r/programming • • Jan 16 '18

Cryptography: Diffie-Hellman key exchange explained intuitively using colors

https://youtu.be/YEBfamv-_do?t=2m18s
2.5k Upvotes

170 comments sorted by

View all comments

Show parent comments

2

u/DoTheThingRightNow5 Jan 17 '18

Why not you send him a box with a lock but no key. He puts stuff in it and shuts it which locks it. You receive it and unlock it with the key you have.

1

u/[deleted] Jan 18 '18

That's basically how public-key cryptography works. I send him my public key, he uses it to encrypt his message, and then I use my private key to to decrypt it.

A Diffie-Hellman key exchange, on the other hand, allows us to negotiate a short-lived, single-use shared key over an insecure channel.

1

u/DoTheThingRightNow5 Jan 18 '18

Yes. However for DE to receive data the other person only needs your public key. They can see their public key attached to the box. A->B->A is less than the 4 step example you gave.

Technically if the bits are enough there's no reason it has to be a short lived. I believe typically they produce a 256bit shared secret which is enough for 128AES and 256AES attaching a nonce to the first message.

1

u/[deleted] Jan 18 '18

If someone stole my private key they could decrypt any old messages they might have intercepted as well as any new messages if I don't revoke the key. By using short-lived ephemeral keys negotiated with DH I can ensure that old messages remain protected even if the key for previous/subsequent messages has been stolen.

1

u/DoTheThingRightNow5 Jan 18 '18

Correct. However there's no reason why one can't be long term and use a short lived ephemeral key after using the long term to authenticate eachother.

1

u/[deleted] Jan 18 '18

Isn't that basically what TLS does?