aldus.nexus

Diffie-Hellman

Two strangers agree a secret in public. Mix paints in the open, keep one colour private, and both sides end up with the same colour that an eavesdropper can't unmix. Then the real modular maths underneath.

Toy only. Never use this for real security: the groups are tiny and nothing is authenticated.

Under the paint

Square and multiply

The numbers

gx mod p jumps about
work: Alice against Evemultiplications, log scale

Eve's brute force

Eve heard p, g, A and B. To get the secret she needs Alice's a: the x with gx ≡ A (mod p), the discrete logarithm. With no shortcut she tries x = 1, 2, 3 and so on. Alice only needed a few dozen multiplications. Toy only.

gx ≡ A (mod p)
time to break, extrapolatedlog scale

Man in the middle

Eve only listens. Mallory sits on the wire and swaps the public values for her own, so Alice shares a secret with Mallory and Bob shares a different one with Mallory. Diffie-Hellman alone can't tell. The fix is to check who you're talking to: compare a short fingerprint of the secret over another channel, or sign the public values.

How it works

The paint version: Alice and Bob agree a base paint in public. Each adds one secret colour of their own and sends the mix across. Each then adds their own secret again to the mix they received. Both end with base + Alice's + Bob's, in a different order, so the colours match. Eve saw every pot that crossed the wire, but mixing those two gives far too much base, and paint can't be unmixed.

The maths version swaps paint for powers. Everyone knows a prime p and a generator g. Alice picks a secret a and sends A = ga mod p; Bob picks b and sends B = gb mod p. Alice computes Ba, Bob computes Ab, and both are gab mod p. Raising to a power is quick by square and multiply, a few dozen steps here. Undoing it, finding a from A, is the discrete logarithm, and nobody knows a fast way for well chosen groups.

Diffie-Hellman agrees a key; it doesn't prove who is on the other end. A man in the middle can run two exchanges at once, which is why real protocols sign the public values or show safety numbers to compare.

two people who have never met agree a secret while shouting every message across a crowded room.

A = ga mod p    B = gb mod pp is prime, g generates the group, a and b stay private. A and B go over the wire.
s = Ba = Ab = gab (mod p)(gb)a = (ga)b: the order of mixing doesn't matter.
brute force ≈ p / 2 tries   vs   ≈ 2 log₂ p multiplicationsEve's expected work against Alice's. Baby-step giant-step cuts Eve to about √p, still hopeless at 2048 bits.

Toy only. Real Diffie-Hellman uses 2048-bit or larger groups or elliptic curves, authenticated public values and audited libraries.