3 ms·
To be pedantic, I don't think the Diffie-Hellman is the weak link as it doesn't specify the group or generator. It just requires that given g^a and g^b it's har
by fryguy 10y ago
To be pedantic, I don't think the Diffie-Hellman is the weak link as it doesn't specify the group or generator. It just requires that given g^a and g^b it's hard to determine g^ab. And obviously if your generator is poor the preconditions to the algorithm don't work. And then as what the post-conditions for what DHKE provides. It just establishes a shared secret with the person on the other end of a connection. You have no idea who that other person is, but you can communicate securely with them (which is why you need authenticated encryption).
I guess a better wording would be "It's extremely easy to implement textbook Diffie-Hellman Key Exchange in was that don't satisfy the preconditions of Diffie-Hellman, and this are gravely insecure."
- baby 10y agoThe backdoor is a nobus one. g^ab is still hard to find for anyone who doesn't have access to the backdoor.
- sdevlin 10y agoNot specifying the group/generator is a weak link, which is what David is taking advantage of. Curve25519 is a good counterexample of a DH function that leaves nothing to the imagination.