Watched channel · Eve is listening

Diffie–Hellman key exchange

Alice and Bob want a shared secret. Everything they send crosses an open line, and Eve is recording all of it. Work through the steps one at a time — or press Play — and watch what Eve does, and doesn't, end up with.

public prime p =23 generator g =5 agreed openly — Eve already has these

Alice

private a—
public Anot yet
shared snot yet

Bob

private b—
public Bnot yet
shared snot yet
A = 8

Eve · on the wire

nothing intercepted yet

Step 0 of 7

Shared secret established: s = 2 Alice and Bob both landed on it. Eve saw p, g, A and B — and still can't get there.
Eve's notebook fills up with real numbers — p, g, A, B — and she can watch every packet cross the wire. But turning A and B back into a or b means solving a discrete logarithm: with small numbers like these it's crackable by brute force, which is why real key exchanges use primes hundreds of digits long instead of 23. That gap between "easy to compute forward" and "hard to reverse" is the entire security of the exchange.