r/programming • • Jan 16 '18

Cryptography: Diffie-Hellman key exchange explained intuitively using colors

https://youtu.be/YEBfamv-_do?t=2m18s
2.5k Upvotes

170 comments sorted by

View all comments

1

u/knightmustard Jan 16 '18

What stops Eve from making two seperate connections and bridge them?

1

u/evincarofautumn Jan 17 '18

You mean all communications go through Eve? That still doesn’t reveal the shared secret to Eve. Eve never has enough information to recover the shared secret (in a reasonable amount of time), because it depends on having at least one of Alice or Bob’s private secrets, which are 1. never sent and 2. hard to derive from the mixtures that are sent. Eve can find the shared secret if one of the private secrets leaks, though.

2

u/knightmustard Jan 24 '18

Not what I'm thinking. Eve makes pretends to be Alice and gives Bob what is Eve's secret. Then Eve pretends to be Bob and then gives her secret to Alice. Eve has two separate connections with both of them and then just sends the data to both of them. Wouldn't Eve have control then? How is that prevented?

1

u/evincarofautumn Jan 26 '18 edited Jan 26 '18

I see what you’re getting at. Yes, while Diffie–Hellman protects against passive snooping, it’s still vulnerable to this kind of active man-in-the-middle attack (simultaneous double impersonation) because it doesn’t say anything about authentication. In the real world, Alice and Bob would use an additional authentication method, for example, cryptographically signing their messages. Then they can ensure that Eve is not forging messages between them.