Noir for that um so for that we need a usable Universal CKD SL we need something that people can write very easily just like they write solidity that's kind of a tough job right just so that usually we talk about Universe polynomial commitments and how do we turn that into something that people can write just like they write solidity so we basically we just copied rust we're like okay rust is a nice language just just copy Kev likes likes rest so Kev just decided to copy I'm kidding but yeah it's just like basically they are saying they're almost the same thing on the surface once you start scratching the surface things get quite different so I'm gonna give you just a quick example just Spot the Difference between these two pieces of code um so yeah I think I think the the colors give it up oh okay okay reload what happened yeah okay well this one doesn't doesn't want no problem well basically this one this is what these are this one is rust so they're the same right but again it's just on the syntax level it's just that because there are many things that are different between between rust and Noir obviously I mean there was no concept of memory in in a in GK in yeah in ZK yes but in in Noir in general so but the syntax is the same and that's that's the whole point so we want to write code instead of writing circuits so people that use Decay are used to write circuits they go and sometimes draw the circuit on a piece of paper and then connect the wires and then that's how they how they write so if you are used to work to work with Socrates or circum that's that's basically how how things usually go so we want to write code instead of circuits something that you can write as unusual language another slider didn't want okay no problem so what tools do we have for Noir right what what kind of tools do we already have just keep in mind that we're in Alpha so we are 0.4 something so uh it's still enough stage software so be careful um it's not production right it's not edited and I think weird things happen sometimes so yeah it's a but what's happening show anyway okay yeah I didn't want to load this okay we have tests okay I'm gonna show you next what tests look like and in Noir and it's pretty easy we have solidity verifier that's very important because if you want to verify proof on chain then you need to have a verifier we have demand solidity because we kind of like the EVMS but obviously you can have it on every chain and if you're interested in in writing verifiers and other another changes talk to us because we'll probably find that we have jscs this part doesn't work so I'm lying here okay I mean it works with with all versions of Noir we're fixing that um yeah but that's that's uh that's pretty cool because you can basically run proofs on the browser run proofs on your server and this allows for a lot of use cases that are very very interesting one thing that yeah we are proving back-end agnostic so basically this means that the language is what you're gonna see but it will compile to a steer which abstract uh circuit in generated representation and so it means that it will compile to something that can be understood by many backends and so this means that it's back in diagnostic it's because you can basically you can plug in whatever backend you want you we usually plunk we usually plug in Planck or Turtle block ultrablanc hunk golden Punk whatever all the proving schemes that Zack's Zach invent but for now we are we are on ultrapound but you can also use ganark for example which is another backhand you can use a Marlin you can use growth as long as they understand Acer you can use them and just plug in that and have your proofs being verified there so past that let's present our build and how what what exactly are we building here okay so we're going to start by um installed in Europe so that's the part that didn't work okay it's a bash script so I'm glad you're not with your laptops because it's kind of a yeah it's a script it's basically if you're used to Foundry app or rest app or uh that's basically the same thing for Noir you just install that surpass script you run it and you have from our app installed so then you can you can run wire up and you're gonna install the latest version stable version of Noir and so then you have nargo version and you can check that you have uh whatever version you're looking for and yeah that's it okay another slide I didn't show our project is going to be we're gonna create a new Noir project this one is easy you just go and write Noah new Narco new okay that's gonna be easy and then we're gonna make it interesting so this common this command doesn't exist but yeah it's gonna unfortunately um and then we're gonna write a test I'm going to show you how tests look like so that's no problem that the other side didn't work because I'm gonna I'm gonna show you and then we're gonna if you have time which I think we'll have we'll try to also generate the solidity verifier and deploy it sometimes it's kind of a it's a difficult task so but we'll try anyway if it breaks please yeah just that's it so let's hack so so here's my oh yeah link tree profile didn't show that's one important yeah you have Demar starters here just talk to me I'm gonna um you can show you can show you the starters which is basically repo you can clone and start building something you also have the radar docs and you also have the New Ireland Road map if you want to know where are we heading yeah just yeah just like him just go and zoom in with whichever QR code you were interested so so let's let's then start with something so I have here already something just in case something goes wrong I can show you the whole project okay then cheats I'm gonna show you so I'm just gonna go another pencil now up already so it's that pass script but I'm gonna show you just run right up and to install the night list because I'm yeah because I'm crazy I want to use nargo like latest version and then I please that's hopefully 0.6 okay that's cool so we can start I'm gonna just go and run nargo new um demo it's okay and it will start a new project here and just CD into demo just kind of code something okay okay that's something so basic program doesn't do much basically just checks that one field you can you can think of the field as a kind of an integer for it's not the same right it's not not remotely disabled but you can treat it in the same way for most for most use cases it just asserts that one is different from the other one so I want to make it slightly more interesting I want to prove that I know the pre-image of a hash this is one of the most basic programs that you can write so I'm gonna first import the library for the hash so I'm gonna use dependency STD and this is for load my standard Library the Noir sternum Library so I'm gonna just rename this for business pretty much I'm going to make this an array of uints uh just three I think yeah sorry yeah okay is it better yeah okay thank you for thank you for letting me know and so here's the image I'm gonna just say hash so this hash is something that people can know and so it could be it could be for example on a smart contract something that everyone knows you just want to prove that you know the image the pretty image but everyone knows what the hash is and so I'm gonna just this is gonna be it's gonna be a shot 256 I mean there are many others that's not a good that's not a good hashing because hash for CK but you should use like Poseidon or hot position or something but yeah I'm just gonna use that one uh and so now I'm just gonna go and say the hash uh nice try that's not that's not it yeah yeah okay 156 pretty much okay um oh cool so uh copilot already knows pretty much what what it is and so yeah this is it this is our circuit pretty pretty simple so far it's going to be like that so basically what I want I just I just calculate a hush I just calculate the shaft that's pre-image and then I just assert and I want to prove that I know that the pre-image the shaft of my pre-image is going to be equal to the shot to the hash everyone knows so I'm gonna just just test this now I need the wins for the pre-image and for the hash that's why I had the cheats here no in the other okay here okay here is it I'm just gonna pass space this here so trust me trust me bro this is the this is the hash of 420 uh yeah trust me it is um so now I just go and yeah co-pilots already knows what I want to do so this hopefully this will give us a correct answer so let's just head out over to my terminal I'm gonna go and go on Argo test uh okay yeah I'm in the wrong derivative another test and it says Auto as fast that's cool I mean if I change something I'm just going to make this is a five it hopefully will fail yeah okay it failed so that's it that's it for our test but now I don't have I know that the syntax is okay but I don't really have a proof I haven't run a proof so I'm gonna prove that first I need to build the constraint system that's very easy I just go and go now go check and then I have the constraint system you see I have the verifier the prover and the verifier the proof of you is what I want to prove stuff I know stuff everyone knows verify is just stuff everyone knows but I don't want to reveal to you so I'm gonna go into my prover I'm gonna just literally pick this place it here uh yeah this is Domo file so I have to clean it up a little bit here I have it cool so I'm ready right I have the proofer I have the circuit so I'm gonna go nargo proof I'm just gonna give it the name of P you can call it whatever people just use P because it then will spit out to prove as P dot proof so yeah it takes a while because again shot 256 is not the best the best one you should use another one um you can have all you can just go to Synergy docs you have all the existing the hash we have we have feathers and we have ketchak we have um then we have I mean we have a hundred bunch of them mimc whatever whatever you want we if we don't have we want we want half and so we'll probably find someone that wants to to build this kind of Primitives um let's wait a little bit yeah that's it that's just we're waiting moment okay so we have so you see our proof is here yeah it's not very human readable but yeah it's a proof so I'm gonna run this little command this little command basically generates our solidity verifier so it will literally speed out a solidity contract for us so while it's still doing that I'm gonna create an anvil Network so I will so yeah so I don't have to use a test net could take a while so I just create an email Network just running on my machine it could be hard hot node whatever I just like Forge like Foundry so yeah I'm using anvil um yeah and this this smart contract it's already it's a nice contract you see you can have like it's very difficult to understand but you can see this is a library and then basically you have here a contract so I'm just copy this and I'm going to remix okay remix IDE so I guess you probably have used this it's a pretty old tool it's pretty cool so I'm going to start a new project if no not default new workspace you know just a blank workspace and I'm going to create a contract I'm going to give it the same name Blanc VK I mean it's Ultra Blanc already it's not you see it's Ultra verifier so Planck is is like two generations before um so we have here it will it just complained that I was trying to copy paste something which is a security risk and it is so in this case it's no problem so I'm going to compile it it will say yes sorry sorry again yeah can you see it it's one more like that okay thank you so it complains about stack too deep so those of you who work with byte code you know that this happens so I'm gonna just use uh like a specific VM version and I think five five thousand rounds of optimization should work okay it worked so here I have contract you see is already built at constraints it's already there so I'm gonna just plug in my Foundry provider which is basically my Anvil Network that I have here is it it has a bunch of money in there so I'm gonna go and deploy my ultra verifier it's deployed and so here is it now I'm gonna just paste my pick my proof my proof is here here okay because let's just add a 0x before so it knows it's uh it's um hexadecimal and then I'm just gonna pick literally my verify stuff that everyone knows this is just basically the byte the byte spotted for 32 but it's because that's that's how that's how solidity likes it and yeah it's going to be very very anticlimactic but just gonna say true just yeah proof it's the proof is is verified if I change something it's gonna enter some kind of loop I guess it's just yeah it says out of guys it just enters some good some Loop it doesn't work and that's it I mean you can you can obviously verify that off chain and don't have to use it on our chain and we don't care about how where do you use it as long as it's it's a it's a it's verified somewhere and and that's it I think we have some time for questions right I hope if you have any questions oh sorry okay okay cool well then that's it I mean yeah just um just hit me if you need anything if you need to know something cool thank you [Applause]
